Talk With an Expert

How to Avoid Information Disclosure when Managing Windows with WMI

How to Avoid Information Disclosure when Managing Windows with WMI (PDF, 3.40MB)Published: 17 Jul, 2007
Created by
Alex Timkov

This paper provides an introduction to accessing Windows via WMI in a secure manner. After introducing the subject of WMI security, we will demonstrate how the default WMI access level leads to unnecessary exposure of rather sensitive information, as management data travels between the management station and the Windows hosts that are being managed via WMI. We will make recommendations on using WMI to manage remote Windows hosts securely, without exposing the sensitive management session information. We will demonstrate how very simple and effective measures can stop unnecessary information leaks and boost management access security.