PAW Handling in Admin Tiering Env.

Hello folks!

I am curious how you handle the PAW Design in your company when admin tiering is implemented.

My Approach:
Tier 0 Administration PAW - Physical notebook on admin-vlan Port and firewalled to allow everything for administrate tier0

Tier 1 PAW - This is the "main" PC of the IT-People. There job is to administer the whole day and I consider Jump-Hosts from office-pcs as no-clean-keyboard and therefore as insecure.

Tier 2 Administration / Office work - this is where the Admin connects from his t1-pc to a remote desktop server hosting all office related stuff like mails, websurfing and teams.

I shifted tier 1 and tier 2 devices around to have clean keyboard. The IT Users I work with sometimes are unsatisfied because office work takes place in a rdp-session. The companies I consult are too small to use 3 physical devices as PAW and it is too incomfortable for them.

Looking forward to hear how you handle the security/comfort.

reddit.com
u/Usr0017 — 5 days ago

Is this considered a Bug?

Hello community!

I found a security misconfiguration but I am not sure if it is enough to be reported as low severity bug.

I am able to request the QR Code for MFA Registration with the same TOTP secret that was registered after enabling 2FA.

The impact is there when an attacker is able to run Javascript via XSS and forward the result of the endpoint to an attacker side. But there is no XSS I could find.

Report as low finding or skip it?

reddit.com
u/Usr0017 — 3 months ago