cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Adam_Z
Level 9
Report Inappropriate Content
Message 1 of 6

ServerSiteList.xml file in plain text

Jump to solution

I manage multiple location from my ePO, each region has own Agent handler and some of them have additional SuperAgent in order to load balancing.

I've putted my attention on ServerSiteList.xml file generated during agent installation because all information about infrastructure are stored in this particular file are in plain text. 

Isn't it a little bit sensitive if we keep FQDN which pointing to particular customer in plain text? 

Having this file attacker don't need to do any reconnaissance and can prepare target attack on AV infrustructure.

From my point of view information about infrastructure should be stored on encrypted XML or Agent DB not in plain text in location where anybody can read file.

Or maybe it's already possibile to encrypted this file but I just omimited option in ePO ?

 

1 Solution

Accepted Solutions
cdinet
Employee
Employee
Report Inappropriate Content
Message 6 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

As suggested, please open a ticket as a vulnerability request.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

5 Replies
cdinet
Employee
Employee
Report Inappropriate Content
Message 2 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

Where exactly are you seeing that sitelist file and what version of the agent are you running?  That should be in the ma.db files.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Adam_Z
Level 9
Report Inappropriate Content
Message 3 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

Trellix Agent 5.7.9 installation brings ServerSiteList.xml to /opt/McAfee/agent/data directory

cdinet
Employee
Employee
Report Inappropriate Content
Message 4 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

If a hacker can get to the file on the local system, it is already compromised.  You can open an SR if you want for investigation.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Adam_Z
Level 9
Report Inappropriate Content
Message 5 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

System has not been compromised yet I'm concerned about keeping information of infrastructure in plain text. That putting some risk on customer environment.
I would not willing to show everybody how AV infrastructure is configured, however keeping this information in plain text putting risk on customer in situation in case of endpoint will be stolen for exampel.

Having knowledge about customer's machines in DMZ and vulenrabilities related to McAfee/Trellix software (including apache and tomcat), the preparation of potential attack on agent handlers in DMZ would be pretty easy, that would led to disabling communication between ePO and endpoints connected to ePO over internet and that would make blind the whole security on customer side.

 

cdinet
Employee
Employee
Report Inappropriate Content
Message 6 of 6

Re: ServerSiteList.xml file in plain text

Jump to solution

As suggested, please open a ticket as a vulnerability request.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community