Backdoor Strategy- opinion needed.

Posted by the Hampster on Stack Overflow See other posts from Stack Overflow or by the Hampster
Published on 2010-05-21T18:53:00Z Indexed on 2010/05/21 19:10 UTC
Read the original article Hit count: 218

Filed under:

I'm creating an application to track publications and grants for a university. Professors will need to put they CV into the system when it is up and running. Yeah, right.

The person in charge is planning on hiring someone to input all of the information, but my questions is how?

The strategy I'm thinking of is to install a backdoor. The lucky undergrad can log in as any professor using the backdoor. Once all the data is removed, the backdoor can be removed.

Doing so would probably be as simple as editing out a comment in the config file. The IT guys would still have access, but since they control the machines, they would have access anyway. Are there any flaws to this strategy?

© Stack Overflow or respective owner

Related posts about security