Backdoor Strategy- opinion needed.
Posted
by the Hampster
on Stack Overflow
See other posts from Stack Overflow
or by the Hampster
Published on 2010-05-21T18:53:00Z
Indexed on
2010/05/21
19:10 UTC
Read the original article
Hit count: 215
security
I'm creating an application to track publications and grants for a university. Professors will need to put they CV into the system when it is up and running. Yeah, right.
The person in charge is planning on hiring someone to input all of the information, but my questions is how?
The strategy I'm thinking of is to install a backdoor. The lucky undergrad can log in as any professor using the backdoor. Once all the data is removed, the backdoor can be removed.
Doing so would probably be as simple as editing out a comment in the config file. The IT guys would still have access, but since they control the machines, they would have access anyway. Are there any flaws to this strategy?
© Stack Overflow or respective owner