COMPUTRACE

Computrace is used to provide services such as:

  • Secure the data of a park of remote stations,

  • Deploy always remotely updates, licenses or launch audits,

  • Geolocate stolen computers,

  • Produce reports about the machines,

  • Recover files,

  • Remotely erase documents or the entire hard drive.

This feature is very powerful. An attacker could use it to deploy a persistence device or a backdoor within the information system. A backdoor that could not be removed even by reinstalling, formatting or changing the disk or the BIOS. Let's add that the functionality seems very light in terms of security (code injection, unencrypted protocol, no authentication, call via simple URL).

Documentation : https://www.kaspersky.com/blog/beware-of-vulnerable-anti-theft-applications/3837/

Therefore, it is recommended to:

  • Disable this feature.

Last updated