• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

How would non admin people access vsphere console?

Red Squirrel

[H]F Junkie
Joined
Nov 29, 2009
Messages
9,223
We've had several incidents where users who do not have admin access somehow accessed the vmware console of a server they own. We manage it, but they can login to it to do certain work. I can't figure out how they'd even get access to do that. They should only have access to RDP, not login to Vsphere. We have a security breach somewhere it seems, which is quite dangerous as it essentially gives those people access to all our other servers too.

We made sure they have no rights within vSphere, and are not part of domain admin group. Is there something I'm missing?
 
if you are using vcenter, then they would need to be part of the local admins by default to log in, otherwise they could be using the client to log into the host directly using root.

You could look under the Tasks & Events(vcenter) or Events(ESX host) tab, selecting Events to see who logged in and when.
 
You know for sure they were accessing the VMware console, or just a 'console' session on the VM itself? Perhaps it was a "console" RDP session: mstsc /v:servername /admin. It used to be the /console switch in previous versions of the RDP client.

If they really do not have access to vCenter or the ESX(i) hosts, then that isn't how they're doing it. We also had LANDesk at one of my previous jobs which people could get console access that way as well assuming they had rights via that avenue.

The only other thing I can think of, is if you have the domain admins with access in vSphere... if you guys have "domain admin service accounts" they might know a password to, they could be doing that. Be sure to check your logs for which specifc users have logged in to vCenter.

The first thing you should do is use a non-default group to provide permissions. I recommend creating AD groups specifically for vCenter access and a local account for a backoor and remove all other access. This streamlines a "role" based type access by just dropping users in the proper group in AD.
 
Hmm I did not know you could actually get to the console using RDP, I will look into that. If that's the case it's not a huge deal then, I just don't want them to have access to modify the VM settings, insert CDs and so on.
 
mstsc /admin or /console depending on the version of the RDP client.
 
Yep tried it and it works, so that's probably what it was. That's reassuring. I don't really care about them using the console, I was just scared they were somehow using vSphere client.
 
Yeah, I can see you opening up the console on a VM and the mouse is moving around :). WHAT THE!?

There is a yellow bar along the top of the console window that will appear and tell you when more than one "VMware" console session is open. It will say: "Number of active connections has changed. There are now # active connections to this console

It is also possible to cause a false positive, for instance, you open a window up by right clicking on a VM -> open console, and then also going to the console tab while having the VM selected. There is no caption like the mirror on your car... "warning messages don't necessarily mean what they say." While that is still two separate console sessions, it can mislead you to think it is two separate vSphere Clients all together.
 
Back
Top