Workstation security

From: Alisson Leite de Morais Veras (alisson@larc.usp.br)
Date: 09/28/01


Message-ID: <3BB4CF3F.975CF3DF@larc.usp.br>
Date: Fri, 28 Sep 2001 16:27:59 -0300
From: Alisson Leite de Morais Veras <alisson@larc.usp.br>
To: focus-ms@securityfocus.com
Subject: Workstation security

Hello to all.

We are having some problems in our NT workstations. I want to give users
no permission to install and uninstall softwares, it's a good beginning
to prevent viruses and other malicious apps like trojan horses
auto-executables, for example. (READ access to:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run, RunOnce, RunOnceEx)

I'm using MMC with Security Configuration Manager and Policy Editor and
I'm too close to do it, but sometimes, somethink strange happens. For
example, in Microsoft Visual C++, a domain user can't access the
'C:\TEMP' directory to create a project, they can't even see it inside
Visual C++, but it works inside Visual Basic. 'C:\TEMP' is with
read/write permission. From explorer, a domain user can create, delete
and execute everything is owner from him and others.

Does anyone have any idea? Any documents to review my policies and
permissions?

Thanks
Alisson



Relevant Pages

  • Re: Help Domain user associated to wrong Wss account
    ... access functions on wss. ... > I understand that you apply different permission to different user. ... > This newsgroup only focuses on SBS technical issues. ... > |> permission is higher than normal domain user. ...
    (microsoft.public.windows.server.sbs)
  • Re: Help Domain user associated to wrong Wss account
    ... DOMAIN\UserA is an administrator of a couple of subsites on wss ... > permission is higher than normal domain user. ... we can apply domain user with different WSS ...
    (microsoft.public.windows.server.sbs)
  • Re: Help Domain user associated to wrong Wss account
    ... I understand that you apply different permission to different user. ... of WSS subsites, and user B have full permission on some site while user A ... This newsgroup only focuses on SBS technical issues. ... |> permission is higher than normal domain user. ...
    (microsoft.public.windows.server.sbs)
  • RE: Windows Shared File Permission error - Access Denied
    ... You have check the Effective Permission state on one of these users and take ... Consider rechecking the group membership, ... We now deleted domain user from the permissions list on the shared ...
    (microsoft.public.windows.server.general)
  • RE: Portal permissioning
    ... domain user reader/guest permission first and then provide higher permission ... level to individual users. ... > upload documents to this portal. ...
    (microsoft.public.sharepoint.portalserver)