RE: Isolating Windows Applications

From: James Ruddy ()
Date: 04/08/03

  • Next message: Ronald Balk: "RE: SUS server"
    From: "James Ruddy" <>
    To: "'Juan José Sánchez Mesa'" <juanjo.listas@dobleJ.net>, <focus-ms@securityfocus.com>
    Date: Mon, 7 Apr 2003 23:19:07 -0400
    
    

    Juan,

    I am running a similar setup as we speak. I have the console app run as
    a very low privileged user. The second step I took was to notify the
    business unit, management and the app vendor that the application needs
    to be written as a service.

    Hope this helps.

    Jim

    -----Original Message-----
    From: Juan José Sánchez Mesa [mailto:juanjo.listas@dobleJ.net]
    Sent: Monday, April 07, 2003 13:52
    To: focus-ms@securityfocus.com
    Subject: Isolating Windows Applications

    (sorry for my bad enlish)

    A client wants to run an application in one of our internet server. The
    application is made by themselves. It's a console application which
    listen
    in one tcp/ip port for conections from a client application.

    We want to protect our server, isolating the application so it can't
    access
    critical files, the registry, listen on more than one tcp/ip port (only
    in
    which is designated to listen), etc ... And if it's possible, protect
    the
    server if the application crash. The server is a Windows 2000 Server
    (SP3).

    Anyone knows a program that isolate other programs in this way ? It's
    possible do this using a user with low privileges and running the
    applicaction as this user ?

    Ideas, tricks ... ???

    Thanks for the replies.

    <b>
    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers
    of
    technology including filtering embedded and attached file content. Rid
    your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------
    </b>

    <b>
    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
    technology including filtering embedded and attached file content. Rid your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------
    </b>


  • Next message: Ronald Balk: "RE: SUS server"

    Relevant Pages

    • RE: SharePoint
      ... in a console app, it must be something to do with web priviledges. ... I hope other SharePoint actions aren't as convoluted... ... the sid used internally may have been somewhat mangled. ... if you have other sharepoint server ...
      (microsoft.public.sharepoint.portalserver.development)
    • Re: Console application to become COM server?
      ... Microsoft MVP, MCSD ... > and turn your console app into a COM server. ... > the client asks, waits again, works again, ... ...
      (microsoft.public.vc.atl)
    • RE: checking server status
      ... Subject: checking server status ... our LAN computers including IE History. ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ... enterprise of unwanted content. ...
      (Focus-Microsoft)
    • Re: Console application to become COM server?
      ... what would you recommend a quick way to go about it? ... modifications and turn your console app into a COM server. ... the server starts, waits for the client to call ...
      (microsoft.public.vc.atl)
    • RE: SharePoint
      ... a Windows 2003 server with an admin account running it, ... sharepoint admin permissions that I shouldn't be running into this, ... this without error (like it runs in the console app)? ... Dim profileManager As New UserProfileManager ...
      (microsoft.public.sharepoint.portalserver.development)