Re: How to block users from installing other apps

From: Ansgar Wiechers (bugtraq_at_planetcobalt.net)
Date: 06/27/03

  • Next message: Dariel Cruz: "RE: Question about windows service"
    Date: Fri, 27 Jun 2003 01:25:58 +0200
    To: focus-ms@securityfocus.com
    
    

    On 2003-06-25 afreyman@dsw.net wrote:
    > You have several options, depending on whether you're using Windows
    > 2k3 or 2k. You can block the "Add/Remove programs" from the control
    > panel or you can block the entire control panel. You can also disable
    > IE. With W2k3, there is an available feature to block based on program
    > path and an .exe hash. This has been discussed here in terms of
    > security, but can also be used to prevent users from installing and
    > running apps, if you have a specific list of apps that you want to
    > block. Do remember that this feature only works on Windows XP. There
    > also additional software restriction rules that you can create in
    > order to prevent the user from installing various applications.

    All of these suggestions will at best create some sort of "Security by
    Obscurity" as long as the users have Local Administrator privileges.

    > Another approach would be to NOT make the users local admins and just
    > run/install apps with elevated privileges.

    No. It's not another approach, it's the *only* approach. Everything else
    is completely pointless, since any local administrator can do (and of
    course should be able to do) anything he/she pleases on the local
    machine.

    My 0.02 $CURRENCY

    Regards
    Ansgar Wiechers

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Dariel Cruz: "RE: Question about windows service"

    Relevant Pages

    • Re: Forcing a screen repaint??
      ... because you see all the windows flash for an instant. ... same result as that of the change to the control panel. ... the apps seem to do fine. ...
      (microsoft.public.vc.mfc)
    • Re: Applications on server
      ... will tell you what apps are installed. ... Control Panel / Add or Remove Programs / Add or Remove Windows components ...
      (microsoft.public.win2000.applications)
    • Re: Forcing a screen repaint??
      ... It does under Windows XP. ... flash like when font smoothing is changed through the control panel. ... fonts so that they get the cleartype ones. ... the apps seem to do fine. ...
      (microsoft.public.vc.mfc)
    • administrative tools folder problem
      ... I have a windows 2000 pc. ... local administrator, but when I open the administrative ... tools folder in the control panel I don't get any icons. ...
      (microsoft.public.win2000.group_policy)
    • Re: control panel = folder
      ... I got to control panel and there is one there. ... I'm not looking so much for a fix, ... Download, install, run, update and perform a full scan with the ... Download/Install the latest Windows Installer: ...
      (microsoft.public.windowsxp.general)