RE: Disabling sharing and group policies

From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: 09/15/03

  • Next message: Pidgorny, Slav: "RE: Why Programs get written to need admin priveleges."
    To: "'Alexander Suhovey'" <asuhovey@mtu-net.ru>, "'Ansgar Wiechers'" <bugtraq@planetcobalt.net>, <focus-ms@securityfocus.com>
    Date: Mon, 15 Sep 2003 13:10:15 -0400
    
    

    The easiest way to know what should or should not be in an application for
    these purposes is to read the application specification for Windows 200x,
    which is here:
    http://www.microsoft.com/windowsserver2003/partners/isvs/cfw.mspx.

    HTH,

    Laura

    > -----Original Message-----
    > From: Alexander Suhovey [mailto:asuhovey@mtu-net.ru]
    > Sent: Friday, September 12, 2003 12:36 PM
    > To: 'Ansgar Wiechers'; focus-ms@securityfocus.com
    > Subject: RE: Disabling sharing and group policies
    >
    >
    > > I still don't see why you won't remove your users from the
    > > local administrators' group and spare yourself the trouble.
    >
    > > I haven't run into a single application that couldn't
    > > be persuaded to run with reduced privileges.
    >
    > [Sorry if it is offtopic...]
    >
    > Why administrators must pesuade some applications to run with
    > reduced privileges anyway? I mean, why don't software
    > developers care about that in first place? Isn't that strange
    > when you must have Administrator privileges to just... Scan a
    > picture? Write to CD? Whatever *not-administrative* tasks...
    >
    > Can you please point me to some public source of information
    > about common ways to make an application to run under user
    > privileges if it won't? As I understand, one should run some
    > filemon- regmon-like tools to monitor application and then
    > make resources needed by app to be available under user
    > account. Is there any otner tips you can share?
    >
    > Thanks,
    > Al.
    >
    >
    > > -----Original Message-----
    > > From: Ansgar Wiechers [mailto:bugtraq@planetcobalt.net]
    > > Sent: Thursday, September 11, 2003 12:46 AM
    > > To: focus-ms@securityfocus.com
    > > Subject: Re: Disabling sharing and group policies
    > >
    > >
    > > On 2003-09-10 Matthew Wagenknecht wrote:
    > > > I'm looking for a solution to keep honest people honest..
    > I will be
    > > > monitoring the network for Everyone shares. If I find any,
    > > I will know
    > > > that it was intentional to circumvent the Group Policy. That way I
    > > > don't have to deal with "I didn't know any better".. I'm
    > > not looking
    > > > for a DoD implementation.
    > >
    > > I still don't see why you won't remove your users from the
    > > local administrators' group and spare yourself the trouble.
    > > Please don't give me that old "our applications require this"
    > > crap. I haven't run into a single application that couldn't
    > > be persuaded to run with reduced privileges.
    > >
    > > Regards
    > > Ansgar Wiechers
    > >
    > > --------------------------------------------------------------
    > > -------------
    > > KaVaDo provides the first and only integrated Web application
    > > scanner and
    > > firewall security suite that prevent Web applications
    > > attacks, the most
    > > common form of online exploitation. Download a FREE
    > > whitepaper on Security Policy Automation for Web Applications.
    > > http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    > > --------------------------------------------------------------
    > > -------------
    > >
    >
    >
    > --------------------------------------------------------------
    > -------------
    > KaVaDo provides the first and only integrated Web application
    > scanner and
    > firewall security suite that prevent Web applications
    > attacks, the most
    > common form of online exploitation. Download a FREE
    > whitepaper on Security Policy Automation for Web Applications.
    > http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    > --------------------------------------------------------------
    > -------------
    >

    ---------------------------------------------------------------------------
    KaVaDo provides the first and only integrated Web application scanner and
    firewall security suite that prevent Web applications attacks, the most
    common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
    http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
    ---------------------------------------------------------------------------


  • Next message: Pidgorny, Slav: "RE: Why Programs get written to need admin priveleges."

    Relevant Pages

    • Re: Why Programs get written to need admin priveleges.
      ... >>Why administrators must pesuade some applications to run with ... >>firewall security suite that prevent Web applications ... >>common form of online exploitation. ... >>Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)
    • RE: windows update
      ... Subject: windows update ... firewall security suite that prevent Web applications attacks, ... common form of online exploitation. ... Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)
    • Re: focus-ms@securityfocus.com
      ... local password caching need never be to a local file on a ... ticket issued Kerberose must use some sort of credential caching. ... > firewall security suite that prevent Web applications attacks, ...
      (Focus-Microsoft)
    • RE: Patch testing
      ... If you don't have mirrored disk capabilities - use Norton Ghost to snap an ... image of the system partition on the server before patching. ... > firewall security suite that prevent Web applications ... > whitepaper on Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)
    • RE: Limiting users on secific machines that are part of a domain
      ... firewall security suite that prevent Web applications attacks, ... common form of online exploitation. ... Security Policy Automation for Web Applications. ...
      (Focus-Microsoft)