Tightening up security for quarantine script
From: Pierre Dufresne (pierre.dufresne_at_messf.gouv.qc.ca)
Date: 02/05/04
- Previous message: Matthew.van.Eerde_at_hbinc.com: "RE: SMTP Service in private DMZ OK?"
- Next in thread: Alan Melia (Melmac): "RE: Tightening up security for quarantine script"
- Reply: Alan Melia (Melmac): "RE: Tightening up security for quarantine script"
- Reply: Sarbjit Singh Gill: "RE: Tightening up security for quarantine script"
- Maybe reply: Pierre Dufresne: "Re: Tightening up security for quarantine script"
- Maybe reply: Watson, Michael: "RE: Tightening up security for quarantine script"
- Maybe reply: BOWSER, DAVID: "RE: Tightening up security for quarantine script"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 5 Feb 2004 15:05:21 -0000 To: focus-ms@securityfocus.com('binary' encoding is not supported, stored as-is)
Hi everybody,
When you use the quarantine functionnality of Windows 2003, you need to write and then distribute a script on the computers of the users that are going to connect through a VPN.
This script is supposed to do some validations and then end with the execution of a small utility called RQC.exe that sends an OK return code to the VPN server.
In our environment, most of the users are local admin of their laptop and are in a position to modify the script, thus bypassing the validation process.
Has anybody been using this quarantine feature and given some thoughts on how to protect the script?
Any comment would be appreciated.
Thanks
---------------------------------------------------------------------------
---------------------------------------------------------------------------
- Previous message: Matthew.van.Eerde_at_hbinc.com: "RE: SMTP Service in private DMZ OK?"
- Next in thread: Alan Melia (Melmac): "RE: Tightening up security for quarantine script"
- Reply: Alan Melia (Melmac): "RE: Tightening up security for quarantine script"
- Reply: Sarbjit Singh Gill: "RE: Tightening up security for quarantine script"
- Maybe reply: Pierre Dufresne: "Re: Tightening up security for quarantine script"
- Maybe reply: Watson, Michael: "RE: Tightening up security for quarantine script"
- Maybe reply: BOWSER, DAVID: "RE: Tightening up security for quarantine script"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|