Re: services running in windows domain (winXP clients)

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 12/16/04

  • Next message: Wim_Remes_at_msp.be: "Re: Subdomain security"
    Date: Thu, 16 Dec 2004 22:32:48 +0100
    To: focus-ms@securityfocus.com
    
    

    On 2004-12-15 Triantafyllidis Christos wrote:
    >> Another thing you can do is set registry permissions on
    >> HKLM\SYSTEM\CurrentControlSet\Services to not allow anyone (even
    >> administrators) to create new keys. Obviously, this will also make it
    >> difficult for an administrator to install new legitimate services, so
    >> that is something you must balance. Another option is to only allow
    >> one specific administrator or a small group of admins to create new
    >> keys.
    >
    > How safe is that?

    Not.

    > i mean if someone is administrator (local administator) can change the
    > registry permissions. i need somehow to disable this ability even to
    > local admins.

    The only possibility to prevent local admins from doing whatever they
    want to the computer is not to have local admins. Any local admin owns
    the machine. Period.

    Regards
    Ansgar Wiechers

    -- 
    "Those who would give up liberty for a little temporary safety
    deserve neither liberty nor safety, and will lose both."
    --Benjamin Franklin
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Wim_Remes_at_msp.be: "Re: Subdomain security"

    Relevant Pages

    • Re: Prevent users from changing domain name
      ... Currently all our user's all local admins of there ... >having to be an administrator. ... >Use Group Policy to remove properties from the My ... >restricting their access to mmc snapins [particularly ...
      (microsoft.public.win2000.group_policy)
    • Re: Setup 2K clients in NT 4.0 domain
      ... To install certain software and install hardware they need to be a local ... registry permissions which may be easy or next to impossible to do. ... users domain account has been added to the local administrator account on that ... Pro on the clients, especially if you are going to be using Windows 2003. ...
      (microsoft.public.win2000.security)
    • Re: Windows XP Update Setup Error
      ... The above KB article describes how to determine IF file and registry permissions are preventing an update from installing. ... When I try to install the latest critical update, I get the Setup Error: You do not have permission to update Windows XP. ... I am the administrator and I have administrator rights. ...
      (microsoft.public.windowsupdate)
    • Re: Running Add/Remove Programs with Administrative Rights
      ... administrator to uninstall the software. ... removing the user from the local admins and then re-logging ... applications which require full admin rights to be uninstalled. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Local Admin Rights
      ... that they are setup at Local Admins and I need to remove that ... included in this will have the local admin rights. ... has to be added to work as an administrator. ...
      (microsoft.public.windows.group_policy)

    Loading