RE: services running in windows domain (winXP clients)

From: Haralambos Mavromatidis (Haralambos_at_msn.com)
Date: 12/19/04

  • Next message: Wim_Remes_at_msp.be: "RE: Subdomain security"
    To: <focus-ms@securityfocus.com>
    Date: Sun, 19 Dec 2004 10:41:05 -0500
    
    
    

    Though some may think it overkill, I audit the logs of Spybot Search &
    Destroy, and if there is a new application that I have not yet restricted I
    get that by looking at the running applications listing. Then I simply put
    out a policy to restrict that one and if there is any other information
    about the installation methods and executables that I can find with some
    more research used I restrict them also...

    -----Original Message-----
    From: Mike Lyman [mailto:mikelyman-security@comcast.net]
    Sent: Friday, December 17, 2004 8:30 AM
    To: focus-ms@securityfocus.com
    Subject: Re: services running in windows domain (winXP clients)

    Christos Triantafyllidis wrote:

    > Is there any way to allow only specific services to run at win XP
    > clients through domain group policy?

    I would think software restrinction polices would be able to help here.
    It would probably be a royal pain to configure but you are supposed to be
    able either block specific applications and allow all others to run or allow
    only specific ones to run and block all others. If nothing else it ought to
    block the installation program from installing the rogue service.

    -- 
    Mike Lyman CISSP*
    *mikelyman-security@comcast.net
    /"You can't take the sky from me"/
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    
    



  • Next message: Wim_Remes_at_msp.be: "RE: Subdomain security"

    Relevant Pages

    • Re: How can I prevent a student to install softwares on windows 98 machines?
      ... opposed to NT-based PCs that you can just restrict users permissions. ... you could consider something called "reborn ... It is a PCI card inserted into your computer's PCI slot. ... initial installation, you can ask the card to capture a fresh copy of ...
      (comp.security.misc)
    • Re: How can I prevent a student to install softwares on windows 98 machines?
      ... >opposed to NT-based PCs that you can just restrict users permissions. ... It is a PCI card inserted into your computer's PCI slot. ... >initial installation, you can ask the card to capture a fresh copy of ... >all software installed into your computer and use the copy to "reborn" ...
      (comp.security.misc)
    • Re: Policy
      ... Policy restricting access to the C drive and downloading from IE are simply ... an installation exe file when entering sites to setup games. ... >> does not restrict a user from installing anything from the Internet. ...
      (microsoft.public.windows.server.security)
    • Reg .software installation previllages
      ... 50-60 user in the active directory server.I want to restrict the ... installation of particualr or any software domain computers,. ...
      (microsoft.public.win2000.active_directory)

  • Quantcast