Re: services running in windows domain (winXP clients)

From: Mike Lyman (mikelyman-security_at_comcast.net)
Date: 12/22/04

  • Next message: ISNYC: "RE: Microsoft Vulnerabilities ARE being reported to Microsoft"
    Date: Wed, 22 Dec 2004 14:12:43 -0600
    To: focus-ms@securityfocus.com
    
    

    Christos Triantafyllidis wrote:

    > Maybe it wasn't clear as i wrote it. What i want is not to disable
    > some services. What i want is to allow only specific services to run.
    > To apply software restriction i must know the name or the hash of the
    > software i want to restrict. Today it is trojan A tomorrow it may be
    > trojan B. if i there is a way to disable all services except the ones
    > that i approve i would be protected against both A and B trojan
    > without even know their name or hash or anything about them.
    >
    Software restriction policies work both in the "allow all but..." and
    "allow none but..." The allow all should be the easier to test and
    configure but the other approach should work since only those things you
    allowed will run.

    -- 
    Mike Lyman CISSP*
    *mikelyman-security@comcast.net
    /"You can't take the sky from me"/
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: ISNYC: "RE: Microsoft Vulnerabilities ARE being reported to Microsoft"

    Relevant Pages

    • Re: services running in windows domain (winXP clients)
      ... running services and disables all except for the ones ... > trojan B. if i there is a way to disable all ... > even know their name or hash or anything about them. ...
      (Focus-Microsoft)
    • Re: services running in windows domain (winXP clients)
      ... apply software restriction i must know the name or the hash of the ... Today it is trojan A tomorrow it may be ... even know their name or hash or anything about them. ... Christos Triantaffyllidis ...
      (Focus-Microsoft)
    • Re: I had high hopes for software restriction policy
      ... This could be due to the hash. ... I am having serious issues with software restriction policy... ... Created a Global Security Group "Restricted Applications Group" and Set ...
      (microsoft.public.windows.group_policy)
    • Re: MSN Messenger Wont Restrict by GPO
      ... but the hash and the test computer were taken from ... > you create a hash rule for a program, Software Restriction Policies ...
      (microsoft.public.windows.group_policy)
    • RE: Windows 2003 Server - MS Rulez?
      ... Attacking the hash is far more work than is required to "get around" a hash ... software restriction, as I mentioned in my other post. ... software restriction default policy as opposed to ... implement and enforce WLAN security policies to lockdown enterprise WLANs. ...
      (Focus-Microsoft)