RE: I need some information on locking down pc's

From: Matthew Farrenkopf (farrenkm_at_ohsu.edu)
Date: 04/08/05

  • Next message: Dubber, Drew B: "RE: I need some information on locking down pc's"
    Date: Fri, 08 Apr 2005 09:43:43 -0700
    To: focus-ms@securityfocus.com
    
    

    I'm just taking a shot in the dark here. I have never tried this, nor have I ever seen this suggested.

    How about:

    * Lock it down as you would a normal PC (turn off unnecessary services, tweak Registry settings to harden them, etc.)

    * Change the shell so that, instead of running Explorer, it runs Internet Explorer

    * Set the desired Web page to the home page

    * Use IE's proxy settings to limit to this one page (set proxy to localhost, then list in the exception list the site(s) you want to be able to visit)

    * Use AppSec (or it's XP equivalent; I understood it's built-in to XP now) to restrict down the applications you want to be able to run

    Theoretically, this will cause it to run IE each time the user logs in.

    More knowledgeable people may be able to tweak this list further.

    Matt

    >>> "Mike Thaxton" <mthaxton@britecomputers.com> 04/07/05 1:18 PM >>>
    Let me add a little more to this - these are xpsp2 boxes for a medical
    purpose they do not want anyone to be able to access anything but one
    webpage. Using fingerprint id to be able to access the pc, there is
    also a webcam, microphone, speakers, printer on these machines.

    The webpage that loads needs to have java and windows media player
    access for the internet connectivitivty.

    I hope that maybe this will help with what I want to do

    Michael Thaxton
    Brite Computers Helpdesk Support
    585-758-0200 x183
    585-758-0222 fax
    mthaxton@britecomputers.com
    www.britecomputers.com
     

    -----Original Message-----
    From: Dominique Davis [mailto:DDavis@pivx.com]
    Sent: Thursday, April 07, 2005 4:12 PM
    To: Mike Thaxton; focus-ms@securityfocus.com
    Subject: RE: I need some information on locking down pc's

    http://www.pivx.com

    Qwik fix

    -----Original Message-----
    From: Mike Thaxton [mailto:mthaxton@britecomputers.com]
    Sent: Thursday, April 07, 2005 12:21 PM
    To: focus-ms@securityfocus.com
    Subject: I need some information on locking down pc's

    I have the need to lockdown a pc so tight that the only thing they can
    do is access a website, have access to media player and java runtime
    environment. Can anybody recommend anything or a way to do this on a
    machine.

    Thank You

    Michael Thaxton

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Dubber, Drew B: "RE: I need some information on locking down pc's"

    Relevant Pages

    • RE: I need some information on locking down pcs
      ... also a webcam, microphone, speakers, printer on these machines. ... The webpage that loads needs to have java and windows media player ... I need some information on locking down pc's ... have access to media player and java runtime ...
      (Focus-Microsoft)
    • Re: You have to be kidding - PowerPoint 2003
      ... Indeo 5.1 AVIs. ... > PPT 2003 actually tries to hand the video off to Windows Media Player if it ... > thinks the MCI Media Player can't play the files for some reason, ... >> I've experienced the same problem on three machines I've recently upgraded ...
      (microsoft.public.powerpoint)
    • Clicking on a WMV file in Explorer causes error...
      ... memory could not be "read". ... These files work on other machines, ... Windows Media Player is version 10. ...
      (microsoft.public.windowsxp.general)
    • Re: SBS 2003, XP Pro and NOD32
      ... Imon is enabled inNOD32, when you try to use Offer Remote Assistance ... It doesn't happen on all machines. ... It's not that anything is locking up. ... The next version of NOD32 will not include IMON. ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003, XP Pro and NOD32
      ... the RPC service crashes on the XP Pro machine and the system goes down ... for reboot. ... It doesn't happen on all machines. ... It's not that anything is locking up. ...
      (microsoft.public.windows.server.sbs)