RE: avoid using domain admin account installing programs

From: Andrew Shore (andrew.shore_at_holistecs.com)
Date: 05/27/05

  • Next message: Miguel Dilaj: "RE: Linking Password Length to Write-down probability"
    Date: Fri, 27 May 2005 08:59:59 +0100
    To: "Laurence Field" <laurence_field@yahoo.com>, <security-basics@securityfocus.com>
    
    

    I know I tend to recommend this a lot but in this case I can say hand on
    heart that I've done it on many occasions.

    Script logic is a login script tool which runs on the local workstation
    with elevated rights and will allow login scripts to do things users can
    not and, to my knowledge, there is no way for the user to gain elevated
    privilege during script execution.

    HTH

    www.scriptlogic.com

    -----Original Message-----
    From: Laurence Field [mailto:laurence_field@yahoo.com]
    Sent: 26 May 2005 07:01
    To: security-basics@securityfocus.com
    Subject: avoid using domain admin account installing programs

    Hi list

    I am observing a project that requires installing a HDD encryption
    software on 1000's of laptops. A team is currently researching various
    installation methods, and the easiest has been to give test users a user
    name and password (installer account) with instructions to log into the
    domain using this account. The acount has a log in script & very limited
    desktop & applications settings etc. ie. you can log on but run no
    programs, and do nothing on the desktop. This is for XP, 2000 & NT40
    clients, that will run a few required operations ie. scandisk etc., copy
    the setup file on local PCs, then run the setup program. After the setup
    is finished, the PC automatically reboots and the HDD software is then
    installed and complete. The problem is the account they propose to use
    to install this program is a domain admin account. An obvious risk is
    although users cannot do anything if they login to this account (except
    install the HDD software) savvy users can use this account to do an
     ything they want ie. net use etc.

    Does anybody have a better way to copy programs on a PC (NT40, XP), then
    run the program as a domain admin, without the user needing to know the
    domain admin account name & password? Group policy I am told in not an
    option as we have NT40 laptops.

    I am sure there are better way to securely install this software. Any
    tips, pointers, URLs would be appreciative.

    Thank you

    LF


  • Next message: Miguel Dilaj: "RE: Linking Password Length to Write-down probability"

    Relevant Pages

    • Re: Deploying Office 07 with Group Policy
      ... computer I tested it on took 30 minutes to install. ... the following script to the Computer Startup Script. ... REM Get ProductName from the Office product's core Setup.xml file. ... REM Set ConfigFile to the configuration file to be used for deployment REM ...
      (microsoft.public.office.setup)
    • Re: [opensuse] Editting PATH variable
      ... SuSEconfig script ... ... not knowing what you options you used to install ... If your unfamiliar with Bash a good book is 'Learning the Bash Shell' by ... For Java use editing the PATH variable is NOT required... ...
      (SuSE)
    • Re: trusted sites
      ... Script Debugging Problem ... checks whether the browser can handle Shockwave Flash so I suspect there may ... There is good information concerning all aspects of the Java situation here: ... Sun also offers an automatic download and install of the 1.4 Java plug-in ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: KB911280 update problem
      ... Microsoft is working on an amended patch which will address this issue. ... Microsoft advises anyone affected by this to not install the patch and to ... That script is broken by the patch. ... He said he could not write a bug report ...
      (microsoft.public.windowsupdate)
    • help with a home network jumpstart
      ... I have the blade running BIND 8 to serve DNS to the home network. ... Here's the output of the boot net - install: ... Using RPC Bootparams for network configuration information. ... Using begin script: install_begin ...
      (SunManagers)