RE: Executing app with admin privileges



That would certainly work but in the process it opens up a wide range of
security isses - the elevated privilages are available from throughout the
app which means that a file dialog could be used to launch other apps with
those privilages, access restricted files etc.

It's the easy way round it but not really the best.

Regards,

Andrew

-----Original Message-----
From: David Smith [mailto:nich95ds@xxxxxxxxx]
Sent: 21 July 2006 19:47
To: 'Dummy cerberus'; security-basics@xxxxxxxxxxxxxxxxx
Subject: RE: Executing app with admin privileges

Could the users use the Run As command and run the app as an administrator?
(Right-click the executable and click Run As.)

-----Original Message-----
From: Dummy cerberus [mailto:dummycerberus@xxxxxxxxx]
Sent: Thursday, July 20, 2006 3:56 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Executing app with admin privileges

Hello everyone,

I have come across with the following problem:

I work at the systems department, and we MUST host every stupid application
that is developed all over the organisation... most of the times with no
common criteria at all, neither with common sense.

Now, we have to install a client/server application, and it has been
developed in such a way, that the user who executes the client side, has to
have "local admin/advanced user" privileges on the desktop where he is
executing it...

There's no way to modify that application, so I wonder whether or not there
is a tool that could allow me to configure the system in such a way that all
the users could execute that application, without giving them "local
admin/advanced user" privileges for the whole system (only for that stupid
application).

I wonder if there's a way to acomplish that wether with AD policies or third
party tools (better if free ;-)

Thanks in advance, and best regards

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in Information
Security. Our program offers unparalleled Infosec management education and
the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------

--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.394 / Virus Database: 268.10.3/394 - Release Date: 7/20/2006


--
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.394 / Virus Database: 268.10.3/394 - Release Date: 7/20/2006



---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: APACHE$PRIVILEDGED
    ... The primary security on OpenVMS and on most other multi-processing operating systems is implemented via the memory management system and via what VAX calls the change-mode routines, via the Alpha SRM PALcode change-mode equivalent, or via what the IA-32 and IA-32e architectures refer to as the call gate. ... With OpenVMS constructs including device drivers )and user-written system services (UWSS; also known as privileged shareable images), these constructs operate in inner processor modes. ... One of the more hazardous situations for system security is a mixed environment; where there are resources shared between trusted and untrusted environments. ... Not only will the operation that requires privileges now be permitted, but other and potentially unintended operations can also be permitted. ...
    (comp.os.vms)
  • [UNIX] Bugzilla Multiple Vulnerabilities (SQL Injections, Privileges Escalation, Information Leak)
    ... Get your security news from a reliable source. ... user may retain privileges that should have been removed, ... Reference: ... secure bug, you can access the summary of that bug even if you do not have ...
    (Securiteam)
  • Re: Happy 10 years of continuous virus free computing on OpenVMS alpha 7.1
    ... OpenVMS provides an inherent security advantage over all the other ... advantage of OpenVMS brings it much closer to such a goal than any OS ... attaining higher mode privileges or services for which a process was ... currently used University-level texts on OS Design. ...
    (comp.os.vms)
  • Re: Microsoft finally acknowledges the security drumbeats
    ... not part of the operating system. ... If the security problems go ... > IIS full administrator privileges. ... If processes like IIS running with admin priveleges is the ...
    (comp.security.misc)
  • Re: Microsoft finally acknowledges the security drumbeats
    ... not part of the operating system. ... If the security problems go ... > IIS full administrator privileges. ... If processes like IIS running with admin priveleges is the ...
    (comp.security.unix)