Re: preventing run-as option



On Friday 06 October 2006 02:16, vijay shetti wrote:
hello all!!!

In my company we have domain based environment...In our proxy access
permissions are given based on the name of the user and only few users
are given rights to view a set of sites like email sites...

For example employee A is given the permission and B does not have
that.What B does is that he runs Internet explorer using run-as option
and gives A's credentials...This way he is able to surf websites that
he is not given permission to.

Is there any option using which I can disable run-as option...


From your description, your problem is not runas...

Your problem is that user B has user A's credentials. That is the security
breach.

Prevent any user from having any other user's credentials. Problem solved.
Perhaps by instituting negative consequences for giving your credentials to
another user...??

--
Clinton E. Troutman

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: preventing run-as option
    ... should be a policy issue. ... For example employee A is given the permission and B does not have ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
    (Security-Basics)
  • RE: preventing run-as option
    ... For example employee A is given the permission and B does not have ... that.What B does is that he runs Internet explorer using run-as option ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • Re: Access denied. You do not have permission to perform this action or access this resource.
    ... message when you try to connect to a Windows SharePoint Services Web ... I have brand new credentials on the server, not the "same" name as the ... Please let me know if other users with administrator permission can ... If you change the site owner to another user with administrator ...
    (microsoft.public.sharepoint.windowsservices)
  • RE: preventing run-as option
    ... For example employee A is given the permission and B does not have ... Is there any option using which I can disable run-as option... ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • Re: preventing run-as option
    ... For example employee A is given the permission and B does not have ... that.What B does is that he runs Internet explorer using run-as option ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence in Information Security. ...
    (Security-Basics)