Re: preventing run-as option



Hello Vijay,

Not only you, but majority of people working in a domain based environment are facing this problem. Windows however provides this facility to block "Run as" utility. Here is the way :

1. On the domain controller go to command prompt & type "dsa.msc".

2. On the OU where the User's desktop resides, open the Group Policy editor & navigate to Computer Configuration > Windows Settings > Security Settings > Software Restriction Policies

3. Right-click on this node and select "New Software Restriction Policies" (This creates a default set of Software Restriction Policies that you can now configure further)

4. To prevent the runas.exe command from executing on the computers affected by this GPO, right-click on "Additional Rules" and select "New Path Rule"

5. Now type the path to runas.exe (C:\Windows\system32\runas.exe) and make sure the policy is set to "disallowed".

Once Group Policy has been updated during its next refresh cycle (or force an immediate update with gpudate /force) users on the affected machines won't be able to use the Run As command to start programs using alternate credentials.
However, if you prefer to apply this policy to specific users instead of computers, use a GPO linked to an OU where the user accounts reside and configuring Software Restriction Policies using User Configuration instead of Computer Configuration, such as:

User Configuration > Windows Settings > Security Settings > Software Restriction Policies

For non-domain environment, I mean for standalone Windows XP or Windows Server 2003 machines in a workgroup environment Group Policy isn't available. However, you can disable Run As by tweaking the Registry instead. Simply use Regedit.exe to locate the following key on each machine:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

Then create a new DWORD value named HideRunAsVerb and assign it a value of 1.

And you are done with it.

Nikhil Wagholikar
CEH

Security Analyst
NII Consulting
www.niiconsulting.com
------------------------------------
Comprehensive Security Assessment Software
http://www.niiconsulting.com/products.html
------------------------------------

This message may contain privileged and confidential information and is
solely for the use of intended recipient. If you are not the intended
recipient you should not disseminate, distribute, store, print, copy or
deliver this message. Please notify the sender immediately by e-mail if you
have received this e-mail by mistake and delete this e-mail from your
system.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: lock down personal Win XP workstation
    ... Description of the Guidance for Securing Microsoft Windows XP Systems ... > console and apply the predefined security template called hisecws.inf. ... > EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... > The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • RE: Please help: spyware in my machine...
    ... 1)Did you try remove these in windows security mode? ... Sent from the Security Basics mailing list archive at Nabble.com. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
    (Security-Basics)
  • Re: ask your advice!
    ... Assuming that your TS is setup using "Full Security" compatibility ... server if you need more security. ... You can consider using Software Restriction Policies to lock it ... Administrator Accounts and Selected Users in Windows Server 2003 ...
    (microsoft.public.windows.terminal_services)
  • lock down personal Win XP workstation
    ... Sometimes I am forced to use Windows XP. ... Additionally I use "Security Configuration and Analysis" MMC ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence in Information Security. ...
    (Security-Basics)
  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)