Re: Separation of applications under NT

From: Ron Ruble (raffles2@att.net)
Date: 03/07/03

  • Next message: Rich marquette: "Re: net share"
    From: "Ron Ruble" <raffles2@att.net>
    Date: Thu, 6 Mar 2003 20:23:48 -0500
    
    

    "BigBart" <bigbart5@hotmail.com> wrote in message news:OzP9a.34$ND3.12347@newsfep2-gui...
    <snip>

    > So what if the two apps actually communicate (exchange messages)
    > between each other? Is it safe to say that because they are both
    > running on the same machine, and are 32-bit, App_B (containing less
    > sensitive information) cannot get at info held in App_A's protected
    > memory space?

    Messaging is irrelevant. Messages are marshaled
    (copied) from one address space to the other by
    the OS.

    App_B can only access the information App_A
    makes available to it. Certainly, the writer of
    App_A may choose to expose sensitive information
    carelessly, but this would be a defect in App_A,
    not a feature of the OS. It should be noted that
    App_A is not rigidly protected against App_B
    in a normal situation, where the user has
    Administrator privileges (or Power User
    privileges). Both accounts have the right to
    open a process token. But an ordinary
    user account does not.

    This is a _very_ involved subject; if you are
    really interested, I would direct you to "Programming
    Applications For Windows", by Jeffrey Richter
    and Windows NT Server Unleashed, for
    information on NT security.


  • Next message: Rich marquette: "Re: net share"

    Relevant Pages

    • Re: Veterans Affairs warns of massive privacy breach
      ... sensitive information about veterans and their families had been ... Thank you once again for pointing out to the world how Windows security can ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers. ...
      (alt.computer.security)
    • [Full-disclosure] CAU-2007-0001: Window Transparency Information Disclosure
      ... Windows made from silica or plastics ... observing externally-facing information through the window. ... Sensitive information stored on whiteboards, cork-boards, calendars, ...
      (Full-Disclosure)
    • Re: complete information deletion wanted
      ... > I am selling my old computer and want to strip all of the ... > sensitive information from my hard drive, windows 98se. ...
      (microsoft.public.security)
    • Re: complete information deletion wanted
      ... Doug wrote: ... > sensitive information from my hard drive, ... Your computer isn't worth much without an OS, so if you have a recovery ... Microsoft MVP for Windows Security ...
      (microsoft.public.security)
    • Re: CD-ROM access
      ... impersonation to run the ASP.NET application under my admin user account. ... Computer Configuration, Windows Settings, Security Settings, Local Policies, ... Look in the right pane for Devices: Restrict CD-ROM access to locally logged ... > no problem when we log on with Administrator privileges and run our test ...
      (microsoft.public.windowsxp.security_admin)