Re: Windows Management Instrumentation

From: Torgeir Bakken (MVP) (Torgeir.Bakken-spam_at_hydro.com)
Date: 01/22/04


Date: Thu, 22 Jan 2004 03:45:46 +0100

shadowriath@hotmail.com wrote:

> WMI brings up system information inclueding username, this
> can even be done remotely. A hacker with the right app
> can open this service on your system and have more then
> half info he needs to log in.
>
> 1: Is there a reason to have this service running at all?

Yes, the system is using it for lot of things.

> 2: If it is required to run the system for some strange
> reason, is there a setting to disallow any veiwing of it?

WMI is a DCOM application, and you should do the lockdown on the DCOM side
of WMI:

Securing Remote Management with WMI
http://www.mcpmag.com/columns/article.asp?EditorialsID=381

COM Security in Practice
http://msdn.microsoft.com/library/en-us/dncomg/html/msdn_practicom.asp

--
torgeir
Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of the 1328 page
Scripting Guide: http://www.microsoft.com/technet/scriptcenter


Relevant Pages

  • Re: logoff.vbs
    ... > I can log people off remote workstations using WMI, ... Subject: ImpersoantionLevel other than impersonate ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.scripting.vbscript)
  • Re: managing shared folders with wsh
    ... The WMI option is exactly what I was looking for. ... >> I can't set permissions on the share. ... > Local or remote directories ... > torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.scripting.wsh)
  • Re: script registry editing
    ... > of remote machines. ... WMI and it's StdRegProv class: ... Documentation in regobj.doc and a remote registry example in registry.vbs ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windows.server.scripting)
  • Re: Copy into remote machine
    ... > I would like that destination path means for example drive E:\ on a remote machine, one of the hundreds in the domain. ... > maybe i'd have to first map drive as drive$ to remote computer? ... Using WMI isn't very good for this task, ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windows.server.scripting)
  • Re: Group policy results wizard - Access denied
    ... Simplify Group Policy Troubleshooting with the NEW GPExpert ... I have searched WMI and RSOP issues on the net until I am blue in the ... can get any kind of remote WMI access to the system? ...
    (microsoft.public.windows.group_policy)