Re: backworm - way to keep safe



It depends. There are a couple of technologies available through
group policy for limiting what software may run. The older, intoduced
in Windows 2000 will not be effective as it only controls what may be
run from within Explorer. The newer, introduced in the XP era is
Software Restriction Policy (aka SAFER). If used as completely
and effectively as you imply (which is not simple to do) then you may
have a chance that SAFER would protect your machines. Consider
though, if a virus is making use of a flaw in a component of the OS,
or of IE, it is likely that your definitions in SAFER would not stop it as
those OS or IE components are likely allowed to run. On the other
hand, if you have used SAFER to prevent all scripts from running
unless you have cryptographically signed them and the exploit does
depend on a script then you are likely protected.
In other words, your question is unanswerable in the abstract.

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
"kevin bailey" <kbailey@xxxxxxxxxxxxxxxxxxx> wrote in message
news:drdm02$l3u$1$830fa7a5@xxxxxxxxxxxxxxxxxxx
> if the domain policy means that users are only allowed to run programs
> from
> a limited list of programs (set up using the gpedit.msc) does this mean
> that we are safe(r) from the blackworm.
>
> indeed, does this mean that most viruses would fail to run?
>
> thanks,
>
> kevin


.



Relevant Pages

  • Re: login script not working for win2k
    ... I am currently only delivering logon scripts with the default doamin policy. ... > Are the Windows XP and Windows 2000 clients located at different sites? ...
    (microsoft.public.windows.group_policy)
  • Windows Shortcut Keys and "ALT+TAB" not working because of GPO
    ... We've got an issue with a machine policy which prohibits us of using Windows ... Deny access to this computer from the network Support_388945a0, ... Policy Setting ...
    (microsoft.public.de.german.windowsxp.gruppen.richtlinien)
  • Re: GP errors
    ... Then later shutdown second one and start the first one. ... machine (MTCCSAPROUTER) to the domain and those errors are not coming. ... The policy for which it is giving access denied error is the Default ... Windows cannot query for the list of Group Policy objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: What program is used to write events to the event log??????
    ... The intent of Safer is for it to be applied from AD in GPOs. ... that they are refteshed by the sce policy engine. ... > registry files is that while apparently the restrictions are aplied...you ... >>> issue....whenever there is an exe being started it normally writes this ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Important information about XP SP2 .ADM Files
    ... The Windows 2000 fix is available here: ... >> your attention to an important issue related to Group Policy. ... >> an important issue around the use of the .ADM files we ship with XP SP2. ...
    (microsoft.public.win2000.group_policy)