Re: Any Way to Stop Service Start and Stop Over Network?



Hello Will,

To disable services from being started (T), stopped (O), or paused (P)
from the network, download SubInACL and run the following command:

SubInACL /Service \\%computername%\(service name, like Alerter) /
Deny=Network=TOP

People with appropriate permissions will still be able to restart the
service when logged onto the console or RDP. They will not be able to
restart the service manually, though they will be able to view its
status.

Hope this helps,

J Wolfgang Goerlich


Related Links:

Download SubInACL
http://www.microsoft.com/downloads/details.aspx?familyid=E8BA3E56-D8FE-4A91-93CF-ED6985E3927B&displaylang=en

Special identities: Network
http://technet2.microsoft.com/windowsserver/en/library/54fb39d6-81e2-42c2-ac23-7c0f4dc81a111033.mspx?mfr=true



On Sep 28, 2:19 pm, "Will" <westes-...@xxxxxxxxxxxxxx> wrote:
If a Windows XP or 2003 computer has File & Printer Sharing turned on, is
there any way to prevent it from acting on service start and stop control
messages it receives over the network? I want service start and stop to be
a console action only.

Assuming NetBIOS over TCP is turned off on the network adapter that has File
& Printer Sharing turned on, will service and stop messages only be possible
over port 445, or are there other channels to accomplishing the same thing?

If there is no way to control this with Microsoft's group policy or other
security settings, then is there any third party product that would at least
monitor for this condition and send out notifications if any attempt to
start or stop a service over the network takes place?

--
Will


.



Relevant Pages

  • Re: Any Way to Stop Service Start and Stop Over Network?
    ... from the network, download SubInACL and run the following command: ... A common infection method for trojans is to write a payload to a file system ... and send a service start command, to get the code to run in SYSTEM context. ...
    (microsoft.public.security)
  • Re: MCE 2005 Xbox 360 Extender PC Setup Cannot find Xbox 360 on Ne
    ... the only Network Service I have enabled is the "Internet Gateway ... Gateway Device Discovery and Control Client), the Internet Gateway Device ...
    (microsoft.public.windows.mediacenter)
  • Re: Towards a theory of the semiotic mind-body link
    ... Let's consider some crude chess heuristics. ... of pieces, control of center, mobility, pawn structure ... So if the network ... what states it happened to see in the games it played. ...
    (comp.ai.philosophy)
  • I started network trouble at work
    ... We used the corporate XP server network to connect 2 XP computer ... work stations (front-end to the control network) to each other. ... the corporate network and server allowed the ... our network vendor came in today to update our ...
    (microsoft.public.windowsxp.security_admin)
  • Re: restrict software installation
    ... > Is there some similar principle in Windows? ... > emphasis on 'minimize network transfers'. ... > Perhaps you can control this via some scripting stuff? ... > just about any scripting language there is (XML objects if everything ...
    (Focus-Microsoft)