Re: Disable Exe and Other File Types from being run/viewed

From: Arkane (Arkane_at_discussions.microsoft.com)
Date: 03/21/05

  • Next message: nbullock: "Audit Failed Logon Attempts"
    Date: Mon, 21 Mar 2005 14:01:03 -0800
    
    

    Something just to note - the USB drives/sticks are all FAT32 filesystems, so
    xACL modification would fail on them, even if my script was able to detect
    when they were plugged in.

    One of these 'viruses' that intercepts all .exe execution and such would be
    good for this - if only they weren't destructive and were configurable...
    like a low-level I/O driver of sorts... am sure other people have had similar
    problems.

    Hopefully the file-association idea will work and will also allow us to deal
    with a few other nuisance filetypes - as the users can't "run" files unless
    they double-click - we have no media players or anything so they can't open
    the files directly... which as far as I'm concerned, kills many problems with
    a single solution... the trick will be making the batch file/parser-thing
    intelligent enough to provide configuration and basic access control (so
    admins/staff can run whatever w/o interruption).

    "Steven L Umbach" wrote:

    > From your options your best bet is probably to populate the "only allowed"
    > applications list. Programs such as filemon from SysInternals can help you
    > track down which executables are used for an application. If you don't want
    > them to have access to USB drives, consider disabling USB in the cmos for
    > the computer and password protecting the cmose settings which is not
    > foolproof but could be a major barrier to access the computers cmos. Also
    > keep in mind that Windows 2000 computers can not use Software Restriction
    > Policies. --- Steve
    >
    >
    > "Arkane" <Arkane@discussions.microsoft.com> wrote in message
    > news:D94B7FDA-7364-4D10-B06B-691378EAF7CE@microsoft.com...
    > > Here's the scenario we have :
    > > We have several hundred W2K SP4 PCs, several hundred WXP Pro SP1a PCs.
    > > Our network is NT4 but we will migrate to AD in-time.
    > >
    > > I know that with AD Software Policies we can stop users from running
    > > applications using policies - however while we currently don't have this
    > > capability, does anyone have a good equivalent?
    > >
    > > The "Don't Run Windows Programs" POLEDIT policy is not feasible as we'd
    > > have
    > > to list vast arrays of files as it does not accept masks.
    > >
    > > Using "Only allow following Windows Programs" is equally bad as the range
    > > of
    > > applications we use really is vast, to track down all of their component
    > > .exe
    > > files and other components (that must be able to be run) would be a
    > > massive
    > > task.
    > >
    > > This restriction, however applied - must work for Network and Removable
    > > Drives - now if there's a setting I can put on Removable Drives (Like No
    > > Exec
    > > on Linux filesystems), then I'd happily do that via a security policy.
    > >
    > > I'm at my wits end with this one as we use a 'sweeper' which erases these
    > > files from our servers, yet the users can still plug in their USB memory
    > > sticks and run .exe files or whatever that may be on them. I work at a
    > > school
    > > so security is something that's better off prevented first (stop them
    > > doing
    > > something at the start), rather than run around and try and catch it
    > > later.
    > >
    > > Any thoughts?
    >
    >
    >


  • Next message: nbullock: "Audit Failed Logon Attempts"

    Relevant Pages

    • Re: Questions about Migrating from workgroup environment to new SBS2K3 domain
      ... Once I've copied all the docs across via the USB and joined the computers to ... logon) to their documents folder in the Company share? ... >> manually move the \\workstation3\Docs folder to the SBS server first? ...
      (microsoft.public.windows.server.sbs)
    • Re: wanted: convenient USB switch for M/K combo
      ... convenient USB switch that allows me to use a single wireless USB ... keyboard/mouse combination to operate both computers. ... I currently have a 'Belkin 2x1 USB Peripheral Switch', ...
      (microsoft.public.windowsxp.hardware)
    • Re: Network setup
      ... I want to use a USB Cable to connect the units as ... I would consider an internet setup to make ... You can install a wireless USB adapter on each of the laptops, ... be able to both share folders and internet connectivity between all 3 computers. ...
      (microsoft.public.windowsxp.network_web)
    • Re: This Newsgroup Is Now Crap
      ... Firewire is dying, nobody hardly uses it. ... phased out of portable devices and computers. ... But I do see eSATA ports on the rise. ... And when USB ...
      (comp.sys.mac.advocacy)
    • Re: Hi-speed USB device plugged into non-hi-speed USB hub
      ... only problem is that there is no advanced tab in the device ... manager. ... -Intel82801AA USB Universal Host Controller ... The computers that are affected by this are running Windows XP ...
      (microsoft.public.windowsxp.hardware)

    Loading