Impersonation issue with PsExec ?

From: Yuri Palagin (ypal_at_utc.ru)
Date: 02/20/04


Date: Fri, 20 Feb 2004 11:58:49 +0400

Hi there.

I want to enable some users to use PsExec utility (www.sysinternals.com) for
executing commands remotely on some servers, but the problem is, PsExec has
a key "-s" that lets "run remote process in the System account"(as the help
goes). My testing shows that using "psexec \\server -s cmd" allows any user
to get access to do just anything on servers with the Admin$ share on. OK, I
can disable the Admin$ share, but this disables using PsExec at all. I got a
hunch that it has something to do with restricting the right to impersonate,
but I've no idea where I can find it. Can anyone give me a lead?

I'm not stuck with PsExec, so maybe there is another way to allow remote
command-line to only the chosen, is there?

Thanks for any ideas,

ypal



Relevant Pages

  • Re: File Copying
    ... workstation would would copy the files to it's own RAM when the files should ... be copied between the servers. ... So, I could try using psexec to run the batch on one of the servers, but ... Having the file copied to local RAM is so old ...
    (microsoft.public.windows.server.networking)
  • Impersonation issue with PsExec ?
    ... executing commands remotely on some servers, but the problem is, PsExec has ... to get access to do just anything on servers with the Admin$ share on. ... but this disables using PsExec at all. ...
    (microsoft.public.win2000.general)
  • Impersonation issue with PsExec ?
    ... executing commands remotely on some servers, but the problem is, PsExec has ... to get access to do just anything on servers with the Admin$ share on. ... but this disables using PsExec at all. ...
    (microsoft.public.win2000.networking)
  • Re: how to create local user accounts on W2k via script?
    ... change myLocalGroup and domain\username to whatever you need. ... >>the OS and apps on several servers every week or so. ...
    (microsoft.public.windows.server.scripting)
  • Re: caspol
    ... Unter Admin kein Problem, als normaler User reichen die Rechte nicht. ... Security - Schicht für der des Betriebssystems ist. ... PsExec arbeitet AFAIK so, dass auf dem Remoterechner ein temporäres ...
    (microsoft.public.de.german.entwickler.dotnet.framework)