Re: How effective is a Limited User Account?



On Nov 27, 4:00 pm, Niniel <Nin...@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Look, the bottom line is this:

Running a limited account does not mean you are absolutely safe. Having an
army of AV and ASW programs does not mean you are absolutely safe.

The fact of the matter is that software has bugs. These bugs can be found
and exploited.
Then there is software where the security holes are actually features - see
ActiveX.

I'm well aware of that but thanks. Personally, I don't expect
infallibility in security setups. But I do try to understand the
limitations of any given method.

NoScript is a tool to protect you from browser-based attacks - specially
prepared web sites that use JavaScript and other scripting for phishing
attacks, and other attacks. Or even badly programmed legitimate sites that
allow hackers to insert and execute code. (It's quite scary. I recently read
an article on a German computer site where an editor had checked out a bank's
site and without trying too hard found multiple ways for cross scripting
attacks to succeed).

I'll give it a try, thanks for the tip.

Also, if you browse down to the thread about SAM databases you'll see that
the windows security settings reside in memory unencrypted, and that there
are tools who can read them. That entire database is very badly protected, it
can be easily cracked and altered (which sometimes works in your favour, e.g.
if you have to break into your own box after malware took over - check out
UBCD4Win).

Aha! And so I finally perceive the true limitation of permissions: it
can be cracked! I thought this was much harder to do.... After reading
that post and investigating a little further it turns out that
cracking the permissions database is a matter of seconds. From the
little I read, you must have physical access to the local machine
(which is not possible to the Internet attacker) but I get the idea.
In relation to viruses cracking permissions I came across this
Microsoft Security Bulletin:
http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx
In the recent past, I think it was the most serious flaw where a user
would get infected simply by hovering the mouse over a malicious
webpage. Of the seven vulnerabilities associated with this flaw, FIVE
were "Elevation of Privilege", meaning: bypassing limited user
accounts!

My conclusion is this. Limited User Accounts are very effective in
deterring viruses installing on your system. They are so effective
that the simple elevation of privileges is a legitimate target for
hackers. Limited User Rights is another hoop hackers have to jump
before taking control.
.



Relevant Pages

  • Re: account locking after 3 unsuccessful login attempts
    ... unlocking many accounts. ... A security issue would be if you let the brute force attacker to ... Then they can use that for privilege escalation attacks etc. ... Exchange users - they will log onto the network using one account, ...
    (microsoft.public.isaserver)
  • Re: Integrated security - why not?
    ... Let me explain why we seldom use Integrated Security for Internet asp.net ... how could we setup accounts for them? ... !server to the public network with services such as SQL Server (remember SQL ... The DC at the ISP is not for our own use. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: absolutepoker news
    ... The chances of uncovering any further cheating at any other site are probably slim to none. ... However, knowing poker players as I do, my guess is most Absolute customers will stay right where they are. ... The statement acknowledges the security breach within Absolute's system that allowed information about opponents' hole cards to be transmitted to several suspect accounts, and confirmed that the hand log released accidentally to Marco 'CrazyMarco' Johnson, the runner-up in the suspect tournament, did in fact highlight the security flaw that allowed the site to be compromised. ...
    (rec.gambling.poker)
  • Re: absolutepoker news
    ... The chances of uncovering any further cheating at any other site are probably slim to none. ... However, knowing poker players as I do, my guess is most Absolute customers will stay right where they are. ... The statement acknowledges the security breach within Absolute's system that allowed information about opponents' hole cards to be transmitted to several suspect accounts, and confirmed that the hand log released accidentally to Marco 'CrazyMarco' Johnson, the runner-up in the suspect tournament, did in fact highlight the security flaw that allowed the site to be compromised. ...
    (rec.gambling.poker)
  • Choosing secure passwords - Feedback solicited
    ... Choosing secure passwords is the most important thing you can do to ... secure your accounts and avoid the headaches of a security breach. ... that will help you remember the PIN. ...
    (comp.security.misc)