Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: Prevent users/admin from installing softwares.

Subject: RE: Prevent users/admin from installing softwares.
Date: Wed, 28 Feb 2007 15:03:17 -0500
But if a user unjoined the domain, they would not be able to log in to
the machine unless they knew the "local" administrator account password.
A domain account would not be able to log on.



-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
On Behalf Of Liu, David
Sent: Tuesday, February 27, 2007 9:21 PM
To: Devin Ganger
Cc: focus-ms@securityfocus.com
Subject: RE: Prevent users/admin from installing softwares.

So here's an interesting one based on the last comment: 

By default all users in AD shd be able to join up to 10 machines without
any special privileges. How do you stop users from unjoin/rejoin
machines, even in an environment where explicit delegated rights have
been given to only a specific group of people to add/delete/move machine
accts?


-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
On Behalf Of Devin Ganger
Sent: Friday, February 23, 2007 5:26 PM
To: Gregory N Pendergast/AC/VCU; Rocky
Cc: focus-ms@securityfocus.com
Subject: RE: Prevent users/admin from installing softwares.

Let's not forget how easy it is to circumvent the application of Group
Policy:

1) Unjoin the computer from the domain, reboot, install your software,
rejoin.
2) Reboot the computer and remove the network tap so GPOs aren't pulled
down. Install your software. Put the network tap back in.

--
Devin L. Ganger, Exchange MVP      Email: deving@3sharp.com
3Sharp LLC                         Phone: 425.882.1032
14700 NE 95th Suite 210             Cell: 425.239.2575
Redmond, WA  98052                   Fax: 425.702.8455
(e)Mail Insecurity: http://blogs.3sharp.com/blog/deving/


-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
On Behalf Of Gregory N Pendergast/AC/VCU
Sent: Thursday, February 22, 2007 1:53 PM
To: Rocky
Cc: focus-ms@securityfocus.com
Subject: Re: Prevent users/admin from installing softwares.


To my knowledge, there's no built-in way to directly prevent the
administrator from installing software. However, you can use Software
Restriction Policies (Group Policy Editor > Computer Configuration >
Windows Settings > Security > Software Restriction Policies)  to limit
software execution so that software only runs from a set of predefined
paths.  By limiting the paths from which software can execute, you may
be able to severely-limit an Administrator's ability to install
software.
However, there are obvious problems with this:

1) If you're setting this in Local Group Policy (as opposed to
Domain-level), the Local Administrator can easily remove the Software
Restriction Policies
2) The obvious "hack" is to copy your installation file to a path where
software is permitted to execute, then to install said software to a
permitted location. Whether this is an acceptable risk depends on the
cleverness of your administrators and the sensitivity of your systems.

Beyond this, I don't personally know of a solution that doesn't involve
3rd party software.

Good luck,
Greg Pendergast

-----listbounce@securityfocus.com wrote: -----


To: focus-ms@securityfocus.com
From: Rocky <pixscreenpoint@gmail.com>
Sent by: listbounce@securityfocus.com
Date: 02/22/2007 07:51AM
Subject: Prevent users/admin from installing softwares.

Hey Guys,

Is there a way to restrict everyone including adminisrator rights from
installing softwares in xp pro? It should be done on registry or gpedit?

we don't want to use 3rd party softwares like winguard.

Thanks a lot!


<Prev in Thread] Current Thread [Next in Thread>