Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

avoid using domain admin account installing programs

Subject: avoid using domain admin account installing programs
Date: 26 May 2005 06:01:25 -0000


Hi list

I am observing a  project that requires installing a HDD encryption software on 
1000's of laptops. A team is currently researching various installation 
methods, and the easiest has been to give test users a user name and password 
(installer account) with instructions to log into the domain using this 
account. The acount has a log in script & very limited desktop & applications 
settings etc. ie. you can log on but run no programs, and do nothing on the 
desktop. This is for XP, 2000 & NT40 clients, that will run a few required 
operations ie. scandisk etc., copy the setup file on local PCs, then run the 
setup program. After the setup is finished, the PC automatically reboots and 
the HDD software is then installed and complete. The problem is the account 
they propose to use to install this program is a domain admin account. An 
obvious risk is although users cannot do anything if they login to this account 
(except install the HDD software) savvy users can use this account to do an
 ything they want ie. net use etc. 

Does anybody have a better way to copy programs on a PC (NT40, XP), then run 
the program as a domain admin, without the user needing to know the domain 
admin account name & password? Group policy I am told in not an option as we 
have NT40 laptops. 

I am sure there are better way to securely install this software. Any tips, 
pointers, URLs would be appreciative.  

Thank you

LF

<Prev in Thread] Current Thread [Next in Thread>