Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Executing app with admin privileges |
|---|---|
| Date: | Thu, 27 Jul 2006 13:56:24 +0200 |
Hi David,
Sure giving users the admin password is not a good idea but if they become a local administrator ie local to their box, what damage can they do to the domain as they only have full control over their box. I thinking along the lines that a there are different types of admins in the AD structure so perhaps giving a user admin priveleges on a read only link is fine as they will not have sufficient admin privileges to edit anything outside of their box? Of course auditing would need to be stepped up to monitor for 'admins' nefarious activities with a strict warning of 'you will be fired if you admin outside of your box, even unknowingly'.Additionally, you can set the properties of the program to always "RunAs", then all the user would have to do is enter in the proper password....
--------------------------------------------------------------------------- This list is sponsored by: Norwich University
http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: How to stop Admins from sniffing ?, Weir, Jason |
|---|---|
| Next by Date: | Re: Deny client from obtaining IP address, chris |
| Previous by Thread: | RE: Executing app with admin privileges, Dixon, Wayne |
| Next by Thread: | Re: Executing app with admin privileges, Raoul Armfield |
| Indexes: | [Date] [Thread] [Top] [All Lists] |