lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <43A895FA.3020701@espen.mine.nu>
Date: Wed Dec 21 04:02:01 2005
From: espen at espen.mine.nu (Espen)
Subject: Bypass user GPO in Windows Xp / 2003

During some security testing in a high security enviorment - I 
discovered that by using the "run as" or "the runas /noprofile" I could 
bypass user GPO settings completely.

I e-mailed the security mail at Microsoft about it -  and they confirmed 
that they had reproducedc the behavior - but said that the user 
restrictons where not ment as security settings - but just to stop the 
user from messing up their enviorment !?!?!?!

To reproduce it:

Set up a domain with strict security settings. Eg. Software restritions 
policies, hide local drives, remove "run", disable cmd.exe and so on.

Log on to an XP computer in that domain - make a link to cmd.exe - 
select "run as" on that link.

Logon with another user in the same domain - with the same restrictions 
- you'll see that the GPO's will not be loaded for that user.

Maybe not a big deal - but I thought you should know......

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ