lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <122120051339.6019.43A95B28000093A90000178322064246139C0A020708D20D@comcast.net>
Date: Wed Dec 21 13:40:12 2005
From: b.hines at comcast.net (b.hines@...cast.net)
Subject: Bypass user GPO in Windows Xp / 2003

Espen,

Take a look at the hardening guides at http://www.cisecurity.org/ . I also believe there is a setting in the Security policy manager for just this item runas.  By removing runas capabilties, and then controling file access via file privilages should correct this.

b

-------------- Original message -------------- 
From: Espen <espen@...en.mine.nu> 

> During some security testing in a high security enviorment - I 
> discovered that by using the "run as" or "the runas /noprofile" I could 
> bypass user GPO settings completely. 
> 
> I e-mailed the security mail at Microsoft about it - and they confirmed 
> that they had reproducedc the behavior - but said that the user 
> restrictons where not ment as security settings - but just to stop the 
> user from messing up their enviorment !?!?!?! 
> 
> To reproduce it: 
> 
> Set up a domain with strict security settings. Eg. Software restritions 
> policies, hide local drives, remove "run", disable cmd.exe and so on. 
> 
> Log on to an XP computer in that domain - make a link to cmd.exe - 
> select "run as" on that link. 
> 
> Logon with another user in the same domain - with the same restrictions 
> - you'll see that the GPO's will not be loaded for that user. 
> 
> Maybe not a big deal - but I thought you should know...... 
> 
> _______________________________________________ 
> Full-Disclosure - We believe in it. 
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html 
> Hosted and sponsored by Secunia - http://secunia.com/ 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20051221/fb6c43a8/attachment.html

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ