Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: First vulnerabilities in the SP2 - XP ?...
From: Robert Decker <rdecker () esbsystems com>
Date: Wed, 18 Aug 2004 23:57:53 -0400

As a work around to the issue - although not to easy to configure for the home user,

I would think if you have users who are ignorant, gullable, or just plain stupid - a windows sysadmin might consider a GPO in AD with one or more of the following policies:

User Configuration --> Administrative Templates --> System --> Prevent Access to Command Prompt

User Configuration --> Administrative Templates --> System --> Run Only Allowed Windows Applications

User Configuration --> Administrative Templates --> System --> Don't Run Specified Windows Applications

Another huge advantage would be the proper implementation of the following in an AD GPO:

Configure some Software Restriction Policies in User Configuration --> Windows Settings --> Security Settings --> Software Restrictions

and if possible, couple it with certificates. (although, i'm not too familiar with this one)

Computer Configuration --> Windows Settings --> Security Settings --> Local Policies --> Security Options --> System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]