Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 09, 2004

Downgrading Application Privileges; More Spyware Solutions

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

In the August 11 edition of this newsletter (at the URL below), I wrote about two tools, PrivBar and MakeMeAdmin, developed by Aaron Margosis. PrivBar is essentially an add-on to Microsoft Internet Explorer (IE) and Windows Explorer. When you install PrivBar, a toolbar is added to both those applications that shows what security context each browser is running under. The toolbar displays the domain and username as well as the group that the account belongs to. The toolbar is color-coded to grab your attention when you run an instance under a highly privileged account, such as an account in the Administrators group.

http://www.windowsitpro.com/Article/ArticleID/43652/43652.html

MakeMeAdmin is a command-line script for Windows that can help you run applications in a more privileged security context. MakeMeAdmin automates the process of using the RunAs command to elevate your privileges. The script performs three actions: Adds your current user account to the local Administrators group, launches a command shell and any other application you want to run, and removes your account from the local Administrators group.

MakeMeAdmin is a handy tool, particularly for those of you who don't want to expose your systems by performing all your tasks while logged on as a member of the Administrators group. But what about those instances in which you're logged on as an administrator (out of need) but don't want to run all your applications in the security context of an administrator account?

Michael Howard (senior security program manager at Microsoft and coauthor of the book "Writing Secure Code") developed a handy tool, DropMyRights, that can help in such instances, provided you use Windows Server 2003 or Windows XP. These two OSs support the Safer API. According to the Microsoft Developer Network (MSDN), "Safer API functions provide any application that launches programs from external sources the ability to query security policy for approval before an executable is launched. The Safer API functions can be called before loading and running an executable or active content. . . . applications where the Safer API is useful include applications that handle attachments (such as mail clients and instant messengers that can transfer files) and script interpreters."

http://msdn.microsoft.com/library/en-us/secmgmt/security/safer.asp

You can use DropMyRights to launch any application under the security context of a nonadministrative user, a restricted user, or an untrusted user. It's simple to install and operate by using a few command-line switches, and you can easily establish shortcuts to launch applications quickly. A sample DropMyRights command to launch IE as a typical user (the default, with no command-line options specified) is

c:\tools\dropmyrights "c:\program files\Internet Explorer\iexplore.exe"

To download a copy of DropMyRights and even see the source code, go to "Browsing the Web and Reading E-mail Safely as an Administrator" at

http://msdn.microsoft.com/library/en-us/dncode/html/secure11152004.asp

Last week, I wrote about enterprise-enabled antispyware solutions. I received numerous responses, and based on those responses, I'd say many of you really needed that sort of consolidated resource! Several people also wrote to tell me about a few other solutions that I didn't include on the list. I've now updated the article on the Web site with four additional products: DynaComm i:scan, Prevx Enterprise, Kaspersky Anti-Virus SuperSecure Database add-ons, and GFI DownloadSecurity for ISA Server, which integrates with the Kaspersky solution. So now a total of 18 solutions are listed.

I also moved the McAfee Anti-Spyware Enterprise Edition Module to the list of soon-to-be-released products because it's actually not available yet. And I added a link to another good list of standalone and enterprise-enabled solutions, which is hosted by one of our readers in the Netherlands. So if you're looking for enterprise-enabled antispyware solutions, re-read the article on the Web to get all the updated information.

http://www.windowsitpro.com/Article/ArticleID/44624/44624.html

Until next time, have a great week.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement