Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Disable commao and and batch files

Status
Not open for further replies.

torledo

IS-IT--Management
Oct 5, 2004
35
GB
I've noticed a slight security flaw in our win2k server and winxp client network setup.

Our XP clients are locked down but domain user accounts have local admin rights in order to run logon scripts and run certain applications (pretty standard setup i believe).

Obviously they have no access to the command prompt or run or C:\ drive (using nodrives). However they can create a simple batch file and execute it from a network share. One example was when a student created a v. simple batch file using the net send command. Yep, you guessed it "xxxxx rulez" messages from computer x to all computers on the domain. Annoying more than harmful, but theres nothing to stop someone from runnig slightly more sophisticated file operations to delete stuff off the local drive. Obviously they have no domain admin rights, so they can't do much damage to our server or other machines...Or can they?

Any suggestions or own experiences on this subject

MA
 
You may wish to have a look at for ways around having users map drives - am reading from your question that they may be able to map to \\workstation1\c$ for example and mess with files.
Towards the bottom of the thread above, I have a solution which can be modified for any "net" command, including net send . Hope that helps a little.

In general, Group Policy should let you lockdown quite well - just have to take into account wether any apps or workability gets affected.



Claudius (What certifications??)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top