Author Topic: Running as limited user - the easy way  (Read 5523 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Running as limited user - the easy way
« on: March 05, 2006, 03:14:29 PM »
Hi forum folks,

In Vista it will be a normal standard feature, surfing with limited rights, more secure against malware. But it can be easily done also for XP: http://www.sysinternals.com/blog/2006/03/running-as-limited-user-easy-way.html


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48628
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Running as limited user - the easy way
« Reply #1 on: March 05, 2006, 04:06:36 PM »
Isn't this basically what we've been doing right along by utilizing the following???
http://forum.avast.com/index.php?topic=7204.msg128315#msg128315
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Running as limited user - the easy way
« Reply #2 on: March 05, 2006, 04:13:17 PM »
Hi Bob3160,

Of course, the strength of educating lies in the the strenght of repeating. So now it can be entitled "a banana problem".

polonus
« Last Edit: March 05, 2006, 04:25:57 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48628
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Running as limited user - the easy way
« Reply #3 on: March 05, 2006, 04:39:46 PM »
Quote
So now it can be entitled "a banana problem".
But this one has whipped cream on it..... ;D ;D
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Running as limited user - the easy way
« Reply #4 on: March 05, 2006, 05:30:27 PM »
This Limited user function of MS Vista and Protected-Mode IE will obviously take some time.

In the meantime, Microsoft's DropMyRights and now Mark Russinovich's 'Process Explorer’s Run as Limited User' (nice looking interface) is another option until Vista and IE7 (vista version) come along.

There is also another method, start as a limited User and either use the Run As context menu shortcut or use a little program RunAsAdmin.

But there really is no excuse not to restrict the rights of programs that access the internet, unless it absolutely has to have admin privileges like windows update.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Running as limited user - the easy way
« Reply #5 on: March 05, 2006, 05:38:07 PM »
Hi DavidR,

I still have a little question, when I look at what is going on in the settings through IbProcMan I see that on a Windows XP SP2 system runs as superuser :D. System account overrules the admin account even, all users and groups trust system.  In howfar is this a threat towards malware vectors, and how to counter that one? If I can run system on a box I own it. Look for some on this here: http://www.grc.com/dos/sockettome3.htm and here:
http://www.windowsnetworking.com/kbase/WindowsTips/WindowsXP/AdminTips/Utilities/XPschtaskscommandlineutilityreplacesAT.exe.html


polonus
« Last Edit: March 05, 2006, 05:42:50 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Running as limited user - the easy way
« Reply #6 on: March 05, 2006, 05:46:02 PM »
I haven't looked into it that deeply (too scary), but I would have to assume the logic that System is always going to over rule an admin user and an admin user has a higher privilege than a superuser, etc.

I don't know if this would also be true of 'The Administrator' account or how difficult it would be to have malware get system privileges, or what level of protection there is to stop this happening.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Running as limited user - the easy way
« Reply #7 on: March 05, 2006, 06:05:31 PM »
Well DavidR,

I posted about this thing before here in the forum, about giving your scan some bite, I think there was not much changed after this trust dependencies came in with Windows NT. And thinking about it that is why automatic installs, updates, plug and play, host memstick use functionality are that dangerous, at least could mean a threat.

This should not be as default configuration. see here for my contribution, all that can be used for a good purpose can also be used for malicious purposes. See: http://forum.avast.com/index.php?topic=14363.0

To dwell a bit more on privilegers here, just have to set a process to Äct as a part of the Operating System"privilege using the Local Security Settings, and then reboot the system. In other way to get this result is to modify machine.config by setting the username attribute equal to "system" in the ProcessModel element, and then reset ISS. Else things do not work and you will get an exeption (Sigh of relief here). To get to the privilege lower than the mentioned one we have to set it to Äct as part of Operating System"privilege using Local Security Setting.

polonus
« Last Edit: March 05, 2006, 06:22:19 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Running as limited user - the easy way
« Reply #8 on: March 05, 2006, 06:26:34 PM »
Yes, possible but not easy and in the example you use there would need to be an element of user co-operation/interaction.

Unless of course it would be possible to create a batch file or a program that would have the privileges and could replicate these actions.

It's at times like these that I'm really glad I have a back-up/recovery strategy that if the worst came to the worst, restoring a disk image would take a few minutes.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Running as limited user - the easy way
« Reply #9 on: March 05, 2006, 06:47:00 PM »
Yes I agree on that one, but then you must start from a point where your OS was in a non- compromised state If you are not aware of that and a compromised situation has endured and you do not know how long, you can't be sure what exactly was backdoored or altered on your machine, and the onlt safe thing to be able to fully trust it again was a re-install.

What LSA privilege can do, see here:
http://www.codeproject.com/csharp/lsadotnet.asp

polonus
« Last Edit: March 05, 2006, 07:31:52 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Running as limited user - the easy way
« Reply #10 on: March 05, 2006, 08:31:09 PM »
Thanks for that.

I said it was scary ;D when you start to delve you don't feel so secure.

Fortunately this is way over my head to realise just how scared I should be ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Running as limited user - the easy way
« Reply #11 on: March 05, 2006, 09:15:34 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Running as limited user - the easy way
« Reply #12 on: March 06, 2006, 12:26:14 AM »
Thanks polonus, I will print that off and save it for a little light ;D bedtime reading, certain to get me off to sleep ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security