Author Topic: Security Permissions in XP Pro  (Read 4243 times)

0 Members and 1 Guest are viewing this topic.

bozo

  • Guest
Security Permissions in XP Pro
« on: June 06, 2008, 05:23:05 PM »
I am setting up a new PC with the intention of making it as secure as possible so I intend to run as a Limited User  I was unhappy therefore to see that after installing the latest Home version that the security permissions set after install enabled Everyone Full Control over most of the the AVAST folder and files 

Can I modify these permissions in any way to make them safe and is this the same in the Paid version  If not I am afraid I cannot continue with this software

I have to say I find it strange that a security software company would design their stuff this way

Many thanks

Mike

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Security Permissions in XP Pro
« Reply #1 on: June 06, 2008, 05:30:12 PM »
This is controlled by avast self-defense module (on Troubleshooting tab of settings).
Which is your avast version? 4.8.1201 is the latest.
The best things in life are free.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Security Permissions in XP Pro
« Reply #2 on: June 06, 2008, 05:47:41 PM »
As Tech said, avast controls filesystem access to its files/registry keys on its own.
That is, even if e.g. Explorer says there's Everyone/FullControl access to the folder, it is not the case (you can try to write a file in that folder and see what happens).

Cheers
Vlk
If at first you don't succeed, then skydiving's not for you.

bozo

  • Guest
Re: Security Permissions in XP Pro
« Reply #3 on: June 06, 2008, 06:44:59 PM »
I am using 4.8.1201

Yes it does appear that the situation is not as bad as it first appears  and that Avast is protecting most of the folders  However there are 2 folders where as a Limited user I can still both write and execute files These are

C:\Program Files\Alwil Software\Avast4\Data\Moved
C:\Program Files\Alwil Software\Avast4\Data\Report

Thanks for your help

Mike


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Security Permissions in XP Pro
« Reply #4 on: June 06, 2008, 09:28:07 PM »
C:\Program Files\Alwil Software\Avast4\Data\Moved
C:\Program Files\Alwil Software\Avast4\Data\Report
That's true and good... common users (non-admins) could move infected files and generate reports ;)
The best things in life are free.

bozo

  • Guest
Re: Security Permissions in XP Pro
« Reply #5 on: June 07, 2008, 12:03:43 AM »
C:\Program Files\Alwil Software\Avast4\Data\Moved
C:\Program Files\Alwil Software\Avast4\Data\Report
That's true and good... common users (non-admins) could move infected files and generate reports ;)

But if you allow Everyone to write/execute permission it could be a target for hackers. How would it compromise Avast if I were to remove the execute permission for instance or at least change Everyone to Authenticated User

Thanks

Mike

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Security Permissions in XP Pro
« Reply #6 on: June 08, 2008, 03:45:44 PM »
But if you allow Everyone to write/execute permission it could be a target for hackers.
Hackers? Like any other folder in your computer... Which hacker will be interested in avast logs and reports?
Malware? They're not affecting avast working and protection...
Won't we becoming paranoid here ;)
The best things in life are free.

bozo

  • Guest
Re: Security Permissions in XP Pro
« Reply #7 on: June 08, 2008, 06:48:14 PM »
I am following the principles described here:

http://www.mechbgon.com/srp/

Essentially you do not  allow both write and execute permission for the same folder (whilst running as a LUA)  If all software writers did this we would have a much safer environment

So I am really interested in why you would allow Execute permission for the folder where the user moves virus's to ?   I would think you  would enable the minimum permissions that are necessary

Thanks

MIke