Full Disclosure mailing list archives
Bypass user GPO in Windows Xp / 2003
From: Espen <espen () espen mine nu>
Date: Wed, 21 Dec 2005 00:38:34 +0100
During some security testing in a high security enviorment - I discovered that by using the "run as" or "the runas /noprofile" I could bypass user GPO settings completely.
I e-mailed the security mail at Microsoft about it - and they confirmed that they had reproducedc the behavior - but said that the user restrictons where not ment as security settings - but just to stop the user from messing up their enviorment !?!?!?!
To reproduce it:Set up a domain with strict security settings. Eg. Software restritions policies, hide local drives, remove "run", disable cmd.exe and so on.
Log on to an XP computer in that domain - make a link to cmd.exe - select "run as" on that link.
Logon with another user in the same domain - with the same restrictions - you'll see that the GPO's will not be loaded for that user.
Maybe not a big deal - but I thought you should know...... _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Bypass user GPO in Windows Xp / 2003 Espen (Dec 20)
- <Possible follow-ups>
- Bypass user GPO in Windows Xp / 2003 Nick Eoannidis (Dec 21)
- Re: Bypass user GPO in Windows Xp / 2003 b . hines (Dec 21)
- Re: Bypass user GPO in Windows Xp / 2003 b . hines (Dec 21)
- Re: Bypass user GPO in Windows Xp / 2003 Espen (Dec 21)