On MovieTome: BRUNO is here?are you worried?

IT Security

Host: Chad Perrin
Contact

Providing only the local system access necessary for business users to perform their jobs should be the ultimate goal.  But until that time, we can drop their rights when appropriate.

——————————————————————————————————————-

Microsoft Windows XP system and security administrators don’t have to wait until management decides to deal with user angst and approves removal of local admin access from normal users–a move necessary to protect end-user systems from risky behavior.  Nor do they have to undertake the more onerous task of moving to Windows Vista.  Instead, implementation of DropMyRights allows them to protect users and the business from the behavior of high-risk applications, like Web browsers.

DropMyRights is a free download.  It comes as an MSI package containing the executable and source.  It’s not easy to find, so Steve Gibson provided a link in the Security Now episode notes in which he discusses the value of this utility.  See Figure 1.

Where to download DropMyRights

Figure 1 (http://www.grc.com/securitynow.htm)

Once installed, DropMyRights runs from a command line, using a path to the desired application and the access level as arguments.  Figure 2 shows the syntax I used to run Firefox.  Note the requirement for the entire path for the executable.  There are three levels of access available.  I used ‘N’, or normal.  Details about the rights removed at each level (Normal, Constrained, Un-trusted) are provided in Browsing the Web and Reading E-mail Safely as an Administrator, written my Michael Howard, author of DropMyRights.

When I entered the command, DropMyRights removed certain rights from my user token.  Using the modified token, now with no local admin rights, it launched Firefox.  Actions like installing a root kit or other unwanted applications while browsing were now blocked.

Command line syntax

Figure 2

This is great for those of us who know what a command line looks like.  However, our business users need a little more handholding.  So I tested a shortcut to launch Firefox with Normal user access to my system, as shown in Figure 3.

Shortcut

Figure 3

Not long ago, I wrote about a free sandboxing program, Sandboxie.  Shouldn’t it be enough to protect our systems?  Yes and no.  As I wrote in the article, Sandboxie prevents unwanted applications and miscellaneous junk from being written permanently to your disk.  However, anything malicious written into the sandbox can still compromise your privacy.
The current version of Sandboxie doesn’t provide a means to reduce user rights when an application is launched.  However, a combination of DropMyRights and Sandboxie seems to work well.

First, I configured my default sandbox to force Firefox into a sandbox every time I ran it, as shown in Figure 4.

Forced into a sandbox

Figure 4

Next, I simply ran Firefox using the shortcut shown in Figure 3.  DropMyRights ran Firefox and Sandboxie forced it to run, with reduced rights, in a sandbox.

Using DropMyRights for an enterprise rollout shouldn’t be a problem, according to the EULA contained in the downloaded MSI.  However, neither DropMyRights nor Sandboxie should be a permanent solution for organizations without the political will or clout to remove local admin access from normal users.  Providing only the access necessary to perform their jobs should be the ultimate goal.  But until that time, we can drop their rights when appropriate.

Tom OlzakTom Olzak is an IT professional with over 25 years experience. He holds CISSP and MCSE certifications and an MBA. Currently, he is Director of Information Security for HCR Manor Care. Read his full bio and profile.

Print/View all Posts Comments on this blog

Addition to article StealthWiFi | 01/07/09
So I've got to create a new shortcut for every app? Palmetto | 01/07/09
new shortcuts dfd9880@... | 01/13/09
Havn't tried Yet but.. Manitobamike | 01/20/09
Alternate program martian@... | 01/14/09
Another Option jeffb@... | 01/22/09

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



IT Professional's Guide to Policies and Procedures, Third Ed
Whether you're creating policies for management, training, personnel, support, privacy, Internet/e-mail usage, security, or inventory, you'll meet the needs of your entire enterprise with this one download!
Buy Now
IT Help Desk Survival Guide, Third Edition
TechRepublic's IT Help Desk Survival Guide, Third Edition provides tools and recommendations to help you better manage help desk services, improve end-user support, troubleshoot frustrating hardware issues, identify quick fixes to vexing Windows problems, and help users make the most of Microsoft Office 2003.
Buy Now

Introducing SmartPlanet

advertisement
Click Here