Security Basics mailing list archives

RE: preventing run-as option


From: "Murda Mcloud" <murdamcloud () bigpond com>
Date: Thu, 12 Oct 2006 08:53:45 +1000



I would find it very hard to do my job without RunAs. Closest thing to sudo
that Windows has(only thing?). Helpdesk staff would also find it difficult.
Which is why I think this a policy issue as much as anything else. If
someone has your creds then they can login as you, as well as use runas as
you.(Apologies for all that 'as'). My exceptional justification is
practicality.
-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On
Behalf Of Ansgar -59cobalt- Wiechers
Sent: Wednesday, October 11, 2006 9:12 AM
To: security-basics () securityfocus com
Subject: Re: preventing run-as option

On 2006-10-10 Lariviere, Stephen wrote:
Disable runAs all together. It is bad unless you have an exceptional
justification for it.

You may want to elaborate on that one.

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: