stefan555
March 12th, 2009, 10:26 AM
I am am planning to use portable applications on my old desktop. My purpose is to make the desktop faster and to avoid the use of applications that makes changes in the registry.
The setup I have is;
-Fully patched XP Pro SP3.
-LUA + disallowed SRP.
-I had kafu to prevent user-mode malware to install in the remaining 7 autostart locations not already blocked by the LUA + SRP approach.
-SW DEP. My old PC doesnt support HW DEP.
-Disabled autoplay for removable media
-Comodo FW 3 (Defence+ disabled)
-No HIPS, no resident virusscanner or antispyware scanner. Virus and spyware scanning on-demand. I am considering to use Sandboxie for the browser though.
The application I intend to use are:
-Firefox Portable
-Thunderbird Portable
-ImageBurn Portable
-Jarte Portable
-Open Office Portable
-IrfanView Portable
-VLC portable
-7zip portable
-IZArc2go
-Sumatra pdf
-FreeCommander Portable
-LUA prevents a user to write in the program folder and system folders
-SRP prevents executables (designated file types in the SRP) to executables other folders than programs and system folders.
To be able to use portable applications on a desktop it requires either that the user has write permissions to the program folder or that executables can be run from the user's document and settings folder.
In this context; which is the best approach from a security perspective;
-To tweak the folder permissions in the program folder, giving the user the neccessary permissions to the applicable folders?
or to
-Add additional path rules to the SRP to make it possible for the portable programs to run from the user's Document and Settings folder?
I am aware the Surun can be used to make it possible to run programs as administrator, but i rather only use Surun when absolutely needed. But Surun is a great application.
Thanks in advance
Stefan
The setup I have is;
-Fully patched XP Pro SP3.
-LUA + disallowed SRP.
-I had kafu to prevent user-mode malware to install in the remaining 7 autostart locations not already blocked by the LUA + SRP approach.
-SW DEP. My old PC doesnt support HW DEP.
-Disabled autoplay for removable media
-Comodo FW 3 (Defence+ disabled)
-No HIPS, no resident virusscanner or antispyware scanner. Virus and spyware scanning on-demand. I am considering to use Sandboxie for the browser though.
The application I intend to use are:
-Firefox Portable
-Thunderbird Portable
-ImageBurn Portable
-Jarte Portable
-Open Office Portable
-IrfanView Portable
-VLC portable
-7zip portable
-IZArc2go
-Sumatra pdf
-FreeCommander Portable
-LUA prevents a user to write in the program folder and system folders
-SRP prevents executables (designated file types in the SRP) to executables other folders than programs and system folders.
To be able to use portable applications on a desktop it requires either that the user has write permissions to the program folder or that executables can be run from the user's document and settings folder.
In this context; which is the best approach from a security perspective;
-To tweak the folder permissions in the program folder, giving the user the neccessary permissions to the applicable folders?
or to
-Add additional path rules to the SRP to make it possible for the portable programs to run from the user's Document and Settings folder?
I am aware the Surun can be used to make it possible to run programs as administrator, but i rather only use Surun when absolutely needed. But Surun is a great application.
Thanks in advance
Stefan