Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 31st, 2010, 09:16 AM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Standard user disabling security software without UAC support

I'm currently working on a security configuration for W7X64 Pro using local group policies, UAC and standard user accounts.

I had composed a shortlist with security programs I already evaluated using the administrative user account.

For security software I use the following principle: the security product should prevent regular end users from disabling the product.

I discovered that after I installed various security programs using the administrative user account, a standard user account can click on the systray icon and disable or reconfigure the product.

Some programs did support passwords, but I still prefer UAC support.

During my limited testing I found that Microsoft Security Essentials, NOD32 and Windows Firewall support UAC. Using these products standard users are not allowed to disable or configure these programs without an UAC prompt.

I would like to know if I did overlook something in my testing or is it actually possible to disable/reconfigure various security software as standard user?
  #2  
Old August 31st, 2010, 10:11 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Standard user disabling security software without UAC support

yes. Also Windows Defender Spynet Advanced Membership features does not work properly under Standard/Limited User.
I go back from Windows 7 to XP so I can have SuRun instead of UAC.

Don't get me wrong. I like UAC as much as I like Win7's firewall and the DirectX 11.
UAC needs flexibility. Such as remembering password for automatically 'running as admin' a specific app.
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.

Last edited by Konata Izumi : August 31st, 2010 at 10:19 AM.
  #3  
Old August 31st, 2010, 10:31 AM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

My goal is to separate standard user and administrative user. Standard user can perform daily tasks and the administrative user can install software or configure system settings.

I don't want standard users having full access to security software installed by the administrative user. They should be prompted by UAC for privilege escalation.

I could't reproduce this issue with Windows Defender. I can access it, but trying to disable the product via Tools > Options > Administrator > "Use this program" is protected by privilege escalation through UAC.
  #4  
Old August 31st, 2010, 10:39 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Standard user disabling security software without UAC support

i was talking about the windows defender feature that will notify you about changes made by unclassified software.

you cannot make decision whether to permit/deny changes made by an unclassified software when Windows Defender prompts about it. that is under LUA/Standard user
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #5  
Old August 31st, 2010, 10:43 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by diginsight
My goal is to separate standard user and administrative user. Standard user can perform daily tasks and the administrative user can install software or configure system settings.

I don't want standard users having full access to security software installed by the administrative user. They should be prompted by UAC for privilege escalation.

I could't reproduce this issue with Windows Defender. I can access it, but trying to disable the product via Tools > Options > Administrator > "Use this program" is protected by privilege escalation through UAC.

I don't know if this will help or not, but did you try to make those security applications start under the Administrator credentials, rather than the standard user?

Security software should come with a password setting to prevent tampering.
  #6  
Old August 31st, 2010, 10:46 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by Konata Izumi
i was talking about the windows defender feature that will notify you about changes made by unclassified software.

you cannot make decision whether to permit/deny changes made by an unclassified software when Windows Defender prompts about it. that is under LUA/Standard user

That's how it should work. Don't forget that Windows Defender doesn't exist only for home users, or that every home user is the Administrator of that system. In these cases, the Administrator is the one who should make the decisions, not the standard users.
  #7  
Old August 31st, 2010, 10:51 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Standard user disabling security software without UAC support

your principle is good. ^_^
I hope your security software will also help improve my scores in Belarc Advisor.


Quote:
Originally Posted by m00nbl00d
That's how it should work. Don't forget that Windows Defender doesn't exist only for home users, or that every home user is the Administrator of that system. In these cases, the Administrator is the one who should make the decisions, not the standard users.

but i know the admin password.
I can't install the unclassified program correctly even after Running as Admin. because I cant permit changes in windows defender.

:<
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.

Last edited by Konata Izumi : August 31st, 2010 at 10:57 AM.
  #8  
Old August 31st, 2010, 11:04 AM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by m00nbl00d
I don't know if this will help or not, but did you try to make those security applications start under the Administrator credentials, rather than the standard user?

I installed them under the administrative user. Logged off. Logged in as standard user. The security applications GUI part were started through autorun and accessible to the standard user via the systray. Once the GUI part was accessed by the standard user, he was permitted to disable/reconfigure the security program.

Quote:
Originally Posted by m00nbl00d
Security software should come with a password setting to prevent tampering.
Agreed, but some didn't or were not easy to locate. With UAC programs are automatically protected.
  #9  
Old August 31st, 2010, 11:05 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by Konata Izumi
your principle is good. ^_^
I hope your security software will also help improve my scores in Belarc Advisor.




but i know the admin password.
I can't install the unclassified program correctly even after Running as Admin. because I cant permit changes in windows defender.

:<

OK. And, under the Administrator account, can you do it just fine? Have you tried to post your issue in Microsoft forums?
  #10  
Old August 31st, 2010, 11:10 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by diginsight
I installed them under the administrative user. Logged off. Logged in as standard user. The security applications GUI part were started through autorun and accessible to the standard user via the systray. Once the GUI part was accessed by the standard user, he was permitted to disable/reconfigure the security program.


Agreed, but some didn't or were not easy to locate. With UAC programs are automatically protected.

I meant, have you tried to remove the autorun entries for the standard user accounts, and then create tasks to start those very same programs as Administrator? I should had said it clearly, sorry.

I'm not sure if will work, though. It's a long shot, but who knows?
  #11  
Old August 31st, 2010, 11:12 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by m00nbl00d
OK. And, under the Administrator account, can you do it just fine? Have you tried to post your issue in Microsoft forums?

Yes. No. I think this is not the right place to ask about suggestion for WD no? Thanks.


@diginsight
So you're using UAC to protect your security app? how about ASLR?
http://www.wilderssecurity.com/showp...69&postcount=1
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #12  
Old August 31st, 2010, 11:25 AM
s23's Avatar
s23 s23 is offline
Frequent Poster
 
Join Date: Feb 2009
Posts: 260
Default Re: Standard user disabling security software without UAC support

And if you remove the registry key starting the tray icon and identify the main executable (that permit access to the UI) and change in properties=> Compatibilty=> Run this program as administrator?

I tried here in Avast and worked.
  #13  
Old August 31st, 2010, 12:31 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by Konata Izumi
Yes. No. I think this is not the right place to ask about suggestion for WD no? Thanks.

[...]


That wasn't my intention, but, for what I've seen so far, not so many people is using Windows Defender. They've moved on to Microsoft Security Essentials, that I could find doesn't have that same ability has Windows Defender.

So, perhaps, you'd find more issues like the one you have on the Microsoft forums, and find the help you need, I guess.

This was my only intent, when suggesting you to go check at Microsoft's forums.

Sorry, if somehow, I made you think you couldn't be helped here. I'm no one to say you can't be helped here.
  #14  
Old August 31st, 2010, 12:33 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,563
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by s23
And if you remove the registry key starting the tray icon and identify the main executable (that permit access to the UI) and change in properties=> Compatibilty=> Run this program as administrator?

I tried here in Avast and worked.

That's even a better approach than the one I suggested! Sometimes, simpler solutions are in front of our eyes, but we do tend to complicate, don't we?

Thanks for sharing.
  #15  
Old August 31st, 2010, 01:28 PM
s23's Avatar
s23 s23 is offline
Frequent Poster
 
Join Date: Feb 2009
Posts: 260
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by m00nbl00d
That's even a better approach than the one I suggested! Sometimes, simpler solutions are in front of our eyes, but we do tend to complicate, don't we?

Thanks for sharing.

Glad i could help!

@ diginsight

I think this behaviour occur by design to not bother limited users with to much prompts. I not found the thread but i remember reading that the a-squared antimalware 4x have that service running only to permit start it under a standard user account without a prompt. If you disable the service, it ask you for ADM privileges.

Another one that ask for ADM privileges to show GUI is Shadow Defender.
  #16  
Old August 31st, 2010, 01:30 PM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,521
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by m00nbl00d
That wasn't my intention, but, for what I've seen so far, not so many people is using Windows Defender. They've moved on to Microsoft Security Essentials, that I could find doesn't have that same ability has Windows Defender.

So, perhaps, you'd find more issues like the one you have on the Microsoft forums, and find the help you need, I guess.

This was my only intent, when suggesting you to go check at Microsoft's forums.

Sorry, if somehow, I made you think you couldn't be helped here. I'm no one to say you can't be helped here.

lol. Don't worry I didnt misunderstand you at all
I dont use WD now and I feel lazy to go to MS forums anyway
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #17  
Old August 31st, 2010, 03:53 PM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by Konata Izumi
your principle is good. ^_^
I hope your security software will also help improve my scores in Belarc Advisor.
Actually the principle is from Roger Grimes' Professional Windows Desktop and Server Hardening, which I consider to be one of the best books written on this topic.

Didn't know about the Belarc Advisor. After reviewing information it could be useful to benchmark the configuration. For building W7 security configuration I'm also using CIS Benchmark for Windows 7. Surprisingly Belarc supports Windows 7, but doesn't mention the CIS W7 Benchmark.
Quote:
So you're using UAC to protect your security app?

I like the UAC concept for privilege escalation. I took it a bit further and enabled a policy that denies privilege escalation to standard users. This in effect will prevent standard users from being prompted to provide credentials for an admin account. Instead they receive an error message when they try to access UAC protected functions. The goal is to prevent standard users from having to make security decisions. The administrative user, is the only user allowed to raise privileges.

I want to apply this concept to security programs, thus preventing access from standard users and them having to make security decisions.
Quote:
how about ASLR?
The links mentions several AV products not using ASRL nor DEP. Off course MSE supports both. I'm not convinced AV on desktops is that important as an attack vector to require exploit mitigation like ASLR and DEP. For MSE, being an popular AV product, this might be a different and Microsoft certainly did well to implement it.

As to attack vector I think the Secunia report on DEP/ASRL has more importance as vulnerabilities in popular program are also popular targets for exploits and can benefit from exploit mitigations like DEP/ASRL.
Quote:
Originally Posted by m00nbl00d
I meant, have you tried to remove the autorun entries for the standard user accounts, and then create tasks to start those very same programs as Administrator? I should had said it clearly, sorry.
Quote:
Originally Posted by s23
And if you remove the registry key starting the tray icon and identify the main executable (that permit access to the UI) and change in properties=> Compatibilty=> Run this program as administrator?

I tried here in Avast and worked.
Both excellent suggestions and easy to implement. I tried this with one program. After changing the GUI part to run as administrator it refused to start with the standard user even without having disabled the autorun. The GUI is an essential part of this program. Without it, I don't know if the program still functions. When I start the GUI part manually I'm prompted to raise elevation, which reintroduces the original problem of standard users having full access. If I want to keep using this program I guess I have to enable it's password protection.

I still think both suggestions are excellent solutions for programs that don't rely on the GUI part to function.
Quote:
Originally Posted by s23
I think this behaviour occur by design to not bother limited users with to much prompts.
That's also my goal
  #18  
Old September 3rd, 2010, 06:18 AM
s23's Avatar
s23 s23 is offline
Frequent Poster
 
Join Date: Feb 2009
Posts: 260
Default Re: Standard user disabling security software without UAC support

Hi diginsight

You sucessfull did it?
  #19  
Old September 3rd, 2010, 03:01 PM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

Quote:
Originally Posted by s23
You sucessfull did it?

I'm running out of time to finish the project. This is why I limit myself using software that supports UAC.
  #20  
Old September 3rd, 2010, 03:10 PM
Sully Sully is offline
Massive Poster
 
Join Date: Dec 2005
Posts: 3,696
Default Re: Standard user disabling security software without UAC support

Have you considered modifying reg keys or the program executeable, program directory, program dependencies (like config/ini files) to take away modify rights for specific users/groups? Most likely the process can be started with high integrity level, where a medium integrity level process (users have this) can read/execute, but not write.

While I haven't given this much thought nor tried it, I should think one could set the rights so that an non-elevated user (those without high integrity level) could be restricted. Fallback to actual ACE for each aspect if needed.

Some food for thought anyway. Maybe you have already investigated this avenue.

Sul.
__________________
I do things TO my computer, not WITH my computer.. I am a nerd.
  #21  
Old September 6th, 2010, 08:11 AM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

Hi Sul,

Good thinking. I will first focus on finishing this project using WFW and either MSE or NOD32. After it's finished I'll consider if I want to add other security software and try your suggestions.
  #22  
Old October 14th, 2010, 08:10 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,867
Default Re: Standard user disabling security software without UAC support

AVG Anti-Virus also supports UAC.
__________________
  #23  
Old October 15th, 2010, 03:54 PM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Standard user disabling security software without UAC support

Thanks for the update. Tried it with the free edition and it's also supported.

I had a recent conversation about this with the dutch Avira distributor and told them it wasn't supported in the free or premium edition. They assured me it's supported in the enterprise edition.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:22 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums