Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 8th, 2011, 02:18 PM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Question Using SRP with AppLocker to block more scripts

Since AppLocker only cares about .ps1, .bat, .cmd, .vbs, and .js scripts, I thought I might use SRP to disallow other scripts to be run outside of %WinDir% and %ProgramFiles% to make life more of a PITA for users

Already removed stuff covered by AppLocker from Designated File Types plus a bunch of others, such as MS Access/Project files, LNK, CHM... So, what would be a good suffix list for this? Ideas?
  #2  
Old April 8th, 2011, 03:23 PM
Sadeghi85 Sadeghi85 is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 697
Default Re: Using SRP with AppLocker to block more scripts

Quote:
Originally Posted by doktornotor

Already removed stuff covered by AppLocker from Designated File Types plus a bunch of others,

When Applocker is active, SRP is disabled, so not sure why you'd want to remove anything from SRP, and if I am not mistaken that feature only blocks by file extension which is easy to circumvent and btw doesn't work if a script is assigned to open by a third-party app.
  #3  
Old April 8th, 2011, 04:00 PM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Default Re: Using SRP with AppLocker to block more scripts

Quote:
Originally Posted by Sadeghi85
if I am not mistaken that feature only blocks by file extension which is easy to circumvent and btw doesn't work if a script is assigned to open by a third-party app.

Yes, by extension. Perfectly enough since their browsing is already restricted to intranet and couple of selected sites.

Why I wanted to do this? Because the users here are complete morons. (Their computer literacy pretty much reflects their salary, ugh... Good that I spend just a couple of hours a week in this company from hell.) Would prefer to not get into more details, suffice to say that recently one of them wiped pretty much his entire user profile by clicking on a "picture" which was a script. It was a "joke" by one of his fellow workers. Similar incidents happen couple of times every month and am I tired of restoring the backups.

Well, since both cannot be applied at the same time I will have to look at alternative GPO stuff to do the same, thread pretty much closed. Or I will just send them to hell and tell them to find another backup-restore monkey
  #4  
Old April 8th, 2011, 04:10 PM
Sadeghi85 Sadeghi85 is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 697
Default Re: Using SRP with AppLocker to block more scripts

Quote:
Originally Posted by doktornotor
Yes, by extension. Perfectly enough since their browsing is already restricted to intranet and couple of selected sites.



Why not just use SRP then ?
  #5  
Old April 8th, 2011, 04:23 PM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Default Re: Using SRP with AppLocker to block more scripts

Quote:
Originally Posted by Sadeghi85
Why not just use SRP then ?

Wanted to avoid it since there is one big office OU with the same AppLocker policy... which includes also normal people with much less restricted internet access. AppLocker obviously preferred there. Also a whole lot better when forcing up-to-date versions of applications etc. Also at least one less policy and OU to manage. Eh well, sigh...

Honestly these morons would be best served with a Linux live CD if a couple of the core apps there did not require Windows.
  #6  
Old April 8th, 2011, 05:10 PM
Sadeghi85 Sadeghi85 is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 697
Default Re: Using SRP with AppLocker to block more scripts

Oh, well...

You can't stop stupidity, the person responsible for that 'joke' should be punished...

btw what kind of script was that?
  #7  
Old April 8th, 2011, 06:43 PM
doktornotor's Avatar
doktornotor doktornotor is offline
Very Frequent Poster
 
Join Date: Jul 2008
Posts: 2,045
Default Re: Using SRP with AppLocker to block more scripts

Quote:
Originally Posted by Sadeghi85
btw what kind of script was that?

IIRC some WSF crap.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:49 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums