Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. This is how windows security should work...

This is how windows security should work...

Scheduled Pinned Locked Moved The Lounge
comsecuritylounge
20 Posts 12 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    M Offline
    Miszou
    wrote on last edited by
    #1

    Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

    The StartPage Randomizer - The Windows Cheerleader - Twitter

    C H S T M 5 Replies Last reply
    0
    • M Miszou

      Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

      The StartPage Randomizer - The Windows Cheerleader - Twitter

      C Offline
      C Offline
      Chris Losinger
      wrote on last edited by
      #2

      sudo make me a sandwich

      image processing toolkits | batch image processing

      E 1 Reply Last reply
      0
      • C Chris Losinger

        sudo make me a sandwich

        image processing toolkits | batch image processing

        E Offline
        E Offline
        Ennis Ray Lynch Jr
        wrote on last edited by
        #3

        You beat me to it.

        Need custom software developed? I do C# development and consulting all over the United States. A man said to the universe: "Sir I exist!" "However," replied the universe, "The fact has not created in me A sense of obligation." --Stephen Crane

        1 Reply Last reply
        0
        • M Miszou

          Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

          The StartPage Randomizer - The Windows Cheerleader - Twitter

          H Offline
          H Offline
          Henry Minute
          wrote on last edited by
          #4

          The problem is that, should Weven introduce something with similar functionality, MS will once again be accused of stifling innovation from others. I know SuRun is free but that won't stop the knockers.

          Henry Minute Do not read medical books! You could die of a misprint. - Mark Twain Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.”

          C S 2 Replies Last reply
          0
          • H Henry Minute

            The problem is that, should Weven introduce something with similar functionality, MS will once again be accused of stifling innovation from others. I know SuRun is free but that won't stop the knockers.

            Henry Minute Do not read medical books! You could die of a misprint. - Mark Twain Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.”

            C Offline
            C Offline
            Chris Losinger
            wrote on last edited by
            #5

            Henry Minute wrote:

            MS will once again be accused of stifling innovation from others.

            if the accusation fits...

            image processing toolkits | batch image processing

            H 1 Reply Last reply
            0
            • C Chris Losinger

              Henry Minute wrote:

              MS will once again be accused of stifling innovation from others.

              if the accusation fits...

              image processing toolkits | batch image processing

              H Offline
              H Offline
              Henry Minute
              wrote on last edited by
              #6

              And it frequently does. :)

              Henry Minute Do not read medical books! You could die of a misprint. - Mark Twain Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.”

              1 Reply Last reply
              0
              • H Henry Minute

                The problem is that, should Weven introduce something with similar functionality, MS will once again be accused of stifling innovation from others. I know SuRun is free but that won't stop the knockers.

                Henry Minute Do not read medical books! You could die of a misprint. - Mark Twain Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.”

                S Offline
                S Offline
                Shog9 0
                wrote on last edited by
                #7

                Henry Minute wrote:

                MS will once again be accused of stifling innovation from others.

                When you realize you've done something stupid, you have two choices: admit it and strive to do better, or deny it and compound the error...

                1 Reply Last reply
                0
                • M Miszou

                  Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

                  The StartPage Randomizer - The Windows Cheerleader - Twitter

                  S Offline
                  S Offline
                  Stuart Dootson
                  wrote on last edited by
                  #8

                  I've been using this sudo for Windows[^] for ages - I think it may be more configurable than SuRun (it's difficult to tell from the automatic English translation of the SuRun page).

                  Java, Basic, who cares - it's all a bunch of tree-hugging hippy cr*p

                  M 1 Reply Last reply
                  0
                  • S Stuart Dootson

                    I've been using this sudo for Windows[^] for ages - I think it may be more configurable than SuRun (it's difficult to tell from the automatic English translation of the SuRun page).

                    Java, Basic, who cares - it's all a bunch of tree-hugging hippy cr*p

                    M Offline
                    M Offline
                    Miszou
                    wrote on last edited by
                    #9

                    I looked at sudown for a bit before I found surun, but there were a couple of things about it I didn't like - and neither it seems did the author of surun! This is from the readme.txt in the installation package: ------------------------------------------------------------------------------ Why not use the built in "Run As..." Windows command? ------------------------------------------------------------------------------ *RunAs can (without any administrative rights) be abused by keyloggers and Import Address Table Hookers to get the credentials of an Administrator. *Windows loads the registry and environment for the user that you run as. If a software is about to be installed, the installation program will see the admins HKEY_CURENT_USER and may create registry entries there. Also the software sees "C:\Documents and Settings\Administrator" as the users profile path. SuRun uses the current user account, so all registry entries and file system paths are the same as the user would expect. ------------------------------------------------------------------------------ Why not use SuDown? ------------------------------------------------------------------------------ *SuDown can very easily be used to spy your account password. SuDowns password dialog runs in the users desktop and the password can be caught by any application that uses Windows hooks, even by autohotkey. *SuDown puts every SuDoer, after he logged on, into the Administrators group. Spying the password and using it in a call to CreateProcessWithLogonW would make the spy running as administrator. *SuDown starts any process as administrator without asking for permission for a couple of minutes after the user entered the correct password. *SuDown does not work in a plain Windows 2000 because the windows function "LogOnuser" in Windows 2000 requires a privilege that only system processes have. ------------------------------------------------------------------------------ Why use SuRun? ------------------------------------------------------------------------------ *SuRun uses a secure desktop for sensitive user interaction: SuRun uses a service to create a secure desktop in the window station of the users logon session. On that desktop it will ask the user for permission or the password. The desktop is not accessible by user applications. Keyboard and mouse hooks will also not work on that desktop. *SuRun does not require a password. *SuRun does not put nor leave the user in the

                    S 1 Reply Last reply
                    0
                    • M Miszou

                      I looked at sudown for a bit before I found surun, but there were a couple of things about it I didn't like - and neither it seems did the author of surun! This is from the readme.txt in the installation package: ------------------------------------------------------------------------------ Why not use the built in "Run As..." Windows command? ------------------------------------------------------------------------------ *RunAs can (without any administrative rights) be abused by keyloggers and Import Address Table Hookers to get the credentials of an Administrator. *Windows loads the registry and environment for the user that you run as. If a software is about to be installed, the installation program will see the admins HKEY_CURENT_USER and may create registry entries there. Also the software sees "C:\Documents and Settings\Administrator" as the users profile path. SuRun uses the current user account, so all registry entries and file system paths are the same as the user would expect. ------------------------------------------------------------------------------ Why not use SuDown? ------------------------------------------------------------------------------ *SuDown can very easily be used to spy your account password. SuDowns password dialog runs in the users desktop and the password can be caught by any application that uses Windows hooks, even by autohotkey. *SuDown puts every SuDoer, after he logged on, into the Administrators group. Spying the password and using it in a call to CreateProcessWithLogonW would make the spy running as administrator. *SuDown starts any process as administrator without asking for permission for a couple of minutes after the user entered the correct password. *SuDown does not work in a plain Windows 2000 because the windows function "LogOnuser" in Windows 2000 requires a privilege that only system processes have. ------------------------------------------------------------------------------ Why use SuRun? ------------------------------------------------------------------------------ *SuRun uses a secure desktop for sensitive user interaction: SuRun uses a service to create a secure desktop in the window station of the users logon session. On that desktop it will ask the user for permission or the password. The desktop is not accessible by user applications. Keyboard and mouse hooks will also not work on that desktop. *SuRun does not require a password. *SuRun does not put nor leave the user in the

                      S Offline
                      S Offline
                      Stuart Dootson
                      wrote on last edited by
                      #10

                      No - I use SudoWin, not SuDown - they're different things!

                      Java, Basic, who cares - it's all a bunch of tree-hugging hippy cr*p

                      M 1 Reply Last reply
                      0
                      • S Stuart Dootson

                        No - I use SudoWin, not SuDown - they're different things!

                        Java, Basic, who cares - it's all a bunch of tree-hugging hippy cr*p

                        M Offline
                        M Offline
                        Miszou
                        wrote on last edited by
                        #11

                        And that is a perfect demonstration of why I hate loosely typed languages. Did you see that erroneous variable get created and then I just used it without even noticing! Heck, even the compiler didn't care, it just let me carry right on as if nothing was wrong! I could have been debugging that for hours... *shudder* :-D

                        The StartPage Randomizer - The Windows Cheerleader - Twitter

                        1 Reply Last reply
                        0
                        • M Miszou

                          Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

                          The StartPage Randomizer - The Windows Cheerleader - Twitter

                          T Offline
                          T Offline
                          Tim Groven
                          wrote on last edited by
                          #12

                          Thank you for posting this! I've had the same problem on my kids' machine where they needed to do Run As Admin for some of the games. Completely misses the point of giving them lower priviledges.

                          N 1 Reply Last reply
                          0
                          • T Tim Groven

                            Thank you for posting this! I've had the same problem on my kids' machine where they needed to do Run As Admin for some of the games. Completely misses the point of giving them lower priviledges.

                            N Offline
                            N Offline
                            nistrum404
                            wrote on last edited by
                            #13

                            Games needing elevation? Wonder why. Manic Miner never used to pop up an elevation prompt. Get the kids a Spectrum +3.

                            Matt Dockerty

                            J T 2 Replies Last reply
                            0
                            • N nistrum404

                              Games needing elevation? Wonder why. Manic Miner never used to pop up an elevation prompt. Get the kids a Spectrum +3.

                              Matt Dockerty

                              J Offline
                              J Offline
                              John M Drescher
                              wrote on last edited by
                              #14

                              nistrum404 wrote:

                              Games needing elevation? Wonder why.

                              Copy protection??

                              John

                              1 Reply Last reply
                              0
                              • N nistrum404

                                Games needing elevation? Wonder why. Manic Miner never used to pop up an elevation prompt. Get the kids a Spectrum +3.

                                Matt Dockerty

                                T Offline
                                T Offline
                                Tim Groven
                                wrote on last edited by
                                #15

                                I blame bad programming. :) I agree, games should not need elevated rights. Especially when it's my daughter's Barbie Fashion Studio. :) Tim

                                N D 2 Replies Last reply
                                0
                                • T Tim Groven

                                  I blame bad programming. :) I agree, games should not need elevated rights. Especially when it's my daughter's Barbie Fashion Studio. :) Tim

                                  N Offline
                                  N Offline
                                  nistrum404
                                  wrote on last edited by
                                  #16

                                  Dressing up Barbie requires kernel mode hooks as every programmer knows :laugh:

                                  Matt Dockerty

                                  1 Reply Last reply
                                  0
                                  • T Tim Groven

                                    I blame bad programming. :) I agree, games should not need elevated rights. Especially when it's my daughter's Barbie Fashion Studio. :) Tim

                                    D Offline
                                    D Offline
                                    Dan Neely
                                    wrote on last edited by
                                    #17

                                    Barbie should be a *nix game, since she needs root. :laugh:

                                    It is a truth universally acknowledged that a zombie in possession of brains must be in want of more brains. -- Pride and Prejudice and Zombies

                                    N D 2 Replies Last reply
                                    0
                                    • D Dan Neely

                                      Barbie should be a *nix game, since she needs root. :laugh:

                                      It is a truth universally acknowledged that a zombie in possession of brains must be in want of more brains. -- Pride and Prejudice and Zombies

                                      N Offline
                                      N Offline
                                      nistrum404
                                      wrote on last edited by
                                      #18

                                      Lolol. $ sudo root barbie.

                                      Matt Dockerty

                                      1 Reply Last reply
                                      0
                                      • M Miszou

                                        Some of you may remember a few weeks ago that my son completely screwed up his gaming machine, because his dad (me) was a lazy arse that couldn't be bothered to get his games to run properly in non-admin mode. Well, I've reinstalled the whole machine, and like a good IT person, I've now restricted his access and locked the thing down correctly. Anyway, in order to do this I had to use a 3rd party piece of software to allow privelege elevation for specific applications from within his limited user account. There are a million reasons why logging on as another user or trying to use the "Run As" comand are both completely inadequate and poorly implemented solutions. So, if Weven can support the kind of functionality that SuRun[^] provides, I will be buying copies for everyone I know and telling everyone that it is the greatest OS ever created. This is without a doubt one of the most useful utilities I have ever come across, but the shameful thing is that it should have been built into Windows years ago. I won't bore you all with the details, instead here's a link to the original software page: SuRun[^] And just for completeness, here's a link to my sycophantic blog entry on this software: sudo for Windows[^]

                                        The StartPage Randomizer - The Windows Cheerleader - Twitter

                                        M Offline
                                        M Offline
                                        mkpro17
                                        wrote on last edited by
                                        #19

                                        I had a client that we manage the network for, and they had a need to use Gradience HR software which needs to acces files that are UAC protected, so only admins could use the program. Vista has a way to bypass UAC for specific programs so any user can now run that program; there is no need for a third party tool. Here is a little how to article on it: http://dailyapps.net/2008/01/hack-attack-disable-uac-for-certain-applications-in-vista/[^]

                                        mathew

                                        1 Reply Last reply
                                        0
                                        • D Dan Neely

                                          Barbie should be a *nix game, since she needs root. :laugh:

                                          It is a truth universally acknowledged that a zombie in possession of brains must be in want of more brains. -- Pride and Prejudice and Zombies

                                          D Offline
                                          D Offline
                                          DragonsRightWing
                                          wrote on last edited by
                                          #20

                                          Not really - she's a natural blonde, and doesn't need to dye ... Him: Quod erat demonstrandum, baby... Her: Ooh - you speak french! Thomas Dolby - "Airhead"

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups