Re: How to best protect against Spyware and Rookits



A major drawbacks for this approach are:
a) By deafault, first created account is an admin account.
b) Default permissions for "Documents and settings" allows execution.

Users should manually change these settings and 99% of them can't do it :(


"na" <na@xxxxxx> wrote in message news:OzE0R6OoIHA.4904@xxxxxxxxxxxxxxxxxxxxxxx

"Waleri Todorov" <invalid@xxxxxxxxx> wrote in message news:eViX%23dFoIHA.6096@xxxxxxxxxxxxxxxxxxxxxxx
Well, the protection is quiet simple, really - DO NOT LOGIN AS AN ADMINISTRATOR.
Furthermore, disable execution permissions from folder with write permissions and vice versa.

Of course, a bunch of lame program will fail to work under these conditions, so that's why UAC was invented, but
that's Vista...

I was just going to suggest this. I am so glad I am not alone. To anyone reading this get ready for
the most basic info you could ever hope to hear.

1. Create and use only a limited user account.
2. Use Software Restriction Polices.

I do the above and have no problems! I have no virus scanning software installed because they
are just vulnerable services running as root anyway!

1. Virus copies itself to desktop because of Internet Exploit. SO WHAT? It can't execute!
2. Linux only recently came up with SELinux...




Relevant Pages

  • Re: Everyone permissions on C Drive
    ... Before you go changing permissions on the WIndows partitions, ... make sure that you do not enable the Guest account. ... > access the root of my machine (if, say the firewall errors out and I ... and I don't want to interfere with defaul t settings too ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Exacutable commands for Folder Options & Startup Menu Properties
    ... Start Menu and Taskbar: ... > account locks them out of some sensitive settings but not ... I'am set up as an "Admin" account, ... > a"Special Access"(FULL access minus Changing Permissions). ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Problem with security settings for internet explorer
    ... I have one limited account and my account is ... >> settings. ... that is the only strange behavior that I've noticed so far. ... anything until I get a much better understanding of permissions. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: SUS and IIS: Error 403 when trying to access the SUS
    ... I have checked the actual folders and the permissions are set for the account I amusing to access it. ... "Ken Schaefer" wrote: ... > settings back to defaul. ...
    (microsoft.public.inetserver.iis)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)