firewall api from limited user



Since XP SP2 an application that wishes to listen for incoming connections
must be authorized with the Windows firewall. The firewall api requires
administrative credentials. However, it is poor security design to have an
application that listens for incoming connections from within the
administrative context. A better design would have the listening
application run in a limited user context but become admin solely for the
purpose of managing the firewall. What is the best way to "impersonate" an
administrator for this purpose? CoSetProxyBlanket would seem to do the job
except that the documentation for this function pAuthInfo member is not used
for calls on the same machine. Do I have to create a thread, call LogonUser
to become admin in that thread and then call CoSetProxyBlanket from the
thread?

Regards,

George.


.



Relevant Pages

  • Re: [fw-wiz] Host based vs network firewall in datacenter
    ... > network administrator in a small datacenter. ... > I'd like to solicit some advice on a firewall implementation. ... Keeping the hosts locked down tight, and open services to a minimum is a ...
    (Firewall-Wizards)
  • Re: Is Windows XP firewall any good?
    ... I believe that the original writer of that article is refering to network ... The function of a software firewall is simple. ... permitted is stored in the registry. ... administrator is a really bad idea for any operating system ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Hidden User Account Created By Disgruntled Room mate.
    ... Be sure you firewall is enabled, if unsure how, go to Help and Support ... i just did that, and tweakui at logon gives me three> options: parse autoexec.bat at logon > show administrator ... >>>>From there you can go to User Accounts in Control ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Is Windows XP firewall any good?
    ... The function of a software firewall is simple. ... registry and give itself permission to send or receive data over the ... Routinely logging on as an account that is also an administrator is ... settings for the Windows Firewall. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Password Protect Folders?
    ... permissions are granted by user and group. ... Sounds like you neglected to tell us that you are using Windows XP Home ... under an administrator account to change permissions. ... By the way, I don't know what you did, but a firewall enabled or not has ...
    (microsoft.public.windowsxp.basics)

Quantcast