Disable share GUI while keeping File and printer sharing

  • Thread starter Thread starter tzvikaz
  • Start date Start date
T

tzvikaz

Hi,
I have a "kiosk" machine that runs on XP SP2.
It must have File and Printer Service.
The logged user is an admin.
I want to somehow not allow him to add shares on folders/drives or if
its impossible to know that he did.

any ideas?
 
Hi,
I have a "kiosk" machine that runs on XP SP2.
It must have File and Printer Service.
The logged user is an admin.
I want to somehow not allow him to add shares on folders/drives or if
its impossible to know that he did.

any ideas?

Why must the logged in user be an admin? There's very little you can do if
someone has local admin rights. This is not a recommended configuration.
 
Why must the logged in user be an admin? There's very little you can do if
someone has local admin rights. This is not a recommended configuration.

I understand, the reason for this it too complicated for me to
explain.
It has to be that way.
What I want to do is have my application that runs on that pc know
that someone just created a share on the HD and when knowing this
disabling the application. This solution is good enough for me.
How Can I know though that a new share was created?

Sorry about the multiple posts btw.
 
I understand, the reason for this it too complicated for me to
explain.
It has to be that way.
What I want to do is have my application that runs on that pc know
that someone just created a share on the HD and when knowing this
disabling the application. This solution is good enough for me.
How Can I know though that a new share was created?

Sorry about the multiple posts btw.

I don't know of anything, sorry. You might try a scripting group, maybe.
 
I have a "kiosk" machine that runs on XP SP2.
It must have File and Printer Service.
The logged user is an admin.
I want to somehow not allow him to add shares on folders/drives

If the logged on user really needs to be an admin, your best bet is to use
software restriction policies (try doing a search of MSDN or the Microsoft
Knowledge Base on that phrase if you aren't familiar with the concept) to
configure a set of allowed executables and block everything else. You need to
think carefully about the effects of each executable on the list; for example,
Windows Explorer should not be permitted, so you'll also need to provide an
alternative shell. In general, any software that allows copying an arbitrary
file or editing a text file isn't safe.

In almost all cases it would be both safer and easier to work around the need
for the user to be an admin. Are you certain this isn't an option?

Microsoft provide a toolkit for shared computers which restores the computer to
the initial state after a reboot, this may provide some additional protection.
Or (better) you could run the kiosk functions on a virtual machine, configured
not to keep changes after reboot. (This might make it OK to allow Windows
Explorer, since it blocks the obvious attack of installing a second operating
system; however, I suspect Windows Explorer would still allow more subtle
attacks even if I can't identify them offhand. You also need to think about
possible attacks on your kiosk application, though you might be able to block
those by putting the kiosk application and data files on the host OS and
accessing them over a virtual network.)

In this context, the File and Printer Service might not need to be on the same
virtual machine as the logged on user, which could provide additional protection.

Harry.
 
What I want to do is have my application that runs on that pc know
that someone just created a share on the HD and when knowing this
disabling the application. This solution is good enough for me.
How Can I know though that a new share was created?

NetShareEnum. However, unless you take precautions such as those I describe in
my other post, the user will be able to easily kill or disable your monitoring
application.

Harry.
 
Back
Top