G 
		
								
				
				
			
		Guest
Hi everyone
This is the setup - a stand alone PC connected to ADSL via a router. The OS
is XP Pro SP2 and there's a floppy, CD/DVD as well as a number of 2.0 USB
ports.
I'd like to prevent Limited users from being able to run cmd.exe. I know
that I can remove <Run> from the Start menu and I can set permissions of
cmd.exe to prevent Limited users running it. I also know about a registry
tweak (RestrictRun or DisallowRun) to prevent a particular program being run,
but what if a user has a copy of cmd.exe on a floppy etc.? Users need access
to a floppy or USB port, so disabling these isn't an option. Even if I did
disable the floppy/CD/USB, a user could e-mail a copy of cmd.exe to himself
and may, even, rename it. I suspect that would get around the DisallowRun or
RestrictRun registry setting.
Does anyone have any suggestions about this? I just wonder if cmd.exe
accesses some ofter file, such as a .dll, the permissions of which could be
modified? I'm thinking aloud and don't know if that would be an option.
Thanks in advance.
				
			This is the setup - a stand alone PC connected to ADSL via a router. The OS
is XP Pro SP2 and there's a floppy, CD/DVD as well as a number of 2.0 USB
ports.
I'd like to prevent Limited users from being able to run cmd.exe. I know
that I can remove <Run> from the Start menu and I can set permissions of
cmd.exe to prevent Limited users running it. I also know about a registry
tweak (RestrictRun or DisallowRun) to prevent a particular program being run,
but what if a user has a copy of cmd.exe on a floppy etc.? Users need access
to a floppy or USB port, so disabling these isn't an option. Even if I did
disable the floppy/CD/USB, a user could e-mail a copy of cmd.exe to himself
and may, even, rename it. I suspect that would get around the DisallowRun or
RestrictRun registry setting.
Does anyone have any suggestions about this? I just wonder if cmd.exe
accesses some ofter file, such as a .dll, the permissions of which could be
modified? I'm thinking aloud and don't know if that would be an option.
Thanks in advance.
