Preventing Execution of standalone EXEs from Flash Drive

Reply

Join Date: Jan 2004
Posts: 35
Reputation: QKSTechTrainee is on a distinguished road 
Solved Threads: 0
QKSTechTrainee's Avatar
QKSTechTrainee QKSTechTrainee is offline Offline
Light Poster

Preventing Execution of standalone EXEs from Flash Drive

 
0
  #1
Jun 19th, 2006
Hello All,

Now then - this is a nasty one.

We run a windows domain with 2003 Enterprise servers and XP Pro clients. About a year ago we removed all the floppy drives from our client machines and installed some swish new USB2.0 adaptors in their place, and started issuing USB Flash Pens to staff and students. So far so good.

It came to our attention recently that students were playing some stupid game on client machines, by running a no-install-necessary standalone .exe direct from the flash pens (we use Group Policy to prevent them from installing software or saving .exe's to their network mapped home drives).


So, discovering the name of the illicit .exe, it was simple enough to use Group Policy to prevent execution of the .exe in question, but still we have a problem - What do we do to prevent them from running .exe's the name of which we don't yet know? It seems that as we stand any of our users could run a (potentially devastating) program on a networked computer and we couldn't do a thing to prevent it. So - anyone know of any .adm's I can use to prevent execution of .exe's from removable storage?


Incidentally - does anyone else see this as a potentially fatal flaw in Microsofts security? I dread to think what could happen if some clever little bugger started compiling his own .exe's...
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Network Security Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC