home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!rpi!ghost.dsi.unimi.it!univ-lyon1.fr!chx400!csghsg5a.bitnet!msieber
- From: msieber@csghsg5a.bitnet
- Newsgroups: comp.os.ms-windows.programmer.win32
- Subject: NT - Security & Eventlog & PVIEW.EXE
- Message-ID: <1992Dec26.231423.343@csghsg5a.bitnet>
- Date: 26 Dec 92 23:14:23 GMT
- Organization: University of St.Gallen, Switzerland
- Lines: 47
-
- NT Security and PVIEW (Process View)
-
- PVIEW.EXE is a sample Program on the CD-ROM. It shows
- all processes and threads. You can also kill a process,
- i.e. terminate a process in a way, that he doesnt ask
- you anything about "save current changes" and all.
-
- I noticed something strange:
- There's a user TEST on my PC. This user isn't even
- a member of the group USER or GUESTS. And, of course
- he is unable to stop the service "EVENTVIEWER".
-
- Well, that's ok, because else he could first stop
- (or pause) the process EVENTLOG and then hack around
- in the system....
-
- But if TEST starts Process View, he can kill the process
- eventlog.exe and then the process is reported
- (by ControlPanel - Services) as stopped. And after
- doing something uncontrolled by EventLog(maybe try out some
- passwords for administrator....) he can start the service
- again. So no administrator realizes anything!
-
- So I thought it would help to configure the Service
- EventLog with "Logon as Administrator". But it didn't help
- at all!
-
- My user Test can still kill the process EVENTLOG!
-
- While my PC is standalone and there is no security-relevant
- data on it, maybe other people (Network - Administrators etc.)
- would not be pleased, that any user can "turn off" auditing
- even if they are not allowed to do so. PVIEW with its DLL
- fits on one DD-Disk and can be started in Program - Manager
- with FILE-RUN ....
-
- On my PC both partitions are (still) FAT. That should
- not change a lot about it, except, that maybe(?) with
- NTFS the User Test can't restart the service Eventlog
- again.
-
- Well as stated above, this problem doesn't really worry ME,
- but I hope MS won't miss the C2-Security standard with that!
-
- Martin Sieber
-
-
-