| Article: |
Windows Server Hacks: Disable "Run As" | |
| Subject: | How does this help security? | |
| Date: | 2004-03-17 14:15:44 | |
| From: | sbonds | |
|
Forgive my ignorance, but how does this improve security? The security is in the password of the administrative user. Without that "ordinary users" won't be able to use "Run As" to do anything malicious.
|
||
Showing messages 1 through 2 of 2.
-
How does this help security?
2004-03-17 14:43:38 Mitch Tulloch |
[View]
-
How does this help security?
2004-03-18 12:01:23 Mitch Tulloch |
[View]
Another reason I like to disable RunAs is because of the new /savecred option on XP Professional desktops, see this NTBUGTRAQ posting for more:
http://archives.neohapsis.com/archives/ntbugtraq/2003-q3/0069.html



Also, the whole idea of having RunAs available on an ordinary user's desktop machine is a bit dangerous. The idea is convenience i.e. an administrator can run a program on a user's machine to fix something without requiring the user log off first. Imagine if a trojan was running on the user's machine when you did this...