PC Review


Reply
Thread Tools Rate Thread

Disable share GUI while keeping File and printer sharing

 
 
tzvikaz@gmail.com
Guest
Posts: n/a
 
      22nd Mar 2007
Hi,
I have a "kiosk" machine that runs on XP SP2.
It must have File and Printer Service.
The logged user is an admin.
I want to somehow not allow him to add shares on folders/drives or if
its impossible to know that he did.

any ideas?

 
Reply With Quote
 
 
 
 
Lanwench [MVP - Exchange]
Guest
Posts: n/a
 
      22nd Mar 2007
(E-Mail Removed) wrote:
> Hi,
> I have a "kiosk" machine that runs on XP SP2.
> It must have File and Printer Service.
> The logged user is an admin.
> I want to somehow not allow him to add shares on folders/drives or if
> its impossible to know that he did.
>
> any ideas?


Why must the logged in user be an admin? There's very little you can do if
someone has local admin rights. This is not a recommended configuration.


 
Reply With Quote
 
tzvikaz@gmail.com
Guest
Posts: n/a
 
      25th Mar 2007

> Why must the logged in user be an admin? There's very little you can do if
> someone has local admin rights. This is not a recommended configuration.


I understand, the reason for this it too complicated for me to
explain.
It has to be that way.
What I want to do is have my application that runs on that pc know
that someone just created a share on the HD and when knowing this
disabling the application. This solution is good enough for me.
How Can I know though that a new share was created?

Sorry about the multiple posts btw.

 
Reply With Quote
 
Lanwench [MVP - Exchange]
Guest
Posts: n/a
 
      25th Mar 2007
(E-Mail Removed) wrote:
>> Why must the logged in user be an admin? There's very little you can
>> do if someone has local admin rights. This is not a recommended
>> configuration.

>
> I understand, the reason for this it too complicated for me to
> explain.
> It has to be that way.
> What I want to do is have my application that runs on that pc know
> that someone just created a share on the HD and when knowing this
> disabling the application. This solution is good enough for me.
> How Can I know though that a new share was created?
>
> Sorry about the multiple posts btw.


I don't know of anything, sorry. You might try a scripting group, maybe.


 
Reply With Quote
 
Harry Johnston
Guest
Posts: n/a
 
      26th Mar 2007
(E-Mail Removed) wrote:

> I have a "kiosk" machine that runs on XP SP2.
> It must have File and Printer Service.
> The logged user is an admin.
> I want to somehow not allow him to add shares on folders/drives


If the logged on user really needs to be an admin, your best bet is to use
software restriction policies (try doing a search of MSDN or the Microsoft
Knowledge Base on that phrase if you aren't familiar with the concept) to
configure a set of allowed executables and block everything else. You need to
think carefully about the effects of each executable on the list; for example,
Windows Explorer should not be permitted, so you'll also need to provide an
alternative shell. In general, any software that allows copying an arbitrary
file or editing a text file isn't safe.

In almost all cases it would be both safer and easier to work around the need
for the user to be an admin. Are you certain this isn't an option?

Microsoft provide a toolkit for shared computers which restores the computer to
the initial state after a reboot, this may provide some additional protection.
Or (better) you could run the kiosk functions on a virtual machine, configured
not to keep changes after reboot. (This might make it OK to allow Windows
Explorer, since it blocks the obvious attack of installing a second operating
system; however, I suspect Windows Explorer would still allow more subtle
attacks even if I can't identify them offhand. You also need to think about
possible attacks on your kiosk application, though you might be able to block
those by putting the kiosk application and data files on the host OS and
accessing them over a virtual network.)

In this context, the File and Printer Service might not need to be on the same
virtual machine as the logged on user, which could provide additional protection.

Harry.
 
Reply With Quote
 
Harry Johnston
Guest
Posts: n/a
 
      26th Mar 2007
(E-Mail Removed) wrote:

> What I want to do is have my application that runs on that pc know
> that someone just created a share on the HD and when knowing this
> disabling the application. This solution is good enough for me.
> How Can I know though that a new share was created?


NetShareEnum. However, unless you take precautions such as those I describe in
my other post, the user will be able to easily kill or disable your monitoring
application.

Harry.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Disable share GUI while keeping File and printer sharing tzvikaz@gmail.com Windows XP Customization 1 28th Mar 2007 12:07 AM
Disable share GUI while keeping File and printer sharing tzvikaz@gmail.com Windows XP General 2 22nd Mar 2007 04:43 PM
File and Printer Sharing - Missing Share =?Utf-8?B?aHVudGVyYW5k?= Windows XP Networking 4 6th Feb 2007 10:09 PM
file share. printer sharing does not work xp to xp howard Windows XP Networking 1 18th Jul 2004 08:09 PM
No file sharing, but can share printer MLO Windows XP Networking 2 27th May 2004 03:00 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:19 PM.