PC Review


Reply
Thread Tools Rate Thread

Securing MSIs to prevent theft

 
 
MadDHatteR
Guest
Posts: n/a
 
      23rd May 2004
We provide a number of licensed applications (Adobe Acrobat, Office, etc.)
to our users via machine-assigned GPOs. In order for self-repair and
installation to occur, all our domain users must have read-access to the
MSIs. By hapenstance, the users have discovered where the MSIs are stored,
and have taken to copying them and installing them without authorization (at
home, or on other computers).

How have other admins dealt with this issue? How does one secure an MSI to
prevent theft, yet still allow self-repair and automated GPO installation?
(I'm all ears for ideas, links, or in-use solutions.)

Thanks,
\\ MadDHatteR


 
Reply With Quote
 
 
 
 
=?Utf-8?B?Sk9obk0=?=
Guest
Posts: n/a
 
      4th Jun 2004
I could think of a couple of ways to stop this.

1. use UNC paths in your sourcelists but hide the shares.

2. put custom actions in the system that require something [%UserDomain] = "your domain" run a type 19 CA if the condition is not met.

darwin sanoy has a couple of scripts which can achieve this.

 
Reply With Quote
 
 
 
 
MadDHatteR
Guest
Posts: n/a
 
      6th Jun 2004
JOhnM

Thanks for the ideas -- it's nice to get some kind of reply. I was really
hoping someone had a sure-fire answer already figured out. As I suspected
however, it seems this feature was left out of the MSI and/or GPO software
deployment specification.*

The ideas I've come up with include inserting a custom action, altering the
UI Execute table so the MSI will not install by "just double-clicking"
(since these MSIs are strictly intended to be deployed via GPO), copying
MSIs local to the boxes and using "install elevated" so normal users can't
copy them, and of course what you mentioned below.

A custom action is limited in usefullness because many MSIs we deploy we
cannot edit/recompile/transform -- usually because they are not written well
(I can't think of an example right now... but I know we've run into this
problem before). I haven't looked much into modifying the UI Execute
table -- I only suggest it because I suspect with a GPO installation that
table might not be used... I need to do more research on this. Copying MSIs
locally is a cubersome option and the install elevated introduces security
risks I'd rather avoid.

In short, I don't think there's a GOOD answer, so I guess it's a
hack-something-together sort of thing :-(.

* If a Microsoft employee reads this, please consider including a means to
specify public properties (like the license key, for example) of an MSI when
deploying via GPO. This would simply and securely provide access control for
MSIs and prevent users from making illegal use of software. The license key
would live in Active Directory with the GPO's ACL (i.e. users couldn't see
it), and would remain separate from the MSI so the MSI was not usable
without authorization from IT.

\\ MadDHatteR

"JOhnM" <(E-Mail Removed)> wrote in message
news:299D3A2F-AA6F-4C70-A798-(E-Mail Removed)...
> I could think of a couple of ways to stop this.
>
> 1. use UNC paths in your sourcelists but hide the shares.
>
> 2. put custom actions in the system that require something [%UserDomain] =

"your domain" run a type 19 CA if the condition is not met.
>
> darwin sanoy has a couple of scripts which can achieve this.
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Issues with MSIs that affect IIS TLB Windows Vista General Discussion 0 10th May 2007 05:51 AM
Securing data against theft of the server or hackers Nick Gilbert Microsoft ASP .NET 7 31st May 2004 01:43 AM
How to prevent theft of BOTH secured Access database AND .mdw file Jacob Microsoft Access Security 9 14th Apr 2004 05:10 AM
How to prevent hostname theft? =?ISO-8859-15?Q?J=F6rg_Sch=FCtter?= Microsoft Windows 2000 DNS 13 23rd Mar 2004 03:53 PM
(OT) Software to "Wipe" Contents of Hard Drive, Prevent Identity Theft, Etc. benalias@hotmail.invalid Freeware 8 30th Sep 2003 10:51 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:57 PM.