This message was deleted.
# citrix-vad
s
This message was deleted.
j
Yes, do it in the build script to stop them being able to create subfolders. Hasn't broken anything
(Enforced by GPO also)
s
did something similar to C:\temp, but apparently it wasn't enough... Isn't this kind of like chasing wind though? They'll always have access to download/run things to their profile
j
Sure, but it cuts off binary planting attacks
Run accesschk from sysinternals and you will be amazed what weak permissions are all over your drive
s
yeah
j
accesschk64.exe -uwdqs Users c:\*
👍 2
And besides running anything from %USERPROFILE% should be blocked
s
like whitelisted, or just in general? what about Teams or Zoom or software that installs as a user
j
I don't let Teams install into the user profile, but you can use AppLocker to allow very specific items
Block everything but allow the bits you can't avoid (GTM was a pain for this, as was Bomgar)
s
make sense, I like that approach
j
The NTFS way stops a "bad app" from installing, say to c:\Apps (which it creates itself with weak perms), and then a user can drop a custom DLL in there with a name that the program uses, and because of PATH searching it loads the malicious DLL when the app launches. Remove the default C: drive permission, and the user can't write to C:\Apps any more - problem solved
s
yeah it does make sense, i just kept coming back to, the user still will have access to their 'downloads' directory to save/run things
but that doesn't mean the flood gates should be open
j
Save, sure, but execute - not really
👍 1
s
are you just removing the top perm?
j
Yes, that exact one, although the second one might need to go to
too*
Really they only need RX, AFAIK
s
sounds good, will do some testing.
were you using Applocker (or insert another whitelisting software tool) to prevent things from running in %USERPROFILE%? Or were you doing NTFS stuff there too?
j
AppLocker, I don't screw with NTFS on user profiles
👍 1