Page 1 of 2 12>
Topic Options
#56303 - 2001-06-06 03:33 PM Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
Please somebody let me know how to disable folppy drive for NTWKS without Admin Privilage

Itried REGINI, FlOPPYLOCK, all this need Local Admin Privilage,I havent seen any solutin on preevious archives also.

Any other way???

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56304 - 2001-06-06 04:06 PM Re: Help!!!!!!!!!!!!!!!
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
Hi Saleem,

You're caught in the classic "Windows NT Security Catch-22" You're trying to perform an administrative task - using a user's context (logon script). When you really think about it - anything that can be done in the login script can also (by default) be un-done by the user.

I think you might only have one option here - and that is to build an "administrative" KiXtart script that scans a list of hostnames (in a flatfile), then copies floplock out to each workstation, then uses something like XNET and SC to remotely install and activate it...

The other benefit of doing it remotely is that once it's installed on all your workstations - you can discard the script - as opposed to having to leave it in the logon script (forever) to support future workstation deployment (assuming that you'll be rolling FLOPLOCK into your new "workstation images")

I mean - the only other thing you can do is to "hide" the A: drive - and we all know what a "joke" that is...

It's too bad Microsoft didn't design the logon process to run at an "elevated" security level (eg, at local admin level). If properly implemented, I don't think this would have introduced many serious security holes. Oh well !

How many workstations are we talking about here ?

-Shawn

Top
#56305 - 2001-06-06 04:14 PM Re: Help!!!!!!!!!!!!!!!
Jochen Administrator Offline
KiX Supporter
*****

Registered: 2000-03-17
Posts: 6380
Loc: Stuttgart, Germany
Saleem,

have you ever thought of disabling it at a lower level ? Means disable it in the BIOS ?
Could be an alternative if there are not too many Workstations ...

Jochen

_________________________



Top
#56306 - 2001-06-06 04:30 PM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
Thanx for ur immediate response..

Shawan-- I think ur suggetion is bit complex way, I 'll see it as a last option.

jpols-- I have more than 200 WKS scatered diffrent locations it's very hard to go induviduel pc's and work on BIO's setup.

I wish if I could get any Utility.

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56307 - 2001-06-06 04:37 PM Re: Help!!!!!!!!!!!!!!!
Jochen Administrator Offline
KiX Supporter
*****

Registered: 2000-03-17
Posts: 6380
Loc: Stuttgart, Germany
Saleem,

ok, i see : BIOS is no option for you ...

Have you already tried shipping around Security with SU.exe .?
just start a search on Starters and Scripts forums searching for SU and you'll get a 100+ hits .

Jochen

[This message has been edited by jpols (edited 06 June 2001).]

_________________________



Top
#56308 - 2001-06-06 04:45 PM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
I never tried SU I think i SU we have to provide Admin user id and passwored in a clear text fromat right ?? if that so again I have pain, cause My WKS Admin passwored's are not common one.
_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56309 - 2001-06-06 05:08 PM Re: Help!!!!!!!!!!!!!!!
Jochen Administrator Offline
KiX Supporter
*****

Registered: 2000-03-17
Posts: 6380
Loc: Stuttgart, Germany
Saleem,

i replied to your mail !

Jochen

_________________________



Top
#56310 - 2001-06-06 07:42 PM Re: Help!!!!!!!!!!!!!!!
Anonymous
Unregistered


Well ... why not let Winlogon run the file in system context?
See

http://www.winguides.com/registry/display.php/210/

Hope it'll help you.

[This message has been edited by Strøm (edited 06 June 2001).]

Top
#56311 - 2001-06-06 08:57 PM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
Strom

could u specify a bit more??

Like which file and how ??

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56312 - 2001-06-06 09:03 PM Re: Help!!!!!!!!!!!!!!!
Shawn Administrator Offline
Administrator
*****

Registered: 1999-08-13
Posts: 8611
A very neat and clever idea but I think this might be security catch-22 again. This key is Everyone read-only - so how would Saleem bootstrap this value into the registry (through the logon script without a plain-text password) ?

-Shawn

Top
#56313 - 2001-06-07 04:31 AM Re: Help!!!!!!!!!!!!!!!
MCA Offline
KiX Supporter
*****

Registered: 2000-04-28
Posts: 5152
Loc: Netherlands, EU
Dear,

SU works great. It is possible to make your administrator password
invisible by using the tools
bat2exec and secure21
which you can find at our site
http://home.wanadoo.nl/scripting
Information on the board
http://kixtart.org/board/Forum2/HTML/001443.html
http://kixtart.org/board/Forum2/HTML/001558.html

Another way is the usage of policy settings, which work always with the
sufficient rights.
Greetings.

------------------
Site map:

_________________________
email scripting@wanadoo.nl homepage scripting@wanadoo.nl | Links | Summary of Site Site KiXforms FAQ kixtart.org library collection mirror MCA | FAQ & UDF help file UDF kixtart.org library collection mirror MCA | mirror USA | mirror europe UDF scriptlogic library collection UDFs | mirror MCA

Top
#56314 - 2001-06-07 09:46 AM Re: Help!!!!!!!!!!!!!!!
Anonymous
Unregistered


- Shawn

Well ... start Scheduler Service in system account ... have AT open a CMD, then the key should be editable (sorry, I can't get to test right now.).

Roll-out by using system policy.

Top
#56315 - 2001-06-07 11:13 AM Re: Help!!!!!!!!!!!!!!!
cj Offline
MM club member
*****

Registered: 2000-04-06
Posts: 1102
Loc: Brisbane, Australia
What about mailing those cool 'put this in the floppy drive and turn the key' locking things to each office. Get the receptionist/cleaner to go to every desk and 'lock the floppy'. She then returns the 1 key you sent her (that locks all thingies) to you and unless someone gets a key or breaks it off you are more-or-less safe.


cj



Top
#56316 - 2001-06-07 05:58 PM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
I am testing SU now and I found out SU has to be installed as a service, which again required admin privilage !!!!!

Any way ??

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56317 - 2001-06-07 06:27 PM Re: Help!!!!!!!!!!!!!!!
Bryce Offline
KiX Supporter
*****

Registered: 2000-02-29
Posts: 3167
Loc: Houston TX
http://kix.isorg.net/other_scripts/su

Bryce

------------------
kix.isorg.net

Top
#56318 - 2001-06-07 06:42 PM Re: Help!!!!!!!!!!!!!!!
bleonard Offline
Seasoned Scripter
*****

Registered: 2001-01-19
Posts: 581
Loc: Chicago, IL
Saleem -
Since no script examples posted...

Have you tried regkey
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon, AllocateFloppies, 0, REG_SZ" ?

I have not tried, but hack resource indicates value of 0 locks access except for all administrators in the Domain, value of '1' only the user logged on locally can access the floppy disks in the drive.

I have not tried this, nor am I sure a non-Admin can write to this key. Should only work in WinNT/2K. If you try in your test environment, please let the Board know how things went.

Bill

Top
#56319 - 2001-06-07 07:38 PM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
Sorry budy............. It's not working.
_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56320 - 2001-06-09 12:41 AM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
Guys

I am very close to victory……. See my code

$flokey="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Floppy\"
$flokeyval="Start"
$Flodata="4"
$flotype="REG_DWORD"

$rkey=readvalue($flokey,$flokeyval)

if (ingroup ("ITD Global Group") or INGROUP("ENABLEDA"))= 0
if ($rkey <> $Flodata)
shell "call \\server\hideshare$\log1.bat"
$wr=WRITEVALUE($flokey,$flokeyval,$flodata,$flotype)
endif
endif

Log1.bat

\\fileprintho\ssaver$\su 000182 < c:\pass.txt “\\sever\hideshare$\regini \\server\hideshare$\reg.txt”

Now my only concern is about reg.txt which is a plain text , A high security breech !!!

How can I tackle this ??

Hey …….. Thanks very much for ur valuable suggestion guys…. Really it helped me a lot..

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56321 - 2001-06-09 12:44 AM Re: Help!!!!!!!!!!!!!!!
Saleem Offline
Hey THIS is FUN
*

Registered: 2001-04-11
Posts: 280
Loc: UAE
SORRY.............. NOT REG.TXT

PASS.TXT WHERE I AM WRITING ADMIN PASSWORED

_________________________
“I’ll not change you unless you don’t have intention to change yourself” --H:Quran

Top
#56322 - 2001-07-19 11:22 AM Re: Help!!!!!!!!!!!!!!!
Anonymous
Unregistered


Take a look at Microsoft KB article "How to Restrict Floppy Disk Drive Access Using Floplock Service [Q185704]"
Top
Page 1 of 2 12>


Moderator:  Glenn Barnas, NTDOC, Arend_, Jochen, Radimus, Allen, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 1574 anonymous users online.
Newest Members
BeeEm, min_seow, Audio, Hoschi, Comet
17882 Registered Users

Generated in 0.083 seconds in which 0.036 seconds were spent on a total of 13 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org