Jump to content

Disable mouse double left click on Start Menu


wedge554
 Share

Recommended Posts

hi guys. after testing an installation of windows server 2003 and xp as a client we have stumbled across a major windows flaw. IT IS MAJOR MAJOR!

If you double left click the startup or accessories folder on any server setup you can access the main root of a server with the "up" toolbar button?

thats CR*P you say? i thought that! - anybody know how to disable this in the registry???

IM GOING CRAZY!!! - its a hackers dream!

Link to comment
Share on other sites

I wouldn't worry much about double clicks. I would worry more about user rights. If your logged on interactively, which is sounds like you are, I see no reason why this wouldn't happen. By root do you mean %homedrive% (usually C)? If so the Everyone group has permission to it, if I remember right. I don't have Server 2003 installed right now to see but I think thats right. Theres major differences in local security policy, domain security policy and domain controller security policies. That may be were some confusion is. Its just hard to believe clicking the start menu twice will break through permissions that secure hundreds of thousands of computers if not more.

One interesting thing to try is opening up a command prompt and entering "at 12:34 /interactive cmd.exe", without quotes and with 12:34 to your local time. This will give you a command prompt running in the system account. People should not really have access to this, its meant more for programs to run in. But at the same time Microsoft allows it and has for a long time for administrators. Its not a hole or privilege escalation like most people think. You can even shutdown explorer, start a new instance of it, go to the start button and it will say SYSTEM instead of the username. Its interesting but disabled in Vista, so its worth a try in XP. PS. You can't really do more with it than you can in an admin account, so don't get excited.

Link to comment
Share on other sites

the problem actually lies in the all programs folder not the start menu. We have gone through permissions numerous times. The fact that the folders are stored on the server and not the local system opens the paths up.

Unless we block the "everyone" permission we wont be able to block it. but we have made it impossible for people to see things in the root directories.

any help would still be appreciated. were going to research into a more powerful OU permission programs.

Link to comment
Share on other sites

You could just remove the everyone group. Its good practice to not block anyone unless there is no other choice. If you want more security you could use a better template. I don't think there is a such thing as more powerful permissions. Just more secure templates. Once the everyone group is gone add the admin group or whatever users you want and make sure their permissions are inherited through out the drive. Another good thing is when your checking a folders/file permission you can look up the effective permissions for a user or group. This will tell you what all that user or group can do to that object.

I also think were some of this may be coming from is a special permission called Traverse folders. This allows users to move through folders to get to the folder they want. If you remove this permission and the accounts you don't want that should fix the problem. It just takes some digging through accounts and folders. Once done you can apply it to your OU or whatever.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy