Jump to content

Windows 7 Applocker application


davidmoore
 Share

Recommended Posts

Hi,

The idea behind AppLocker seems to be good. What I like the most is Publisher Based rules. However let's say I create a rule that says:

"Allow all files digitally signed by Microsoft"

What prevents someone from spoofing a signature? Can someone get a signing tool and sign their malware as if they were Microsoft? or how does Microsoft prevent the Publisher Rules feature from being a huge security hole?

Can someone please explain?

Regards,

Dave

Link to comment
Share on other sites

Hi,

The idea behind AppLocker seems to be good. What I like the most is Publisher Based rules. However let's say I create a rule that says:

"Allow all files digitally signed by Microsoft"

What prevents someone from spoofing a signature? Can someone get a signing tool and sign their malware as if they were Microsoft? or how does Microsoft prevent the Publisher Rules feature from being a huge security hole?

Can someone please explain?

Regards,

Dave

Hi Dave, and Welcome.

how does Microsoft prevent the Publisher Rules feature from being a huge security hole?

That is one of the questions I also had also been wondering about recently.

I looked all through **Here** and also read the article **Here**after that, I read some more **Here**

I then found an article on "Signed Applications" which I read through **Here**

I was fortunate in my search and found this little snippet:

"Can AppLocker rules be created to allow certain computer users to access a program and deny access to others?"

"Yes, you can target AppLocker rules to users and groups. You can create as many rules as you want for the same application. For example, you could have one rule that allows the Finance group to run winword.exe, and you could also have a second rule that allows the HR group to run winword.exe."

After searching for some while I was finding that my original questions were becoming blurred at the edges, and I had forgotten what I was searching for !! :angry:

If you could continue the quest in those hallowed halls of Microsoft where I have left off, and are lucky enough to come upon the answer, I would be grateful if you would publish it here.

Can someone get a signing tool and sign their malware as if they were Microsoft?

I got so sick of looking, that in the end I came to the conclusion that it was dependent if the signing tool was either "Metric" or "Whitworth" :lol: (That is a measurement joke by the way)

Let us know how you get on, and your findings Dave.

Link to comment
Share on other sites

Hi,

I got an answer in another forum that seems to be as close as I could get to getting the truth out of this. I didn't find anything else, and that's kind of upsetting as this is an important issue.

--

Q/ What prevents someone from spoofing a signature? Can someone get a signing tool and sign their malware as if they were Microsoft? or how does Microsoft prevent the Publisher Rules feature from being a huge security hole?

A/ There is another thing that you have missed. Each signing certificate MUST chain up to trusted root certification authority that is installed in LocalComputer store. Standard users (users with no admin rights) cannot add their own roots to computer store, therefore you will unable to run signed software if signing certificate chain is not trusted. There is no way to restrict users with administrator rights.

--

If someone has additional information, please share.

HTH

Link to comment
Share on other sites

Hi,

I got an answer in another forum that seems to be as close as I could get to getting the truth out of this. I didn't find anything else, and that's kind of upsetting as this is an important issue.

--

Q/ What prevents someone from spoofing a signature? Can someone get a signing tool and sign their malware as if they were Microsoft? or how does Microsoft prevent the Publisher Rules feature from being a huge security hole?

A/ There is another thing that you have missed. Each signing certificate MUST chain up to trusted root certification authority that is installed in LocalComputer store. Standard users (users with no admin rights) cannot add their own roots to computer store, therefore you will unable to run signed software if signing certificate chain is not trusted. There is no way to restrict users with administrator rights.

--

If someone has additional information, please share.

HTH

.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=

If we find out any more, we can all share it over at the TechNet thread that you started on the same day if you like Dave. Save a bit of bandwidth and the clogging up of the old intertubes thingy.

Even when you go direct to source you cant always get a straight answer can you ? Bugger aint it ?

carlos.jpg

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy