ITGURU Posted May 18, 2016 Posted May 18, 2016 Hi Looking for some advice what to do in this situation. I have 2 policies in place: - Removable drives, blocking of copying or opening ZIP or executable files which can be released per user, rather than per computer so can be excluded if necessary for that user. - FSRM - blocking .exe files on a shared drive - to protect from cryptolocker and other viruses creating executable files. However, I have a member of staff who wants to copy several resources from their USB drive to the network drives. Other than unchecking the block .exe files from FSRM whenever they want to copy the files across, is there any other way around this?
Steve21 Posted May 18, 2016 Posted May 18, 2016 Guess that depends if you want that one user to always be able to copy to it or not, or did you mean like disabling it temporary but just for one user? You could always just create a folder within it that only they have permissions on and block the FSRM from that folder. (Depends if these resources need to go in other places, but if they can't run exe's what's the point as such? :s) But surely if you have the entire drive blocked via SRP/AppLocker from running exe's in the first place (assuming this is like a Staff Shared area) then even if a virus copies exe there it wouldn't do anything? Steve
ITGURU Posted May 18, 2016 Author Posted May 18, 2016 Guess that depends if you want that one user to always be able to copy to it or not, or did you mean like disabling it temporary but just for one user? You could always just create a folder within it that only they have permissions on and block the FSRM from that folder. (Depends if these resources need to go in other places, but if they can't run exe's what's the point as such? :s) But surely if you have the entire drive blocked via SRP/AppLocker from running exe's in the first place (assuming this is like a Staff Shared area) then even if a virus copies exe there it wouldn't do anything? Steve The users are able to run exe files from network shares, but obviously only those that we have put there by the users coming through us to copy them over of which I have to disable the FSRM rule temporarily whilst I copy over. They will need to copy to several folders so excluding one wouldn't be an option. I am thinking more on the client end, that if they ran an exe off a network share this could propagate and create additional exe files. In addition, the AV on the server is also set to block remote creation of exe files, so protected in all ways. We've had about 3 instances of Crytolocker but it has only affected that individual users space and created html and txt files, due to the tight restrictions, and therefore only had to restore the single user area from the night before, so what I have in place has been beneficial.
Steve21 Posted May 18, 2016 Posted May 18, 2016 The users are able to run exe files from network shares, but obviously only those that we have put there by the users coming through us to copy them over of which I have to disable the FSRM rule temporarily whilst I copy over. They will need to copy to several folders so excluding one wouldn't be an option. Slightly confused now. :s Not sure if I misunderstood. So in our example we have a Staff Shared Drive. - SRP blocks everything exe wise from this, but Staff have access to copy things over to it without an issue. We then have an Apps Drive - SRP allowed to run, but Staff have no write access to this, so FSRM isn't needed. That way we copy exes to the Apps Drive without requiring FSRM removed each time, and they can copy resources to Staff Shared without our intervention. If they copy a dodgy exe to Staff Shared it can't run anyway. If that makes sense? Steve
ITGURU Posted May 18, 2016 Author Posted May 18, 2016 Slightly confused now. :s Not sure if I misunderstood. So in our example we have a Staff Shared Drive. - SRP blocks everything exe wise from this, but Staff have access to copy things over to it without an issue. We then have an Apps Drive - SRP allowed to run, but Staff have no write access to this, so FSRM isn't needed. That way we copy exes to the Apps Drive without requiring FSRM removed each time, and they can copy resources to Staff Shared without our intervention. If they copy a dodgy exe to Staff Shared it can't run anyway. If that makes sense? Steve On the staff shared drive, if you are blocking .exe files, how can they still copy exe files to it?!
Steve21 Posted May 18, 2016 Posted May 18, 2016 Because SRP only blocks them running, nothing to do with copying the files onto it. So if a user wants to backup/store their entire USB stick on the drive as a backup (as an example) it'll all copy over, just exe's are blocked via SRP when they try to run them unless we put them onto the Apps server. Steve
ITGURU Posted May 18, 2016 Author Posted May 18, 2016 Because SRP only blocks them running, nothing to do with copying the files onto it. So if a user wants to backup/store their entire USB stick on the drive as a backup (as an example) it'll all copy over, just exe's are blocked via SRP when they try to run them unless we put them onto the Apps server. Steve Oh I see - thanks!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now