Kyle Posted April 18, 2007 Posted April 18, 2007 I have not posted for a while because of personal reasons but have been reading the forums when i got chance. I have followed a few posts on setting up software restriction policies on users USB sticks. I have set it using USBAdmin that all USB sticks use the letter U:. I want to block all exe from running from this drive letter. My confusions is how o stop all exe from the drive. I know in the policy i can set it to block U:\*.exe but do i need to repeat this so it covers a lotof sub folder options ie; U:\*\*.exe and U:\*\*\*.exe and so on or is there a way of doing it only once so it blocks all exe no matter what level of folder the exe is in. ( i have just read my own question and not even sure if i have answered myself with my examples) Could someone help please?
Gambit Posted April 19, 2007 Posted April 19, 2007 I recently did this, and yes you need to specify for each level U:\*.exe U:\*\*.exe U:\*\*\*.exe etc., for as many sub folders as you wish, I only went 5 sub folders deep, I figured most kids would give up after that. This was the only way I know of. 1
ajbritton Posted April 19, 2007 Posted April 19, 2007 I think it's better to put a blanket block on executable and then create exceptions for the areas that users are allowed to launch EXEs from.
ChrisH Posted April 19, 2007 Posted April 19, 2007 Hmm there must be an easier way with the first examples . That does seem rather rubbish if you ask me.
Geoff Posted April 19, 2007 Posted April 19, 2007 With my security hat on, ajbrittons default deny method is a better solution. Although it'll be slightly more annoying to implement.
ChrisH Posted April 19, 2007 Posted April 19, 2007 I wonder if that trust no exe program would be a bit more flexible ?
MkII Posted April 19, 2007 Posted April 19, 2007 Had all sorts of problems with trust-no-exe - my machines just cycled in the end there were so many errors.
john Posted April 19, 2007 Posted April 19, 2007 My solution is switch to Vista, it has built in removable device filtering etc so you can stop certin things being run and used etc, may not be everything you need but worth looking into with other solutions
CyberNerd Posted April 19, 2007 Posted April 19, 2007 @John - wheres the software restriction policy to prevent exe's? AFAIK vista only blocks devices or sets read/write permissions on selected devices. blocking devices can be done with adm on 2k/xp
sreiach Posted April 20, 2007 Posted April 20, 2007 I had the same problem at work. After looking (and trying) several methods I've found the best is to white list method mentioned. All exe are blocked by default. I made sure to add all the recommended paths from MS and it seems to have worked as advertised. Just make sure you test out the policy first!
john Posted April 20, 2007 Posted April 20, 2007 @John - wheres the software restriction policy to prevent exe's? AFAIK vista only blocks devices or sets read/write permissions on selected devices. blocking devices can be done with adm on 2k/xp I did put that it probably won't do everything you need to, and it won't but it can be useful and I suspect they will build upon it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now