Why is "Act as part of the operating system" dangerous?

Ask a Question related to ASP.NET Security, Design and Development.

  1. #1

    Default Why is "Act as part of the operating system" dangerous?

    Hello everybody:

    I have a question: Why is "Act as part of the operating system"
    dangerous? I have an application that will go live on Windows 2000,
    and it impersonates a user; I have to enable it (it copies some files
    in the server and creates a new IIS application on the server. That's
    why it needs to impersonate a user) I am using LogonUser.

    Thanks!

    Arturo
    Arturo Guest

  2. Similar Questions and Discussions

    1. Is it dangerous to set "JRunConfig Verbose true"?
      When used together with Apache, CFMX702 setup generates a JRun Settings section in httpd.conf. Two lines are of particular interest. They are ...
    2. Getting "A potentially Dangerous Request.Cookies Value" error
      Hello, I recently upgraded from VS.NET 2002 to VS.NET 2003. Since I did that, I receive the following error from time to time: A potentially...
    3. Windows Server 2003/IIS 6.0/ASP.NET "Could not find a part of the path"
      I have an ASP.NET web application running on a load-balanced Windows Server 2003 web farm running IIS 6.0, using Active Directory authentication. ...
    4. Sony DSC-F1 Video Connector?? "Battery adapter attaching part"???
      Sony DSC-F1 Video Connector? What's the connector for the DSC-F1 Video Out? If I stuff in a 1/8" phone plug, I get video out. Problem is that...
    5. Lsass.exe System error "object name not found". System keeps rebooting
      When trying to install the drivers for the PCI modem in my laptop, prompted for the driver CD. Installed the driver without any errors but asked...
  3. #2

    Default Re: Why is "Act as part of the operating system" dangerous?

    Act as Part of the Operating System allows the account to do stuff directly
    in kernel mode, bypassing the entire Windows security system if it wants to.
    Essentially, the account is equivalent to SYSTEM.

    Does that answer the question adequately?

    Did you consider the possibility of factoring out this code into a seperate
    component that could run under COM+ so that you could specify a particular
    identity to run as? That would be much more secure? Alternately, moving to
    2003 server fixes this problem as well.

    Joe K.

    "Arturo" <arturo-g@lycos.com> wrote in message
    news:e1a45d36.0404130712.5c53e6a7@posting.google.c om...
    > Hello everybody:
    >
    > I have a question: Why is "Act as part of the operating system"
    > dangerous? I have an application that will go live on Windows 2000,
    > and it impersonates a user; I have to enable it (it copies some files
    > in the server and creates a new IIS application on the server. That's
    > why it needs to impersonate a user) I am using LogonUser.
    >
    > Thanks!
    >
    > Arturo

    Joe Kaplan \(MVP - ADSI\) Guest

  4. #3

    Default Re: Why is "Act as part of the operating system" dangerous?

    > Act as Part of the Operating System allows the account to do stuff directly
    > in kernel mode, bypassing the entire Windows security system if it wants to.
    > Essentially, the account is equivalent to SYSTEM.
    Thanks, Joe. I think I will create a console application and call it.
    That's the easyest solution so far. Thanks!

    Arturo
    Arturo Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139