Difference between revisions of "Securing Truxton Services"
Jump to navigation
Jump to search
| Line 1: | Line 1: | ||
| − | + | If you must operate in a more "locked down" mode, [https://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002 FISMA] for instance, you must change how Truxton's services run. | |
| − | To find out what the permissions are for a service, use the | + | =How Secure Truxton Services= |
| + | To find out what the permissions are for a service, use the <code>sc sdshow</code> command: | ||
<source lang="cmd"> | <source lang="cmd"> | ||
sc sdshow Les | sc sdshow Les | ||
| Line 19: | Line 20: | ||
</source> | </source> | ||
| − | A better way to begin to understand it is by adding spaces and | + | A better way to begin to understand it is by adding spaces and line breaks: |
<pre>D: | <pre>D: | ||
(A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU) | (A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU) | ||
| Line 55: | Line 56: | ||
</source> | </source> | ||
| − | == | + | ==External links== |
* [https://web.archive.org/web/20200719210404/https://support.microsoft.com/en-us/help/914392/best-practices-and-guidance-for-writers-of-service-discretionary-acces Microsoft Guidlines] | * [https://web.archive.org/web/20200719210404/https://support.microsoft.com/en-us/help/914392/best-practices-and-guidance-for-writers-of-service-discretionary-acces Microsoft Guidlines] | ||
| + | * [https://web.archive.org/web/20150810083345/http://networkadminkb.com/KB/a152/how-to-read-a-sddl-string.aspx How to Read SDDL] | ||
Revision as of 12:33, 26 January 2021
If you must operate in a more "locked down" mode, FISMA for instance, you must change how Truxton's services run.
How Secure Truxton Services
To find out what the permissions are for a service, use the sc sdshow command:
sc sdshow Les
sc sdshow Truxton
sc sdshow TruxtonDatabaseOn my machine, it produces this lovely string:
D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
You can use the Powershell ConvertFrom-SddlString command to convert it to something humanly readable.
ConvertFrom-SddlString -Sddl "D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)" | Foreach-Object {$_.DiscretionaryAcl}
A better way to begin to understand it is by adding spaces and line breaks:
D: (A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU) (A;;CC LC SW RP WP DT LO CR RC;;;SY) (A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BA) (A;;CC LC SW LO CR RC;;;IU) (A;;CC LC SW LO CR RC;;;SU)
The most common permissions to alter are DC, WD and WO.
| Code | Meaning |
|---|---|
| DC | Change Configuration (aka Write Data) |
| WD | Change Permissions (aka Write Descriptor) |
| WO | Take Ownership (aka Write Owner) |
It looks like the BuiltIn Users is the culprit. Let's change the BU part to get rid of those:
(A;;CC LC SW RP WP DT LO CR SD RC;;;BU)
Start a command prompt as Administrator then:
sc sdset Les D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
sc sdset Truxton D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
sc sdset TruxtonDatabase D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)