Difference between revisions of "Securing Truxton Services"

From truxwiki.com
Jump to navigation Jump to search
Line 1: Line 1:
=Securing Truxton Services=
+
If you must operate in a more "locked down" mode, [https://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002 FISMA] for instance, you must change how Truxton's services run.
  
To find out what the permissions are for a service, use the "<code>sc sdshow</code>" command:
+
=How Secure Truxton Services=
 +
To find out what the permissions are for a service, use the <code>sc sdshow</code> command:
 
<source lang="cmd">
 
<source lang="cmd">
 
sc sdshow Les
 
sc sdshow Les
Line 19: Line 20:
 
</source>
 
</source>
  
A better way to begin to understand it is by adding spaces and new line:
+
A better way to begin to understand it is by adding spaces and line breaks:
 
<pre>D:
 
<pre>D:
 
(A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU)
 
(A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU)
Line 55: Line 56:
 
</source>
 
</source>
  
==Links==
+
==External links==
 
* [https://web.archive.org/web/20200719210404/https://support.microsoft.com/en-us/help/914392/best-practices-and-guidance-for-writers-of-service-discretionary-acces Microsoft Guidlines]
 
* [https://web.archive.org/web/20200719210404/https://support.microsoft.com/en-us/help/914392/best-practices-and-guidance-for-writers-of-service-discretionary-acces Microsoft Guidlines]
 +
* [https://web.archive.org/web/20150810083345/http://networkadminkb.com/KB/a152/how-to-read-a-sddl-string.aspx How to Read SDDL]

Revision as of 12:33, 26 January 2021

If you must operate in a more "locked down" mode, FISMA for instance, you must change how Truxton's services run.

How Secure Truxton Services

To find out what the permissions are for a service, use the sc sdshow command:

sc sdshow Les
sc sdshow Truxton
sc sdshow TruxtonDatabase

On my machine, it produces this lovely string:

D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)

You can use the Powershell ConvertFrom-SddlString command to convert it to something humanly readable.

ConvertFrom-SddlString -Sddl "D:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)" | Foreach-Object {$_.DiscretionaryAcl}

A better way to begin to understand it is by adding spaces and line breaks:

D:
(A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BU)
(A;;CC LC SW RP WP DT LO CR RC;;;SY)
(A;;CC DC LC SW RP WP DT LO CR SD RC WD WO;;;BA)
(A;;CC LC SW LO CR RC;;;IU)
(A;;CC LC SW LO CR RC;;;SU)

The most common permissions to alter are DC, WD and WO.

Code Meaning
DC Change Configuration (aka Write Data)
WD Change Permissions (aka Write Descriptor)
WO Take Ownership (aka Write Owner)

It looks like the BuiltIn Users is the culprit. Let's change the BU part to get rid of those:

(A;;CC LC SW RP WP DT LO CR SD RC;;;BU)

Start a command prompt as Administrator then:

sc sdset Les D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
sc sdset Truxton D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
sc sdset TruxtonDatabase D:(A;;CCLCSWRPWPDTLOCRSDRC;;;BU)(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)

External links