| Windows 7: Elevated Program Shortcut - Create for Standard User |
25 Oct 2011
|
#99 | | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise Texas |
Elevated Program Shortcut - Create for Standard User How to Create an Elevated Program Shortcut Any User is able to Run in Vista, Windows 7, and Windows 8
Last edited by Brink; 09 Apr 2013 at 01:05 PM..
| My System Specs |
| Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
14 Mar 2013
|
#100 | | 7x64 ultimate / 7x64 pro / Some linux x64 distro |
Hello, thanks you very much !
With the saved credentials, can the user, by a way or an other, start other .exe as admin by making the correct .lnk file ? | My System Specs |
| Computer type PC/Desktop OS 7x64 ultimate / 7x64 pro / Some linux x64 distro CPU i7-870 Motherboard MSI P55-GD85 Memory Kingston 4x2gb 1600 9-9-9 Graphics Card MSI GTX460 Cyclone 1GDDR5x2 + Gigabyte 285GTX 1GDDR5(PhysX) Sound Card Realtek alc 889 Monitor(s) Displays Samsung syncmaster 2333sw + some old acer screen Screen Resolution 3200x1024 Keyboard Razer Lycosa Mouse Razer Imperator PSU LC Power "Arkangel" 850W Case Aerocool BX-500 Cooling Noctua NH something Hard Drives WDC WD1500HLFS-01G6U1 - System partition
WDC WD1500HLFS-01G6U1 -
WDC WD1500HLFS-01G6U1 | RAID
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1- Antivirus Kaspersky Pure/Kaspersky Small Office Security Browser Chrome+Chrominium & Internet Explorer Other Info Razer Nostromo (Because there's not enough buttons for all the shortcut on a keyboard) |
14 Mar 2013
|
#101 | | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise Texas |
Hello Magissia,
You would need to create a new elevated shortcut for each one you want to allow the user to be able to run. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
18 Mar 2013
|
#102 | | 7x64 ultimate / 7x64 pro / Some linux x64 distro |
Hello, also would like to know why we use the -500 admin account and not any admin account, what's so different but the fact the -500 one is built in ? Wouldn't it be a secuirty issue to enable the -500 admin account ?
How things will appear on logs if a normal user use a program with runas and the built in admin account (or an other account) ?
Should we consider that the -500 admin account should be used to make something similar to sudo on linux ? (su acces without really having it) Edit : I just tested this with my account (not the 500 account)
I created a shortcut with the runas and all, it asked for my password, i gave it, then i copied the shortcut to a normal user desktop, but this user had command prompt screen asking for my password, how can i "share" the credential ?
Since it was a test, i entered te password myself on the user session, the program was run as admin, but then i was able to run other programs as admin without this prompt by modifying the shortcut path, leaving the first part, and just changing the program to run. It seems to be a security issue for me.
Last edited by Magissia; 18 Mar 2013 at 11:48 AM..
| My System Specs | | Computer type PC/Desktop OS 7x64 ultimate / 7x64 pro / Some linux x64 distro CPU i7-870 Motherboard MSI P55-GD85 Memory Kingston 4x2gb 1600 9-9-9 Graphics Card MSI GTX460 Cyclone 1GDDR5x2 + Gigabyte 285GTX 1GDDR5(PhysX) Sound Card Realtek alc 889 Monitor(s) Displays Samsung syncmaster 2333sw + some old acer screen Screen Resolution 3200x1024 Keyboard Razer Lycosa Mouse Razer Imperator PSU LC Power "Arkangel" 850W Case Aerocool BX-500 Cooling Noctua NH something Hard Drives WDC WD1500HLFS-01G6U1 - System partition
WDC WD1500HLFS-01G6U1 -
WDC WD1500HLFS-01G6U1 | RAID
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1- Antivirus Kaspersky Pure/Kaspersky Small Office Security Browser Chrome+Chrominium & Internet Explorer Other Info Razer Nostromo (Because there's not enough buttons for all the shortcut on a keyboard) |
18 Mar 2013
|
#103 | | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise Texas |
Magissia,
Enabling the built-in "elevated" Administrator account (-500 admin account) and creating a password for it would be no more of security risk than any other administrator account. In fact it may be more secure now that a password as been created for it when by default it doesn't have one.
This will not work with any other user account than the built-in "elevated" Administrator account.
Yes, that could be a security breach by changing the target of the shortcut. I have updated the tutorial to address and prevent this with steps 9-16. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
18 Mar 2013
|
#104 | | 7x64 ultimate / 7x64 pro / Some linux x64 distro |
Hello, thanks for the update but i think the user may still be able to exploit it this way :
1. Right click on desktop
2. New
3. New shortcut
4. Write manually C:\Windows\System32\runas.exe /user:COMPUTER_NAME\ADMIN'S_NAME /savecred "Path:\To\The\.exe"
While it may sound a bit paranoid, as a chess player, i'm looking at all the possibilities the user will be able to acces if (s)he really wishes to start a program with admin rights for whatever reason and start to dig arround.
I agree on the part that denying modify rights on the shortcut will stop most people, but it may not be enough.
Regards | My System Specs | | Computer type PC/Desktop OS 7x64 ultimate / 7x64 pro / Some linux x64 distro CPU i7-870 Motherboard MSI P55-GD85 Memory Kingston 4x2gb 1600 9-9-9 Graphics Card MSI GTX460 Cyclone 1GDDR5x2 + Gigabyte 285GTX 1GDDR5(PhysX) Sound Card Realtek alc 889 Monitor(s) Displays Samsung syncmaster 2333sw + some old acer screen Screen Resolution 3200x1024 Keyboard Razer Lycosa Mouse Razer Imperator PSU LC Power "Arkangel" 850W Case Aerocool BX-500 Cooling Noctua NH something Hard Drives WDC WD1500HLFS-01G6U1 - System partition
WDC WD1500HLFS-01G6U1 -
WDC WD1500HLFS-01G6U1 | RAID
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1- Antivirus Kaspersky Pure/Kaspersky Small Office Security Browser Chrome+Chrominium & Internet Explorer Other Info Razer Nostromo (Because there's not enough buttons for all the shortcut on a keyboard) |
18 Mar 2013
|
#105 | | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise Texas |
Magissia,
I don't blame you. It's best to not allow standard users to run anything elevated for just that reason.
I'm not sure about a way to prevent that workaround. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
18 Mar 2013
|
#106 | | 7x64 ultimate / 7x64 pro / Some linux x64 distro |
Hello, problem is, some old (or badly written) programs need rights to write on it's own folder because it doesn't use %userprofile% to store settings, that's why i tried to find something, from the system itself if possible.
The only workaround i know is a paid software making an encrypted file that contain the runas command with the correct parameters and without /savecred, the users just need read/execute rights on the software, and the encrypted file to start the program as admin.
The file is encrypted with AES256 but i don't know more. As i don't know if it's allowed to name paid programs here, i will give it to any admin that ask for it and let the admin team decide to make a guide for this paid software, or name it in the guide for "increased" security.
"Increased" because I don't know how robust is their encryption, and have no more information than "AES256".
I don't know if they have any backdoor, if the passphrase used for encryption is unique on each machine (and if it's the case, some may be able to find it, since it must be saved somewhere to run)
I hope Microsoft will adress this issue in future release of Windows, best would be an update for our current systems too.
Even if we didn't found a "super secure" solution here, i hope it will make users reading this guide that security is important, and that they should think twice before leaving a program with elevated priviledge.
Best regards, Magissia | My System Specs | | Computer type PC/Desktop OS 7x64 ultimate / 7x64 pro / Some linux x64 distro CPU i7-870 Motherboard MSI P55-GD85 Memory Kingston 4x2gb 1600 9-9-9 Graphics Card MSI GTX460 Cyclone 1GDDR5x2 + Gigabyte 285GTX 1GDDR5(PhysX) Sound Card Realtek alc 889 Monitor(s) Displays Samsung syncmaster 2333sw + some old acer screen Screen Resolution 3200x1024 Keyboard Razer Lycosa Mouse Razer Imperator PSU LC Power "Arkangel" 850W Case Aerocool BX-500 Cooling Noctua NH something Hard Drives WDC WD1500HLFS-01G6U1 - System partition
WDC WD1500HLFS-01G6U1 -
WDC WD1500HLFS-01G6U1 | RAID
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1 |
WDC WD1500HLFS-01G6U1- Antivirus Kaspersky Pure/Kaspersky Small Office Security Browser Chrome+Chrominium & Internet Explorer Other Info Razer Nostromo (Because there's not enough buttons for all the shortcut on a keyboard) |
09 Apr 2013
|
#107 | | Windows Vista Home Premium 32bit SP2 |
Hello,
I'm just curious whether this could work on an elevated command prompt instead of a particular program on the PC. Also, can this technique work on Vista too? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Packard Bell OS Windows Vista Home Premium 32bit SP2 |
09 Apr 2013
|
#108 | | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise Texas |
Hello Abdul, and welcome to Seven Forums.
Yes, you can do this in Vista as well.
If you like, you could use this tutorial with an elevated command prompt shortcut instead of a program. However, if you let a standard user be able to use an elevated command prompt, they will be able to have full administrator rights and access to everything on the computer through that elevated command prompt.
Hope this helps, 
Shawn | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
09 Apr 2013
|
#109 | | Windows Vista Home Premium 32bit SP2 |
Thanks! Just what I was looking, I'll let you know how it works out with this tutorial.
Oh and thanks for the quick reply BTW.
Abdul, | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Packard Bell OS Windows Vista Home Premium 32bit SP2 Elevated Program Shortcut - Create for Standard User problems? All times are GMT -5. The time now is 03:46 PM. | |