Solved UAC and System Protection

dw85745

New member
Member
VIP
Local time
12:08 PM
Messages
199
Is UAC only valid for system login or does it work for other things?

For example if a user logs in as a "standard user" (no admin rights) and then uses
IE, Firefox or Thunderbird for example, what happens in the following cases (windows 7 Pro):

1) User wants to download a webpage and save to the system
2) User wants to view his/her email and then save an attachment to the system
3) User clicks on an embedded link within the email and the email contains malware
4) User clicks on a web page link and is taken to a malware page
5) User wants to run a program that requires streaming data for a server and that
data must be saved to a database on the system

Thanks
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
build -
OS
Win 7 Pro x32
CPU
Intel I5-4690K
Motherboard
ASUS H-97Plus
Memory
8 GB
Graphics Card(s)
On Board
Sound Card
On Board
Other Info
ASUS MOBO Issues never resolved even by ASUS:
1) MOBO will NOT boot from other than the Default HDD drive.
2) MOBO will NOT boot Most DOS based CDs
The user can do all they need to do all it stops is system things which may effect the o/s like format drive change critical services files etc
 

My Computer

Computer type
PC/Desktop
OS
win 8 32 bit
UAC is simply a dual token system that simplifies the correct way of working that has been in use for many years in major computer systems.

Before UAC an administrator would perform their normal day to day tasks as a standard user, (with possibly a slightly raised set of access permissions). When the administrator wished to perform an administrative task they would either use a password protected RunAs process or in more complex cases they would log out and log back in with an administrative account, (with password) perform the tasks and then log-out and back in as a standard user again.

As you can see this was a long winded process and thus the use of UAC gives the same protection levels with a lot less effort, so is more likely to be used, and also as the elevation of rights is on a case by case basis there is no need to reduce the rights level.

With your examples above as long as you assume that the local save location is one which the standard user has Read/Execute/write access to then there will be no issue with running or saving data.

The case of the malware is a little more complex, If there is no anti-malware protection running, (normally these run with system rights so protect all users and files ), then the malware will infect the files and possibly some programs that the user has rights to access but will not be able to infect any critical systems so the clean-up will just need the removal of the infected account and it's replacement
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
samuria: Thanks for responding.

Based on your response the UAC affects what the user can do to the system and does NOT have anything to do to
keep malware off the system. I was under the impression -- rightly/ wrongly - that when a "standard" user account was created that those "gifted" rights belonged to the user. Hence, if the user can Not create a file, then the malware "MIGHT" be also prohibited from creating a file, unless the malware is somehow going around the user account such as directly manipulating memory which impacts the system when something is done where that memory is now saved to file.

Barman58: we crossed posts. Thanks for responding. If appears you answered my above followup,
except for trying to understand how malware (email click for example) can gain access to the system
if User is denied "write" access -- or -- better yet:

Say user has"write" access. How can malware go outside the directory where right access exists?
For example, if the User is allowed to run Thunderbird (email)
they need write access. Since Thundebird upon install makes a number of directories, how is one (admin) to know which directories have write access when one allows a User write access to Thunderbird since Thunderbird does NOT id those directories during install?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
build -
OS
Win 7 Pro x32
CPU
Intel I5-4690K
Motherboard
ASUS H-97Plus
Memory
8 GB
Graphics Card(s)
On Board
Sound Card
On Board
Other Info
ASUS MOBO Issues never resolved even by ASUS:
1) MOBO will NOT boot from other than the Default HDD drive.
2) MOBO will NOT boot Most DOS based CDs
The standard user cannot access any system files or memory locations directly so neither can the malware that is running as that user the only damage that malware can produce when running as a standard user is to that particular user alone so running as a standard user prevents malware damage and BTW also malicious actions by a disgruntled user
 

My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Barman58:

Thanks a bunch. That clears up a few things for me.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
build -
OS
Win 7 Pro x32
CPU
Intel I5-4690K
Motherboard
ASUS H-97Plus
Memory
8 GB
Graphics Card(s)
On Board
Sound Card
On Board
Other Info
ASUS MOBO Issues never resolved even by ASUS:
1) MOBO will NOT boot from other than the Default HDD drive.
2) MOBO will NOT boot Most DOS based CDs
Back
Top