´ë·«°ú ´º½º ´ç½ÅÀÇ Á¦ÀÏ Á¤º¸ Ãâó winvista, ¿îÀü»ç ±×¸®°í â Àü¸Á ÀÎÅͳݿ¡

ºñ½ºÅ¸ ±â»ç Á¤»ó 50 ºñ½ºÅ¸ ¿µ»ó ¿¬¾àÇÑ ºñ½ºÅ¸ ºñ½ºÅ¸ µµ¿ò

Á¤Ã¥

´ç½ÅÀº ÇöÀç ±â»ç¸¦¿¡¼­ ã¾Æº¸°í ÀÖ´Ù MS Windows ºñ½ºÅ¸ ȣȯ¼º ¼ÒÇÁÆ®¿þ¾î Á¾·ù ÀÏÄ¡ Á¤Ã¥.

ITsVISTA À¥Àº ¿¬°áÇÑ´Ù: 2007³â 9¿ù Á¦ 12

Á¶¿¡ ÀÇÇØ À§¿¡ ¾²´Â 2007³â 9¿ù Á¦ 12 ÄÚ¸àÆ® ¾øÀ½.
±â»ç¸¦ ´õ À§¿¡ ÀÐÀ¸½Ê½Ã¿À ¹ý ±×¸®°í Á¤Ã¥ ±×¸®°í ±×·ì ±×¸®°í GPO ±×¸®°í ¼ö»ö ±×¸®°í ´º½º ±×¸®°í Àç·á ±×¸®°í SP1 ±×¸®°í beta.

ºñ½ºÅ¸¿¡ ÇöÁö »ç¿ëÀÚ Á¤Ã¥À» ¼öÃâÇϽʽÿÀ

³ª´Â Àç¹ÌÀÖ´Â Áú¹®À»¿¡ ´ëÇÏ¿© ÀÏÀü¿¡ ¿ìÆíÀ¸·Î ¹Þ¾Ò´Ù Windowsecurity.com¿¡ MLGO¿¡ °üÇÏ¿© ³ªÀÇ ±â»ç. Áú¹®Àº ƯÁ¤ÇÑ »ç¿ëÀÚ¿¡°Ô ÇÒ´çµÈ ´Ù¸¥ ÄÄÇ»ÅÍ¿¡ »ç¿ëÀÚ¿¡°Ô ÇöÁö Á¤Ã¥À» ¼öÃâÇÏ´Â °ÍÀÌ °¡´ÉÇÑ °æ¿ì¿¡¡¦, À̾ú´Â°¡?

³ªÀÇ ¸Ó¸®¸¦ ±Ü°í ¿¡ ÀÇÇÏ¿© ¾Æ¹«µµ °°ÀÌ º¸ÀÎ Á¶±ÝÀ» ¿¬±¸ÇÑ ÈÄ¿¡ À̰ÍÀ» À§ÇÑ ¸í´äÀÌ ÀÖ°í GUI °ø±¸´Â ¸í¹éÇÏ°Ô À¯È¿ÇÏÁö ¾Ê´Ù - ±×·¡¼­ ³ª´Â ¶°¿Ã¶ó¾ß Çß´Ù ³ª Àڽй«¾ð°¡ °¡¡¦ À̰ÍÀº °á°úÀÌ´Ù:

µÚ¿¡ ¿À´Â ¹®¼­È­ÇÏÁö ¾Ê´Â °Í -¿Í ¾Æ¸¶ ¹ÞÃÄÁöÁö ¾Ê´Â - ¹æ¹ýÀº Àú¸¦ À§ÇØ ÀÛµ¿Çß´Ù:

"¼Ò½º ÄÄÇ»ÅÍ¿¡":
1. âÁ¶Çϰųª º¯°æÇϽʽÿÀ "±Ù¿ø »ç¿ëÀÚ"¸¦ À§ÇÑ ÇöÁö Á¤Ã¥À»
2. °¡½Ê½Ã¿À "C:\Windows\System32\GroupPolicyUsers\" ÃÖÈÄ ¼öÁ¤ Á¤Ã¥ Æú´õ¸¦ ã¾Æ³»°Åµç
- Æú´õ´ÂÀ¸·Î Áö¸íµÇ¾î¾ß ÇÑ´Ù SID (¾ÈÀü ID) "±Ù¿ø »ç¿ëÀÚÀÇ", ¿¹¸¦µé¸é. "S-1-5-21-452792215-1268730067-2626448776-1108 ¡È
3. µ¿ÀÏÇÑ ÀüÈ­¹øÈ£ºÎ ±¸Á¶·Î "¸ñÇ¥ ÄÄÇ»ÅÍ"¿¡ Æú´õ ¹× ³»¿ëÀ» º£³¢½Ê½Ã¿À

"¸ñÇ¥ ÄÄÇ»ÅÍ¿¡":
1. "Ç¥Àû »ç¿ëÀÚ"ÀÇ SID¿¡°Ô »õ·Ó°Ô º£²¸Áø Æú´õ¸¦ °³¸íÇϽʽÿÀ ("¼öÃâÇÑ" Á¤Ã¥À» ¹Þ¾Æ¾ß ÇÏ´Â »ç¿ëÀÚ)
- ÇöÁö »ç¿ëÀÚÀÇ SID¸¦ ã¾Æ³»´Â ¹æ¹ý?
2. »õ·Ó°Ô °³¸íÇÑ Æú´õ¿¡ NTFS Çã°¡¸¦¿¡ ³õÀ¸½Ê½Ã¿À:
- ü°è = "ÃæºÐÈ÷¡¦

´©¸£½Ê½Ã¿À "¼öÃâ Àд °è¼ÓµÇ À§ÇÏ¿© ºñ½ºÅ¸¿¡ ÇöÁö »ç¿ëÀÚ Á¤Ã¥"¸¦

Jakob H.¿¡ ÀÇÇØ ¾²´Â. À§¿¡ ÇÏÀ̵¨º£¸£Å© 2007³â 5¿ù Á¦ 19 no comments.
Read more articles on policy and sid and mlgpo and group policies and vista and Windows.

Blocking U3 USB devices

Hey,

I get this question a lot: how can we block U3 devices on the network?

Well, one approach that some companies take is to simply block the physical USB ports by glue etc. - no USB devices are able to get in, so we have a ¡°secure¡± system¡¦ Hmmm, this would mean that we are not able to use other USB devices either - maybe not the best solution for all of us then¡¦

If you have Windows Vista deployed the new Device Control functionality, but most companies have Windows XP and Windows Server 2003 products in production (and probably waits for Vista Service Pack 1 before they go ahead with the Vista deployment)¡¦ So, what could they do then?

Third party software, like GFI EndPointSecurity is capable of blocking USB devices etc. - and it¡¯s does a very good job too, but there¡¯s also a free way to do it (if you ask me it¡¯s the best way to do it): implement Software Restriction Policies (SRP)!

I¡¯ve been writing about the ¡°Default Deny All Applications¡± approach and this is (of couse) also capable of blocking U3 devices - out¡¦

Click to continue reading "Blocking U3 USB devices"

Written by Jakob H. Heidelberg on May 10th, 2007 with no comments.
Read more articles on endpointsecurity and srp and u2 and software restriction policies and gfi and block and policy and vista and xp and hacker and Windows Server 2003 and GPO and Windows.