Hello all,
i just come around this article: http://www.sophos.com/blogs/chetw/g/2010/07/15/windows-day-vulnerability-shortcut-files-usb/
My Enviroment: Windows 2000 Pro Clients (some) Windows XP Clients (a lot) Windows 7 Clients (not much) Windows 2003 Server (a lot) Windows 2008 Server (a lot)
i would like to prevent against above situation with an GPO, which disables HKEY_CLASSES_ROOT\lnkfile\shellex\IconHandler
is this possible?
Is it possible to create a GPO to prevent using USB things except Admins or special Workstations? If yes, did someone has a GPO ready for that? Could someone post how to do that? ( i think exporting GPO's work).
lets create an easy GPO Solution for that.
|