Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | firefox won't start

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > General IT Discussion
Register FAQ Community Calendar

Best Way to Disable 'command.com'
Reply
 
Thread Tools
Old 05-08-2009, 08:31   #1
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Best Way to Disable 'command.com'

Morning All,

Need to disable access to command.com on a Windows XP Pro system.

Anybody done this? If so, what did you find to be the best way to do it?

I can just delete the executable, but that a) might cause compatibility problems down the line, and b) won't stop it running from a USB drive/CD.

Thanks
Raistlin is offline   Reply With Quote
Advertisement
Old 05-08-2009, 08:42   #2
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,398
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Best Way to Disable 'command.com'

http://www.edugeek.net/forums/how-do...mmand-com.html

post #10 has a solution but it does involve restricting 16bit apps
Kymmy is offline   Reply With Quote
Old 10-08-2009, 20:30   #3
Mauldor
Inactive
 
Mauldor's Avatar
 
Join Date: Jan 2004
Location: Scunthorpe
Age: 57
Services: 50mbit, Base TV, Base Phone
Posts: 437
Mauldor is a glorious beacon of lightMauldor is a glorious beacon of lightMauldor is a glorious beacon of lightMauldor is a glorious beacon of lightMauldor is a glorious beacon of lightMauldor is a glorious beacon of lightMauldor is a glorious beacon of light
Re: Best Way to Disable 'command.com'

I found this on the good old web:

In non-domain environment you can create software restriction policy for
cmd.exe and command.com. You can do it in Group Policy.

Open Group policy -> expand Computer Configuration -> Security Settings ->
Software Restriction Policies! Right click additional rule and my suggestion
is Hash rule. It is most reliable but it is still possible to get around it.
E.g. applying service pack might change e.g. cmd.exe. This will most likely
change the hash and users will be able to run cmd.exe command.

In domain environment you can e.g. change permission on file and give only
admins e.g. full control and remove all other users and groups...
Open Group policy -> expand Computer Configuration -> Security Settings ->
File System. Add file from c:\windows\system32\cmd.exe and select who has
any rights on it...

Hope that helps..
Mauldor is offline   Reply With Quote
Old 11-08-2009, 23:58   #4
Matth
Inactive
 
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,516
Matth has reached the bronze age
Matth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze age
Re: Best Way to Disable 'command.com'

http://www.askvg.com/all-kinds-of-re...003-and-vista/

Not sure if it's correct but:

20.) Restrict Command Prompt:
HKEY_CURRENT_USER\Software\Policies\Microsoft\Wind ows\System
Create DWORD value DisableCMD and set its value to 2

Doh! Command.com, now that is sneaky

12.) Restrict Programs to run:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre nt Version\Policies\Explorer\DisallowRun
create String value with any name, like 1 and set its value to the program's EXE file.
e.g., If you want to restrict msconfig, then create a String value 1 and set its value to msconfig.exe. If you want to restrict more programs, then simply create more String values with names 2, 3 and so on and set their values to the program's exe.

Wonder if that restriction can also be applied for command.com ?
Matth is offline   Reply With Quote
Old 12-08-2009, 00:03   #5
zing_deleted
Guest
 
Posts: n/a
Re: Best Way to Disable 'command.com'

I personally can not see how you can stop a system totally using command.com as you say you can boot to it via usb/cd drive ive got dos boot discs of both types neither of which have anything to do with windows.
It appears its easy to disable it in windows password protect bios and set to boot from hdd and then hope no one removes the battery
  Reply With Quote
Old 12-08-2009, 06:58   #6
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: Best Way to Disable 'command.com'

The final solution was in the post that Kymmy made above.

Disabling Windows' access to the 16-bit subsystem completely prevents command.com from running as it needs to be able to access those services and interpreters to run.

As for booting from an alternative media well.....if you're going to allow physical access to your system then it's pretty much game over anyway. However, if you apply full disk encryption to the system then the main threats from being able to boot to an alternate OS (password harvesting, file access, user account enumeration/amendments) disappear.
Raistlin is offline   Reply With Quote
Old 12-08-2009, 09:55   #7
zing_deleted
Guest
 
Posts: n/a
Re: Best Way to Disable 'command.com'

No wthat depends on who has access to the system. Bitlocker for example has been hacked . Anyone with the right set of skills and access to the machine can render some encryptions useless
  Reply With Quote
Old 12-08-2009, 10:08   #8
Raistlin
Inactive
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,384
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Raistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered starsRaistlin is seeing silvered stars
Re: Best Way to Disable 'command.com'

The encryption that BitLocker provides hasn't been hacked, just the the mechanism that it uses to apply it - even then it is possible to employ BitLocker in a manner that effectively protects the data on your computer, and prevents access to it from an OS booted from alternative media.

Perhaps my comment above should have read 'if you correctly apply full disk encryption'.....
Raistlin is offline   Reply With Quote
Old 12-08-2009, 10:14   #9
zing_deleted
Guest
 
Posts: n/a
Re: Best Way to Disable 'command.com'

aye
  Reply With Quote
Old 17-08-2009, 02:46   #10
Dude111
An Awesome Dude
 
Join Date: Mar 2009
Posts: 3,874
Dude111 has a bronzed appealDude111 has a bronzed appeal
Dude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appeal
I have always wondered what that COMMAND.COM program was for in my root directory...

If i delete the file what programs might not run?
Dude111 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 16:19.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.