Solved

Policies to disable browsing 'my computer' don't prevent users from doing the same thing in Word and Excel

Posted on 2006-07-14
5
148 Views
Last Modified: 2013-12-04
Hi,

On a W2K3 Terminal Server with many policies I found a very stupid securty leak. With the policies I've disallowed users to browse 'my computer'. They cannot go to c:\ or d:\ from the explorer address bar.

But when a user starts MS Office Word (or any other office application) it's possible to click 'my computer' from the 'file/open' menu. Also it's possible to browse to c:\ and d:\ from the file location bar.

Is there a way to make office applications more secure? To disable those features?

Frank.
0
Comment
Question by:tagnet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 

Author Comment

by:tagnet
ID: 17111985
Allready found this article http://support.microsoft.com/kb/826214/en-us
but that only removes the 'my places' icons. It still keeps the option open to manually enter a path in de file/open menu.

Anyone who has a solution for that?
0
 
LVL 88

Accepted Solution

by:
rindi earned 250 total points
ID: 17113631
Use ntfs file permissions and change the security there.
0
 
LVL 37

Expert Comment

by:bbao
ID: 17113737
another kit:

Microsoft Shared Computer Toolkit for Windows XP
http://www.microsoft.com/windowsxp/sharedaccess/default.mspx

"This toolkit helps make it easy for anyone to set up, safeguard, and manage shared computers running Windows XP, such as those in schools, libraries, Internet cafes, and other public places."
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Come and listen to Percona CEO Peter Zaitsev discuss what’s new in Percona open source software, including Percona Server for MySQL (https://www.percona.com/software/mysql-database/percona-server) and MongoDB (https://www.percona.com/software/mongo-…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question