Why am I deleting these files

Why am I deleting these files

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Why am I deleting these files Mike 06-12-2008
Posted by Mike on June 12, 2008, 9:36 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,
I was told that the security regulations at my organization require me
to delete the following files. I was curious if anyone could tell me
why and possible consequences. Thanks for any help.

Delete:
ir* : c:\winnt\inf
c:\winnt\inf\system32\drivers
c:\winnt\inf\system32\drivers\dllcache

netir* : all directories
nscirda*: all directories
Posix: all directories
os2*.exe: all directories
*.ex_ : all directories

Posted by Shenan Stanley on June 12, 2008, 4:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Mike wrote:
> I was told that the security regulations at my organization require
> me to delete the following files. I was curious if anyone could
> tell me why and possible consequences. Thanks for any help.
>
> Delete:
> ir* : c:\winnt\inf
> c:\winnt\inf\system32\drivers
> c:\winnt\inf\system32\drivers\dllcache
>
> netir* : all directories
> nscirda*: all directories
> Posix: all directories
> os2*.exe: all directories
> *.ex_ : all directories

Who told you this?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by Special Access on June 12, 2008, 10:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Thu, 12 Jun 2008 15:55:17 -0500, "Shenan Stanley"

>Mike wrote:
>> I was told that the security regulations at my organization require
>> me to delete the following files. I was curious if anyone could
>> tell me why and possible consequences. Thanks for any help.
>>
>> Delete:
>> ir* : c:\winnt\inf
>> c:\winnt\inf\system32\drivers
>> c:\winnt\inf\system32\drivers\dllcache
>>
>> netir* : all directories
>> nscirda*: all directories
>> Posix: all directories
>> os2*.exe: all directories
>> *.ex_ : all directories
>
>Who told you this?
>
>--
>Shenan Stanley
> MS-MVP

Most likely an over-anxious security person. Even DISA (used to
secure Gov't computer systems) doesn't require you to delete all of
those files. POSIX and OS2, yes... but not the rest, especially the
dllcache directory!

Most security folks are of the mindset to eliminate any possibility of
compromise. For example, I can take an ex_ file and expand it to
allow me to use the exe that is being blocked by security settings
elsewhere. This may be stopped by setting the security the same, but
most security folks don't think that's enough of a prevention method.
Protection in multiple layers, in case one layer is compromised there
is another.

Mike

Posted by Kevin Hatfield on July 7, 2008, 3:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Kind of funny though :)

He is correct - those directories are being deleted due to the high
probability of being attacked by viruses/malware. The filenames
are being deleted because they can either be manipulated or exploited. This
seems a little paranoid..

Shouldn't actually hurt anything, though.

> On Thu, 12 Jun 2008 15:55:17 -0500, "Shenan Stanley"
>
>>Mike wrote:
>>> I was told that the security regulations at my organization require
>>> me to delete the following files. I was curious if anyone could
>>> tell me why and possible consequences. Thanks for any help.
>>>
>>> Delete:
>>> ir* : c:\winnt\inf
>>> c:\winnt\inf\system32\drivers
>>> c:\winnt\inf\system32\drivers\dllcache
>>>
>>> netir* : all directories
>>> nscirda*: all directories
>>> Posix: all directories
>>> os2*.exe: all directories
>>> *.ex_ : all directories
>>
>>Who told you this?
>>
>>--
>>Shenan Stanley
>> MS-MVP
>
> Most likely an over-anxious security person. Even DISA (used to
> secure Gov't computer systems) doesn't require you to delete all of
> those files. POSIX and OS2, yes... but not the rest, especially the
> dllcache directory!
>
> Most security folks are of the mindset to eliminate any possibility of
> compromise. For example, I can take an ex_ file and expand it to
> allow me to use the exe that is being blocked by security settings
> elsewhere. This may be stopped by setting the security the same, but
> most security folks don't think that's enough of a prevention method.
> Protection in multiple layers, in case one layer is compromised there
> is another.
>
> Mike



Posted by Special Access on July 7, 2008, 8:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Mon, 7 Jul 2008 14:20:52 -0500, "Kevin Hatfield"

You're only paranoid if the whole world ISN'T out to get you <grin>

Shouldn't hurt if you secure the directories from all but system and
admin (read: remove EVERYONE group) as these are your "trusted" folks.
Also helps if you are behind (multiple) firewall(s)

Mike

>Kind of funny though :)
>
>He is correct - those directories are being deleted due to the high
>probability of being attacked by viruses/malware. The filenames
>are being deleted because they can either be manipulated or exploited. This
>seems a little paranoid..
>
>Shouldn't actually hurt anything, though.
>
>> On Thu, 12 Jun 2008 15:55:17 -0500, "Shenan Stanley"
>>
>>>Mike wrote:
>>>> I was told that the security regulations at my organization require
>>>> me to delete the following files. I was curious if anyone could
>>>> tell me why and possible consequences. Thanks for any help.
>>>>
>>>> Delete:
>>>> ir* : c:\winnt\inf
>>>> c:\winnt\inf\system32\drivers
>>>> c:\winnt\inf\system32\drivers\dllcache
>>>>
>>>> netir* : all directories
>>>> nscirda*: all directories
>>>> Posix: all directories
>>>> os2*.exe: all directories
>>>> *.ex_ : all directories
>>>
>>>Who told you this?
>>>
>>>--
>>>Shenan Stanley
>>> MS-MVP
>>
>> Most likely an over-anxious security person. Even DISA (used to
>> secure Gov't computer systems) doesn't require you to delete all of
>> those files. POSIX and OS2, yes... but not the rest, especially the
>> dllcache directory!
>>
>> Most security folks are of the mindset to eliminate any possibility of
>> compromise. For example, I can take an ex_ file and expand it to
>> allow me to use the exe that is being blocked by security settings
>> elsewhere. This may be stopped by setting the security the same, but
>> most security folks don't think that's enough of a prevention method.
>> Protection in multiple layers, in case one layer is compromised there
>> is another.
>>
>> Mike
>

Similar ThreadsPosted
Deleting TEMP files in C:\ April 1, 2006, 4:46 am
controlling deleting of files with NTFS June 27, 2007, 12:50 pm
Stop Users Deleting and Moving Files June 16, 2006, 10:21 am
How to prevent users from deleting Word/Excel files in a Share? May 14, 2008, 9:45 pm
Problems deleting Certificate January 15, 2006, 3:51 pm
deleting security updates August 12, 2006, 2:22 pm
Unknown source deleting data January 4, 2006, 4:35 am
Deleting Archived Certificates from Users' My store on Workstations July 8, 2008, 3:50 pm
EFS with OST/PST files December 11, 2006, 6:37 pm
What creates these files? September 22, 2005, 3:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy