Block A Program Using Hash

Posted on October 20, 2009 at 8:43 pm

Here is a lit­tle tuto­r­ial on how to block a pro­gram with Group Pol­icy, and the program’s hash.

block_hash_gpo

Start by either edit­ing an exist­ing GPO on AD, or cre­ate a new GPO. You can also do this stand alone using gpedit.msc on any Win­dows XP machine.

Drill down to Soft­ware Restric­tion Poli­cies. It depends on where you cre­ate the GPO as to which con­fig­u­ra­tion you put this under. If the GPO resides in a User OU, then it needs to go under “User Con­fig­u­ra­tion”. Like­wise, if it is in a com­puter OU, then you need to go the the “Com­puter Configuration”.

block_hash_gpo_2

After you deter­mine which con­fig­u­ra­tion is best for you, right click “Soft­ware Restric­tion Poli­cies” and click “Cre­ate New Polices”. For you stand-alone non AD guys, if you want to block a cer­tain user from access­ing a pro­gram, you can log in as them and put these set­tings under the “User Configuration”.

block_hash_gpo_3

You should now have some new fold­ers under “Soft­ware Restric­tion Poli­cies” called “Secu­rity Lev­els” and “Addi­tional Rules”. Under “Secu­rity Lev­els” are the default restric­tions. If you want total con­trol over what pro­grams are ran, then you can make the “Dis­al­lowed” the default level — but that’s another post.

For now we will focus on “Addi­tional Rules”. Right click in the “Addi­tional Rules” folder and click “New Hash Rule”.

block_hash_rule

This will bring up the “New Hash Rule” box, where you just need to browse for the pro­gram in ques­tion. I chose Inter­net Explorer — since I hardly ever use it any way. It should auto­mat­i­cally fill in the Hash value for the soft­ware, and also the file infor­ma­tion. Then you can choose the secu­rity level, which in this case would be “Dis­al­lowed”. You may also put in a descrip­tion if you wish.

block_hash_error

After you click “OK”, here is the result when try­ing to run Inter­net Explorer, or any pro­gram of your choosing.


Filed Under

Group Policy, Tutorials

Tagged


ICDSoft Promo

Use promo code: shawnville to get a one-time 40% dis­count for a ICD­Soft host­ing account.