Re: Exchange 2007 direct file access security hole!

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



On Wed, 10 Oct 2007 08:24:06 -0700, bill
<bill@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

I have set up a new exchange 2007 server and removed all other exchange
servers. configured direct file access to one of our file servers. when a
user puts in \\<servername>, they see a list of shares ( including hidden
ones) then they can browse these shares well below the point where ntfs
permissions do not allow. while they cannot open documents in these folders,
this does not comply with what I would expect. also I saw that this can be
controlled by user, can I configure that some users have access to one server
while others have access to another?

I had a completely vanilla install just made up on 2003 and although I
can see dollar shares (bad) so long as the permissions on the share
are correct (i.e. I made sure the default everyone - read was removed
and only a different account to mine was given read access) the user
on OWA can't get in.
So on first glance it only looks half as dodgy as you make out. It's
still bad though.......
.



Relevant Pages

  • Re: Exchange 2007 direct file access security hole!
    ... configured direct file access to one of our file servers. ... ones) then they can browse these shares well below the point where ntfs ... can see dollar shares so long as the permissions on the share ...
    (microsoft.public.exchange.admin)
  • Re: Testing configurations
    ... Let say you are using shares. ... Read" then Any user will have read permissions while if DC2 share only has ... > Users are created on both servers. ... >> Microsoft MVP - Windows Security ...
    (microsoft.public.windows.server.networking)
  • Re: Enumerate shares and permissions
    ... >access on my servers. ... Ideal Migration can export all the shared folders and permissions into ... > Shares, export into a Microsoft ... - In Hyena, right click on the Shares object for a server and select View ...
    (microsoft.public.windows.server.networking)
  • Re: Exchange 2007 direct file access security hole!
    ... What are the permission settings on the shares (not the NTFS permissions)? ... configured direct file access to one of our file servers. ...
    (microsoft.public.exchange.admin)
  • Re: Exchange 2007 direct file access security hole!
    ... configured direct file access to one of our file servers. ... ones) then they can browse these shares well below the point where ntfs ... can see dollar shares so long as the permissions on the share ... and browsing down to a folder I don't have permission to does ...
    (microsoft.public.exchange.admin)