Re: Exchange 2007 direct file access security hole!



On Wed, 10 Oct 2007 16:37:27 +0100, "Mark Arnold [MVP]"
<mark@xxxxxxxx> wrote:

On Wed, 10 Oct 2007 08:24:06 -0700, bill
<bill@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

I have set up a new exchange 2007 server and removed all other exchange
servers. configured direct file access to one of our file servers. when a
user puts in \\<servername>, they see a list of shares ( including hidden
ones) then they can browse these shares well below the point where ntfs
permissions do not allow. while they cannot open documents in these folders,
this does not comply with what I would expect. also I saw that this can be
controlled by user, can I configure that some users have access to one server
while others have access to another?

I had a completely vanilla install just made up on 2003 and although I
can see dollar shares (bad) so long as the permissions on the share
are correct (i.e. I made sure the default everyone - read was removed
and only a different account to mine was given read access) the user
on OWA can't get in.
So on first glance it only looks half as dodgy as you make out. It's
still bad though.......

Yeah, and browsing down to a folder I don't have permission to does
let me list the contents of that folder but won't let me open any
files within it.
.



Relevant Pages

  • Re: Folder Security
    ... You have a server with shares and you ... in question from their own or other machines on the network. ... there a way to secure folder access by which machine is trying to access ... permissions apply only to network users. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Shared folders not visible from one PC on network
    ... >We have an NT Domain with NT and W2k Servers and XP clients. ... >setting the permissions is to allow the required NT groups Full Contol ... >Share level permissions to a shared folder. ... Can other servers be seen / accessed from the problem computer, ...
    (microsoft.public.windowsxp.network_web)
  • Re: How to Hide Folders and Files under Windows 2003
    ... I recommend that you create hidden shares and set both the Share and NTFS ... permissions such that only the relevant security groups have permission to ... You can also set the folder permissions so that only particular security ...
    (microsoft.public.windows.file_system)
  • Re: Testing configurations
    ... Let say you are using shares. ... Read" then Any user will have read permissions while if DC2 share only has ... > Users are created on both servers. ... >> Microsoft MVP - Windows Security ...
    (microsoft.public.windows.server.networking)
  • RE: Share Permissions
    ... Subject: Share Permissions ... Create personal folders - No problem, NTFS rights on a folder for user ... Create shares - As far as I can tell, ...
    (Focus-Microsoft)

Loading