Re: Restricting rights on a file to system account

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Thanks you.
I understand that it is impossible to forbid access to a file to the
computer administrator.
J.


On 16 nov, 18:20, "Jimmy Brush" <j...@xxxxxxxx> wrote:
Hello,

Ownership implies the ability to both read and write the security
permissions on a file, regardless of what permissions are actually present.

In addition to that, administrators have the ability to take ownership of
any securable object, and then, by resetting the security permissions,
gaining full control.

- JB

"Johni" <john.silverd...@xxxxxxxxx> wrote in message

news:62bb3282-404c-4238-8bfc-0f0c8e73319d@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx



Hi,
I try without success to set these ACLs on a file :
- SYSTEM has full access (my windows service is able to modify and
delete this file)
- EVERYONE has just read access, and so cannot delete it.

The problem is that it doesn't work as I want : the local
administrator is able to delete the file, and to change ACLs on the
file (and so can have all access on the file).
I don't understand why.
Even if I remove the EVERYONE entry, it doesn't change.

If I ask for effective permissions of the administrator local, I see
that he has read rights and modify acl rights.
Why ?
Does it deal with the owner attribute ?
Thanks.

J.- Masquer le texte des messages précédents -

- Afficher le texte des messages précédents -

.



Relevant Pages

  • Run As Security `
    ... will not even have the ability to choose that option - ... under security, change the settings. ... administrator, or use mmc to change the security level for ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Restricting rights on a file to system account
    ... Ownership implies the ability to both read and write the security permissions on a file, regardless of what permissions are actually present. ... In addition to that, administrators have the ability to take ownership of any securable object, and then, by resetting the security permissions, gaining full control. ... If I ask for effective permissions of the administrator local, ...
    (microsoft.public.windows.file_system)
  • [NT] User Downgraded from Administrator to User Retains the Ability to List Other Users Running Task
    ... Beyond Security would like to welcome Tiscali World Online ... Windows XP presents a new option called "Fast User Switching" (FUS). ... Eitan has found that if a user is downgraded from an administrator role to ... as shown in task manager)) via tempting the local ...
    (Securiteam)
  • Re: Is complete home security possible?
    ... > If you are a gamer, some computer games will only run in administrator ... I have a clean disk image made from Norton Ghost, ... security issues to deal with to do it monthly, ... I have been using computers since 76, never had a virus on any of my ...
    (comp.security.firewalls)
  • Re: FOR A SKILLED IT EXPERT - WIN2K SERVER - DOMAIN CONTROLLER
    ... After installing a parallel copy of WIN2K SERVER, ... Administrator access in Directory Services Restore Safe Mode. ... This reset the local policy back to ... manual security reset. ...
    (microsoft.public.win2000.security)