Re: A method to gain access to files via built in account

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



By default, no drives or folders are shared, so there is no network access
at all. When you share a drive and so make it accessible, you need to be
careful to set the access you wish to allow. Microsoft changed the default
file permissions for a new drive to be more restrictive in W2K3 than in W2K.
Anthony
www.airdesk.co.uk


<grahame.worth@xxxxxxxxxxxxxx> wrote in message
news:1170791062.999611.253440@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I have noticed that discs formatted by windows 2003 server SP1
automatically give 'special read' permissions to the built in account
'local users'. This did not appear to be the case with windows 2000
server. This account is automatically added to 'domain users' when the
server joins the domain. As a result ANY authenticated user gains read
access to ALL files by default (i.e. without the user, or any other
group which user is a member being explicitly listed. As we were not
using security on shares (as recommended my Microsoft) some users
discovered that the could map shares by adding the UNC path to a word
document and hence access files which we believed they has not access
to

Am I correct that the above scenario is correct, if so then other
system could be 'hacked' via this route



.



Relevant Pages

  • Local Session Authentication Cache
    ... Select domain users need to access hidden shares on this ... server via statically mapped drives and local accounts. ... I'm looking to enable an idle session timeout, disconnecting the user ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Incorrect mapped drives size
    ... Apply, then re-enable Quota Managment? ... > Our quotas were set at 2GB, but the mapped drives are still saying 1GB. ... >> GB for domain users and 'unlimited' for admins. ... >> Merv Porter [SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Script refuses to map a share?
    ... you can remove mapped drives with net use also. ... I was creating a login script to map network shares. ... > /persistent:yes it lets me disconnect? ... >>>I have a faithful Windows 2000 login script batch file for domain users. ...
    (microsoft.public.scripting.vbscript)
  • Re: Sharing a network drive when not logged in
    ... | drives from "SERVER A" so that they can be shared to domain users. ... | We do not want "SERVER B" to be logged in, as any user, all the time. ... | see the shared drives on "SERVER B". ...
    (microsoft.public.windows.file_system)