Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Bug in 2008 security?

Reply
Thread Tools Display Modes

Bug in 2008 security?

 
 
JackH
Guest
Posts: n/a

 
      11-01-2009

I have several shares with permissions of Domain admins full control and
System special.

When staff try to access these folders they receive and access denied.
Which is great. However, I've found that these staff can right
click->properties->security tab and add them selves with full control. How
is this possible?


 
Reply With Quote
 
 
 
 
neo
Guest
Posts: n/a

 
      11-02-2009
First question I would ask is why is your site going with "SYSTEM" on the
share permissions tab?

"JackH" <> wrote in message
news:...
>I have several shares with permissions of Domain admins full control and
>System special.
>
> When staff try to access these folders they receive and access denied.
> Which is great. However, I've found that these staff can right
> click->properties->security tab and add them selves with full control.
> How is this possible?
>


 
Reply With Quote
 
JackH
Guest
Posts: n/a

 
      11-02-2009
I believe because it is a DFS share? Is this not needed?


"neo" <> wrote in message
news:...
> First question I would ask is why is your site going with "SYSTEM" on the
> share permissions tab?
>
> "JackH" <> wrote in message
> news:...
>>I have several shares with permissions of Domain admins full control and
>>System special.
>>
>> When staff try to access these folders they receive and access denied.
>> Which is great. However, I've found that these staff can right
>> click->properties->security tab and add them selves with full control.
>> How is this possible?
>>

>



 
Reply With Quote
 
neo
Guest
Posts: n/a

 
      11-02-2009
Not knowing exactly what you need from this share, my gut says....

On share permissions tab, no. On NTFS permissions tab, yes.

"JackH" <> wrote in message
news:...
>I believe because it is a DFS share? Is this not needed?
>
>
> "neo" <> wrote in message
> news:...
>> First question I would ask is why is your site going with "SYSTEM" on the
>> share permissions tab?
>>
>> "JackH" <> wrote in message
>> news:...
>>>I have several shares with permissions of Domain admins full control and
>>>System special.
>>>
>>> When staff try to access these folders they receive and access denied.
>>> Which is great. However, I've found that these staff can right
>>> click->properties->security tab and add them selves with full control.
>>> How is this possible?
>>>

>>

>
>


 
Reply With Quote
 
JackH
Guest
Posts: n/a

 
      11-02-2009
That's what I was referring to was the NTFS permissions.


"neo" <> wrote in message
news:%235ltt$...
> Not knowing exactly what you need from this share, my gut says....
>
> On share permissions tab, no. On NTFS permissions tab, yes.
>
> "JackH" <> wrote in message
> news:...
>>I believe because it is a DFS share? Is this not needed?
>>
>>
>> "neo" <> wrote in message
>> news:...
>>> First question I would ask is why is your site going with "SYSTEM" on
>>> the share permissions tab?
>>>
>>> "JackH" <> wrote in message
>>> news:...
>>>>I have several shares with permissions of Domain admins full control and
>>>>System special.
>>>>
>>>> When staff try to access these folders they receive and access denied.
>>>> Which is great. However, I've found that these staff can right
>>>> click->properties->security tab and add them selves with full control.
>>>> How is this possible?
>>>>
>>>

>>
>>

>



 
Reply With Quote
 
Al Dunbar
Guest
Posts: n/a

 
      11-03-2009

So, to summarize, permissions on the folder in question are:

administrators: FULL
system: special

With no permissions given to EVERYONE, Authenticated Users, or any other
trustee.

If that is the case, then your users would need to be administrators, which,
if they were, they would not need to grant themselves any further
permissions.

What, exactly, are the permissions on the NTFS folder that contains the
folders being shared?

/Al


"JackH" <> wrote in message
news:...
> That's what I was referring to was the NTFS permissions.
>
>
> "neo" <> wrote in message
> news:%235ltt$...
>> Not knowing exactly what you need from this share, my gut says....
>>
>> On share permissions tab, no. On NTFS permissions tab, yes.
>>
>> "JackH" <> wrote in message
>> news:...
>>>I believe because it is a DFS share? Is this not needed?
>>>
>>>
>>> "neo" <> wrote in message
>>> news:...
>>>> First question I would ask is why is your site going with "SYSTEM" on
>>>> the share permissions tab?
>>>>
>>>> "JackH" <> wrote in message
>>>> news:...
>>>>>I have several shares with permissions of Domain admins full control
>>>>>and System special.
>>>>>
>>>>> When staff try to access these folders they receive and access denied.
>>>>> Which is great. However, I've found that these staff can right
>>>>> click->properties->security tab and add them selves with full control.
>>>>> How is this possible?
>>>>>
>>>>
>>>
>>>

>>

>
>




 
Reply With Quote
 
neo
Guest
Posts: n/a

 
      11-03-2009
Please post/review the share and ntfs permission on both dfs path and the
location it points to. One of them has something you don't expect.

"JackH" <> wrote in message
news:...
> That's what I was referring to was the NTFS permissions.
>
>
> "neo" <> wrote in message
> news:%235ltt$...
>> Not knowing exactly what you need from this share, my gut says....
>>
>> On share permissions tab, no. On NTFS permissions tab, yes.
>>
>> "JackH" <> wrote in message
>> news:...
>>>I believe because it is a DFS share? Is this not needed?
>>>
>>>
>>> "neo" <> wrote in message
>>> news:...
>>>> First question I would ask is why is your site going with "SYSTEM" on
>>>> the share permissions tab?
>>>>
>>>> "JackH" <> wrote in message
>>>> news:...
>>>>>I have several shares with permissions of Domain admins full control
>>>>>and System special.
>>>>>
>>>>> When staff try to access these folders they receive and access denied.
>>>>> Which is great. However, I've found that these staff can right
>>>>> click->properties->security tab and add them selves with full control.
>>>>> How is this possible?
>>>>>
>>>>
>>>
>>>

>>

>
>


 
Reply With Quote
 
JackH
Guest
Posts: n/a

 
      11-03-2009
Here they are:

Anyone in the Termed Staff security group should have read only permissions
to the following location. Folders within this, permissions are granted on
a per user basis. Folders within this location have the same security
listed below except the termed Staff security group is removed.
d:\dfsroots\Termed Staff
Administrators full control
Creator Owner special
Domain Admins full
System full
Termed Staff Read & Execute, list, read

Permissions are the same as above via the dfs.

I think I see what the issue may be. I've found that is
domain\administrators have access then all domain users have full control.
I have no idea why this is as domain users are not in the administrators
group.




"neo" <> wrote in message
news:%...
> Please post/review the share and ntfs permission on both dfs path and the
> location it points to. One of them has something you don't expect.
>
> "JackH" <> wrote in message
> news:...
>> That's what I was referring to was the NTFS permissions.
>>
>>
>> "neo" <> wrote in message
>> news:%235ltt$...
>>> Not knowing exactly what you need from this share, my gut says....
>>>
>>> On share permissions tab, no. On NTFS permissions tab, yes.
>>>
>>> "JackH" <> wrote in message
>>> news:...
>>>>I believe because it is a DFS share? Is this not needed?
>>>>
>>>>
>>>> "neo" <> wrote in message
>>>> news:...
>>>>> First question I would ask is why is your site going with "SYSTEM" on
>>>>> the share permissions tab?
>>>>>
>>>>> "JackH" <> wrote in message
>>>>> news:...
>>>>>>I have several shares with permissions of Domain admins full control
>>>>>>and System special.
>>>>>>
>>>>>> When staff try to access these folders they receive and access
>>>>>> denied. Which is great. However, I've found that these staff can
>>>>>> right click->properties->security tab and add them selves with full
>>>>>> control. How is this possible?
>>>>>>
>>>>>
>>>>
>>>>
>>>

>>
>>

>



 
Reply With Quote
 
JackH
Guest
Posts: n/a

 
      11-03-2009
In addition to my last response, where should I be updating permissions?


domain.local\share or
server\share

I would think either way would replicate itself.




"neo" <> wrote in message
news:%...
> Please post/review the share and ntfs permission on both dfs path and the
> location it points to. One of them has something you don't expect.
>
> "JackH" <> wrote in message
> news:...
>> That's what I was referring to was the NTFS permissions.
>>
>>
>> "neo" <> wrote in message
>> news:%235ltt$...
>>> Not knowing exactly what you need from this share, my gut says....
>>>
>>> On share permissions tab, no. On NTFS permissions tab, yes.
>>>
>>> "JackH" <> wrote in message
>>> news:...
>>>>I believe because it is a DFS share? Is this not needed?
>>>>
>>>>
>>>> "neo" <> wrote in message
>>>> news:...
>>>>> First question I would ask is why is your site going with "SYSTEM" on
>>>>> the share permissions tab?
>>>>>
>>>>> "JackH" <> wrote in message
>>>>> news:...
>>>>>>I have several shares with permissions of Domain admins full control
>>>>>>and System special.
>>>>>>
>>>>>> When staff try to access these folders they receive and access
>>>>>> denied. Which is great. However, I've found that these staff can
>>>>>> right click->properties->security tab and add them selves with full
>>>>>> control. How is this possible?
>>>>>>
>>>>>
>>>>
>>>>
>>>

>>
>>

>



 
Reply With Quote
 
JackH
Guest
Posts: n/a

 
      11-03-2009
I just blew one of my theories.

I have another dfs called Outlook Archives.
NTFS permissions on the dfs path on via local only has the following
permissions:

Domain Admins full
Domain users read and execute, list folder, and read
System full

Domain users are able to give themselves full permissions to folders within
this share.



"neo" <> wrote in message
news:%...
> Please post/review the share and ntfs permission on both dfs path and the
> location it points to. One of them has something you don't expect.
>
> "JackH" <> wrote in message
> news:...
>> That's what I was referring to was the NTFS permissions.
>>
>>
>> "neo" <> wrote in message
>> news:%235ltt$...
>>> Not knowing exactly what you need from this share, my gut says....
>>>
>>> On share permissions tab, no. On NTFS permissions tab, yes.
>>>
>>> "JackH" <> wrote in message
>>> news:...
>>>>I believe because it is a DFS share? Is this not needed?
>>>>
>>>>
>>>> "neo" <> wrote in message
>>>> news:...
>>>>> First question I would ask is why is your site going with "SYSTEM" on
>>>>> the share permissions tab?
>>>>>
>>>>> "JackH" <> wrote in message
>>>>> news:...
>>>>>>I have several shares with permissions of Domain admins full control
>>>>>>and System special.
>>>>>>
>>>>>> When staff try to access these folders they receive and access
>>>>>> denied. Which is great. However, I've found that these staff can
>>>>>> right click->properties->security tab and add them selves with full
>>>>>> control. How is this possible?
>>>>>>
>>>>>
>>>>
>>>>
>>>

>>
>>

>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Error 0x80070643 joysaliken Windows Live Messenger 27 08-27-2010 10:30 AM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 06:02 PM
SBS 2008 security status showing not available Abhi Mishra Server Security 1 10-26-2009 08:46 AM
Visual studio 2008 security Update KB972221 no go! DOSrelic Windows Update 2 10-23-2009 08:55 PM
Re: 2008 Migration to fix issue - Yes/No? Meinolf Weber [MVP-DS] Server Migration 0 10-22-2009 07:42 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59