Folders created by Mac clients override inherited NTFS permission s

From: Alan Finn (afinn@SAPIENT.COM)
Date: 09/30/01


Message-ID:  <199166AC4AF5D4119DF70002A52CC54ABE9743@dalmmsx01.sapient.com>
Date:         Sun, 30 Sep 2001 08:16:10 -0500
From: Alan Finn <afinn@SAPIENT.COM>
Subject:      Folders created by Mac clients override inherited NTFS permission s
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Macintosh clients automatically modify inherited NTFS permissions when
creating subdirectory within a volume. This occurs on Windows 2000 server
SP1 with a Mac client using OS 9.x and UAM version 5. This bug has been
reproduced by Microsoft as shown below and is still currently being met with
resistance to fix the code as the developers encountered several other
issues within the protocol stack when the bug was fixed in the lab:
***The name of the folder is contained to the left of the folder
description.

Data - root folder
1. shared as data
2. share permissions = Everyone (change)
3. NTFS permissions = Administrators (full), Everyone (list)

External - subdirectory
1. NTFS permissions = Administrators (full), Everyone (list)
2. Allow inheritable permissions is checked.

XYZ - subdirectory (team folder)
1. NTFS permissions = Administrators (full), Everyone (list), XYZ
Global Group (modify)
2. Allow inheritable permissions is checked.

Comps_for_site_dev - subdirectory
1. NTFS permissions = Adminstrators (full), Everyone (list), XYZ Global
Group (modify)
2. Allow inheritable permissions is checked.

Global_elements - subdirectory
1. This is the directory created by the Macintosh.
2. NTFS permissions = Administrators (full), Domain Users (read &
execute), Everyone (read & execute), XYZ Global Group (modify), SYSTEM
(modify), MacintoshUsername (full)
3. Allow inheritable permissions is checked.
4. None of the above permissions were assigned in addition to the ones
in comps_for_site_dev. All additional users, groups, and permissions were
automatically granted and/or modified when the Mac user created the folder.

-Alan Finn

============================================================================
Delivery co-sponsored by Trend Micro, Inc.
============================================================================
BEST-OF-BREED ANTIVIRUS SOLUTION FOR MICROSOFT EXCHANGE 2000
Earn 5% rebate on licenses purchased for Trend Micro ScanMail for
Microsoft Exchange 2000 between October 1 and November 16. ScanMail
ensures 100% scanning of inbound and outbound traffic and provides
remote software management. For program details or to download your
30-day FREE evaluation copy:
http://www.antivirus.com/banners/tracking.asp?si=53&BI;=245&UL;=http://www.ant
ivirus.com/smex2000_rebate



Relevant Pages

  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The fact that the tech support is based in India has nothing to do with the ... If so you may want to leave this folder alone. ... down to all children folders because i can set those permissions to ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Deny User permissions upon moving files within shared folder
    ... set permissions on the shared folder in question so the targeted users ... users who should have more elevated permissions (to modify). ... permissions group (likely Modify perms). ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The only computers i fix are my own. ... If so you may want to leave this folder alone. ... it includes all subdirectories with inherited permissions. ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Word mail merge data source
    ... "Peter Jamieson" wrote: ... Word on it) then there may be a problem if the folder containing the data ... Word builds a connection string. ... superset of other users' permissions - for example, ...
    (microsoft.public.word.vba.general)