Re: NTFS inherited permissions bug on W2K
From: Ondřej Tučný (tucny@ALSOFT.CZ)Date: 10/12/01
- Previous message: Tony Thai: "Re: NTFS inherited permissions bug on W2K"
- In reply to: Sam Greenfield: "NTFS inherited permissions bug on W2K"
- Next in thread: Barry Dorrans: "Microsoft Security Bulletin : MS01-52 Terminal Services Failure - Patch kills terminal services"
- Next in thread: Fernando Trias: "Re: NTFS inherited permissions bug on W2K"
- Reply: Barry Dorrans: "Microsoft Security Bulletin : MS01-52 Terminal Services Failure - Patch kills terminal services"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <3BC6D0D1.A9F4B70F@alsoft.cz> Date: Fri, 12 Oct 2001 13:15:29 +0200 From: Ondřej Tučný <tucny@ALSOFT.CZ> Subject: Re: NTFS inherited permissions bug on W2K To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Hello,
there is another point to consider - junctions, NTFS's rather
undocumented feature enabling hardlinks between directories. Let's
have the following directory structure:
\x ... permission set 1
\x\z ... junction target, inherited permission set 1
\x\z\zz ... subdirectory with inherited permission set 1
\y ... permission set 2
\y\z ... junction linking to \x\z, inherited permission set 2
\y\z\zz ... links to \x\z\zz, permission set **1**
When \x and \y subtrees are created and \y\z is linked to \x\z, the
subdirectory \y\z\zz has the permission set one ! The logic of
inheritance assumes that it should have inherited the permission
set two.
Furthermore when a change occurs in permission set two, it is
propagated to \y\z\zz and so to its primary location in \x\z\zz.
Note that junctions are an application of (documented) reparse
points. Other applications of reparse points also need to handle
access control, so there should be a precisely defined behavior
of permission inheritance.
-- Yours sincerely Ondřej Tučný, A && L soft s.r.o.Phone: +420 2 6973320 Support: +420 2 6973335 Fax: +420 2 6973329 www: http://www.alsoft.cz
====================================== Delivery co-sponsored by Trend Micro, Inc. ====================================== BEST-OF-BREED ANTIVIRUS SOLUTION FOR MICROSOFT EXCHANGE 2000 Earn 5% rebate on licenses purchased for Trend Micro ScanMail for Microsoft Exchange 2000 between October 1 and November 16. ScanMail ensures 100% scanning of inbound and outbound traffic and provides remote software management. For program details or to download your 30-day FREE evaluation copy: http://www.antivirus.com/banners/tracking.asp?siS&BI;$5&UL;=http://www.ant ivirus.com/smex2000_rebate
- Previous message: Tony Thai: "Re: NTFS inherited permissions bug on W2K"
- In reply to: Sam Greenfield: "NTFS inherited permissions bug on W2K"
- Next in thread: Barry Dorrans: "Microsoft Security Bulletin : MS01-52 Terminal Services Failure - Patch kills terminal services"
- Next in thread: Fernando Trias: "Re: NTFS inherited permissions bug on W2K"
- Reply: Barry Dorrans: "Microsoft Security Bulletin : MS01-52 Terminal Services Failure - Patch kills terminal services"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|