Desktop.ini file ignored by Windows Encryption...

From: Scott Lockington (SLockington_at_VICAL.COM)
Date: 11/01/04

  • Next message: Russ Cooper: "Alert: Microsoft Security Bulletin MS04-039 - Vulnerability in ISA Server 2000 and Proxy Server 2.0 Could Allow Internet Content Spoofing (888258)"
    Date:         Mon, 1 Nov 2004 12:55:15 -0800
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Hello All,

    In working with Windows EFS (i.e. 2000 sp4 and XP sp2) Any file named
    "desktop.ini" is ignored when encrypting the containing directory with EFS.
    The contents of this file are not verified to be that of a valid desktop.ini
    file, instead it can contain anything. Any file dropped named desktop.ini
    could avoid requiring decryption at a later date. Abuses of such an exclusion
    are left as an exercise for the reader.

    Thank you

    J. Scott Lockington
    Security Administrator
    slockington@vical.com

    --
    NTBugtraq Editor's Note:
    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    --
    

  • Next message: Russ Cooper: "Alert: Microsoft Security Bulletin MS04-039 - Vulnerability in ISA Server 2000 and Proxy Server 2.0 Could Allow Internet Content Spoofing (888258)"

    Relevant Pages

    • Re: Encryption Across Network File Shares
      ... the user should be able to decrypt and work on the EFS files. ... for Delegation" and the user that is encrypting/decrypting will have to be ... certificate/private key into your domain account, by encrypting a file ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Encryption Across Network File Shares
      ... The computer with the share that you want to contain EFS files and the ... certificate/private key into your domain account, by encrypting a file while ... "Rick Blake" wrote in message ...
      (microsoft.public.windowsxp.security_admin)
    • Re: EFS Certificate Needed
      ... Backup and save on non-degrading media the EFS DRA .pfx file ... Foe sure I will follow "Windows Recommendations". ... that recovery agent will only have ... Best practices for the Encrypting File System ...
      (microsoft.public.security)
    • Re: EFS Certificate Issue
      ... It's most useful for EFS certs when users have roaming profiles. ... user's Personal cert store, ... >> Keys are stored in a user's profile. ... >> generate) another keypair when encrypting a file. ...
      (microsoft.public.win2000.security)
    • Re: What _does_ EFS stand for?
      ... EFS = Encrypting File System ... > space required to back up the entire disc so having done ...
      (microsoft.public.windowsxp.security_admin)