RE: Windows 2000's Everyone permission

From: Michael R. White (michael.white@lmscae.com)
Date: 08/23/01


From: "Michael R. White" <michael.white@lmscae.com>
To: <FOCUS-MS@securityfocus.com>
Subject: RE: Windows 2000's Everyone permission
Date: Thu, 23 Aug 2001 09:05:56 -0500
Message-ID: <NEBBKFNEMKHLMEOEHJPMAEGMDNAA.michael.white@lmscae.com>

This will be my last comment on this subject.

Paul Schmehl,
Great comment by you...I post here to pass on my knowledge and
understanding; not opinions. I subscribe to gain more knowledge and better
understanding.

Jerry Roy,
Thanks for your support...always good to have someone on your side in all of
this.

Deji,
To make this more believable for you, my exerpt was from the MSPress Win2k
Pro Training Kit, Ch 15: Administering Shared Folders, Lesson 4: Combining
Shared Folder Permissions and NTFS Permissions, pg 361-362.

Final comment:
I understand reasons for feeling it necessary to remove Everyone from both
Share and NTFS permissions. However, Microsoft's recommendation comes from
the premise of attempting to simplify administration tasks while minimizing
confusion. It is true that standard users shouldn't have interactive access
to a server, but unfortunately, it is common for small companies to have
multiple people capable of accessing a server for whatever reason. I see it
all the time, and upon recommending to the company owner or office manager,
more often than not, they prefer to leave it as it is. At any rate, if you
set up permissions on your servers through share perms and it works for you,
great. If you use NTFS permissions, great. The bottom line is securing the
resources so users get the level of access required. As long as you're
meeting that goal, you're succeeding.

BTW - Please don't take this as bragging, because I certainly know I'm not a
guru in this field, and I have so much more to learn, but I've been an MCSE
for almost 3 years, and an MCSE Instructor at a local college for two years.
As I enjoy passing on knowledge, I try my best to only respond to those
things I've researched and feel comfortable answering. I leave the rest to
the experts.

God Bless you all!!!

Michael
LMSCADSI

That wouldn't seem to be practical in a file server where each user had a
personal drive. Users would expect to be able to drag a file from their
private drive to a shared location and have anybody else be able to open the
file, but under Microsoft's recommendation they would have the additional
step of editing the permissions on the file (which is maybe too much to
expect of users.)

-----Original Message-----
From: Michael R. White [mailto:michael.white@lmscae.com]
Sent: Wednesday, August 22, 2001 14:40
To: akomolafe; 'FOCUS-MS@SECURITYFOCUS.COM'
Subject: RE: Windows 2000's Everyone permission

Deji,

You can find information on my previouse comment in the Win2K & NT 4
Resource Kits and the MCSE training kits.

I'll find some exerpts and post later if I have time.

Michael
LMSCADSI

From: akomolafe [mailto:deji@prontomail.com]

"leave share perms as they stand"? Which Microsoft document says that?

Deji

----- Original Message -----
From: "Michael R. White" <michael.white@lmscae.com>
To: "'FOCUS-MS@SECURITYFOCUS.COM'" <FOCUS-MS@securityfocus.com>
Sent: Wednesday, August 22, 2001 11:09 AM
Subject: RE: Windows 2000's Everyone permission

> You have be careful where you make the permissions modifications, share
> perms (sharing tab) and/or NTFS perms (security tab). Mixing the perms
will
> create problems remotely. Microsoft's recommendation is to leave share
> perms as they stand, and modify NTFS perms as you see fit. This covers
> remote and local access without confusing your perms.
>
> Regards,
>
> Michael
> LMSCADSI
>
>
> -----Original Message-----
> From: Damon Brinkley [mailto:damon@betcoinc.com]
> Sent: Wednesday, August 22, 2001 9:58 AM
> To: 'phoebe'; 'FOCUS-MS@SECURITYFOCUS.COM'
> Subject: RE: Windows 2000's Everyone permission
>
>
> The first thing I do when I install a Windows 2000 OS is to remove the
> permissions Everyone has to everything on the system. I then go back and
> create users and groups and give them permissions as needed. I don't know
> why Microsoft has the default giving the Everyone group those permissions
> but I think they should be removed upon installing for obvious security
> reasons.
>
> -----Original Message-----
> From: phoebe [mailto:phoebe@tollon.net]
> Sent: Wednesday, August 22, 2001 7:02 AM
> To: 'FOCUS-MS@SECURITYFOCUS.COM'
> Subject: Windows 2000's Everyone permission
>
>
> Hi all,
>
> Could someone give me some advice if I remove the permission as below,
>
> - Everyone at root c:\
> - Everyone at c:\winnt\system\*.exe
> - Everyone and Users at c:\winnt\system32\*.cpl
> - Everyone and Users at c:\winnt\system32\*.msc
> - Everyone and Users at c:\winnt\system32\*.msi
>
> But, I will assign "Administrators" and "System" with Full Control to all
> those files which took "Everyone" out.
>
> Please advice.
>
> Thanks,
>
> Regards,
> Phoebe
>
> ---
> Incoming mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.273 / Virus Database: 143 - Release Date: 8/16/2001
>
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.273 / Virus Database: 143 - Release Date: 8/16/2001
>



Relevant Pages

  • RE: What server hardening are you doing these days?
    ... permissions on their data, and Microsoft encourages ISVs to minimize ... I've been able to discuss ACLs and other security issues in Windows with ... Control or DAC (which is what you're referring to by the "stupid ...
    (Focus-Microsoft)
  • Re: Unnown process... 5eplorer.exe
    ... do not remove the cause (a "super"-hidden .dll program) but only remove ... symptom files and registry settings. ... It has all permissions but 'copy' denied to everyone, ... then by using the Windows XP Recovery Console. ...
    (microsoft.public.win2000.general)
  • RE: dcom permissions and vista?
    ... user BLAH with Local Activation and Local Launch permissions. ... Windows Vista indeed do some changes in handling DCOM and you may need to ... Windows Vista introduces the notion of Mandatory Access Labels in security ... Microsoft Online Community Support ...
    (microsoft.public.vc.atl)
  • RE: SBS 2003 Outoging Fax Problem w/Error 32028 (Cannot send - fatal error)
    ... 1.Reduce the baud rate of the incoming fax modem and see how it goes. ... Click Permissions and verify that the user attempting to fax has at ... 3.If you have configured the fax client on the Windows XP computer ... On the "Additional Server Types" page, ...
    (microsoft.public.windows.server.sbs)
  • Re: Passwords on Folders
    ... domain computer [there is also a recovery agent for a domain]. ... > Windows under which those permissions were defined. ... use NTFS on your hard drives so you can then EFS ...
    (microsoft.public.win2000.security)