Re: Problem with READ-ONLY access

From: Jean-Paul F. Otin (jpfo@mitre.org)
Date: 01/08/03


From: "Jean-Paul F. Otin" <jpfo@mitre.org>
Date: Wed, 08 Jan 2003 10:04:07 -0500


Carl,
By using the /E option, you added "user" permissions of Read to the ACL. Since you say that this
user still seems to be able to create new folders and modify files, that may mean there are other
ACEs in this ACL, like Domain Users:C, or Users:C, or Everyone:C. Check the overall security of the
D drive.
jp

--
Jean-Paul F. Otin               Applied Secure Systems Engineering
Internet: jpfo@mitre.org     The MITRE Corporation
Voice:    781 271 8331      202 Burlington Road, M/S S124
Fax:      781 271 3816       Bedford, MA 01730-1420
Carl Wilson wrote:
> I am trying to set up restricted permissions for a user
> that is a member of domain users group on Windows 2000
> (from the command line). D drive has read-only and a
> folder on D has RW. I set this with xcacls d:\ /T /C /E /G
> <user>:R. After this is applied, the user still seems to
> be able to create new folders and modify files. How can he
> do this if he only has read, read and execute, and list
> folder contents?



Relevant Pages

  • Re: How can I control folder permissions when creating a folder
    ... > I'll dig into the ACL stuff a bit more. ... > get into it was the idea of trying to figure out what permissions to add ... folder are the same on Win2K and WinXP? ... I hope that means your application's folders, ...
    (microsoft.public.dotnet.security)
  • Re: Folder permissions & security??
    ... Messing with permissions can create a mess - what follows comes from memory ... If you go under the security tab for the ACL it ... Now he can access the parent folder, ... cant access 3 of the 6 child folders on the drive nor can he edit the ACL ...
    (microsoft.public.windows.server.general)
  • Re: Network service default permissions
    ... In general ACL permissions are inhirited by parent ... 1-I went to a non system partition, and check the ACL ... Network service was not listed there; ... creator owner permissions in my "web application folders" to prevent that). ...
    (microsoft.public.inetserver.iis.security)
  • Re: removing user from domain users group doesnt help
    ... user permissions to any shares and instead give permissions to the global groups you want to have access or give the global group deny permissions to the shares you don't want them to access or deny access this computer from the network user right for computers you don't want them to access shares on which can easily be managed via Group Policy. ... I have few shared folders on my w2k3 file server and most of them allow read access for the domain users group. ...
    (microsoft.public.windows.server.security)
  • Re: Problem to update ACL using ADsSecurity from VBScript
    ... > myself to the ACL and I'll have a complete solution. ... >> ownership and permissions and then set them back that way after the ... >> Microsoft MVP (Windows Server System: ... >>> folders from one Server to another. ...
    (microsoft.public.windows.server.scripting)

Quantcast