Re: NTFS rights not honored

From: Pål Andreassen (see_at_signature.for.email)
Date: 12/16/03


Date: Tue, 16 Dec 2003 10:17:04 -0800


"Daniel O'Connell" <onyxkirx@--NOSPAM--comcast.net> wrote in
news:uR#md$#wDHA.1744@TK2MSFTNGP12.phx.gbl:
> However, you could probably modify your aspx page to filter based on
> permissions, you will simply need to get ahold of the user token and
> do file security checks. I am surei ts possible but I don't know how.
> I will do some research shortly and see what I can come up with.
>
> If all users can open all files, then there is a deeper security
> problem at hand, in which case I would recommend posting to the
> security newsgroups for help.

Yes, not only are files visible, but also readable to everyone. I've
checked with System.Security that the currect user is logged in. I assume
it would return ASPNET if the request process was running in that user
context.

-- 
Paal Andreassen
cnny.naqernffra@gevznarg.ab
(ROT13 to reply)


Relevant Pages

  • Re: PATCH: cdrecord: avoiding scsi device numbering for ide devices
    ... Each device could have a filter set, which could be empty to require ... appropriate permissions can be started, ... It also allows various security setups, ... with fifos command and status. ...
    (Linux-Kernel)
  • RE: What server hardening are you doing these days?
    ... permissions on their data, and Microsoft encourages ISVs to minimize ... I've been able to discuss ACLs and other security issues in Windows with ... Control or DAC (which is what you're referring to by the "stupid ...
    (Focus-Microsoft)
  • Re: get rid of security center?
    ... I have come up with a solution that does not disable Security Center, ... By changing the Permissions of that key, ... settings from being changed again. ... the firewall alert settings in Security Center get ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Password Protect IExplore
    ... You can protect the files and folders you store on your computer to make ... To set, view, change, or remove special permissions for files and folders ... clear the Inherit from parent the permission entries that apply ... To configure security so that the subfolders and files will not ...
    (microsoft.public.internet.explorer.ieak)
  • Re: Removing the Internet Security in SP2
    ... I have come up with a solution that does not disable Security Center, ... By changing the Permissions of that key, ... settings from being changed again. ... the firewall alert settings in Security Center get ...
    (microsoft.public.windowsxp.security_admin)

Quantcast