How to get an ACL exception report

kenw_at_kmsi.net
Date: 03/21/05


Date: Mon, 21 Mar 2005 17:18:40 GMT

I'm looking for a program that will summarize ACL settings on a directory
structure. I'd be happy with an option to use with XCACLS * /T that showed
only settings that are not inherited from a parent.

If I'm checking the security of a filesystem, it's impractical to check the
security of every single file -- and highly redundant, as most files simply
inherit ACLs from the parent folder. Yet any tool I've found lists ACLs in
excruciating detail, burying important differences in a mass of irrelevant
inherited data.

I'm sure such a tool exists somewhere. Heck, Novell had it years ago --
but then, their security structure was more efficient (;-/2).

/kenw
Ken Wallewein
K&M Systems Integration
Phone (403)274-7848
Fax (403)275-4535
kenw@kmsi.net
www.kmsi.net



Relevant Pages

  • Re: about common group & user ID space (PR kern/14584)
    ... most security "extensions" I've seen contain relatively ... many applications exist that make strong ... permissions: uid 0 and the uid used to represent NOVAL in vop_setattr ... I should take a moment also to respond to your comments on ACLs. ...
    (FreeBSD-Security)
  • Re: how to run application(exe) in browser
    ... directories, etc., in the usual way we handle ACLs. ... Another ActiveX control that exists on my machine might NOT ... We have a whole security mechanism in the kernel which is ... COMPLETELY IGNORED by these kludges of scripting. ...
    (microsoft.public.vc.mfc)
  • Re: Security groups, ntfs access lists and active directory synchroniz
    ... You can get the SID of the security principal from AD by reading the ... if the %logonserver% is the same as the domain controller ... how can I force the windows service to use the same ... controller to resolve names to SID in order to use them with ACLs, ...
    (microsoft.public.dotnet.security)
  • RE: Cisco ACL Question
    ... It seems that you are on the right track in being interested in security. ... There are many ways to bypass ACLs, ... I have a question about the following inbound Cisco ACL entry... ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • RE: Unexpected PolicyException thrown on System config file
    ... you should not have to add the IIS account to the ACLS. ... If you have not modified any security policies pertaining to the .NET ... © 2002 Microsoft Corporation. ... | Content-Type: text/plain; ...
    (microsoft.public.dotnet.framework.aspnet.security)