Re: 2003 Web Server Security flaw

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 12/29/03


Date: Mon, 29 Dec 2003 07:17:51 -0500


"Robert Moir" <bofh@mvps.org> wrote in message
news:OejKXaXzDHA.3520@tk2msftngp13.phx.gbl...

> You can also use them as a template for setting permissions to deny
> read/write to *everyone*, including admins, which would certainly
"cripple"
> them to all intents and purposes, so as it happens I believe I answered
your
> question anyway.

> Sure. Delete them from the system file protection cache folder as well -
> C:\WINDOWS\system32\dllcache is the default location for this and its a
> protected operating system folder as well so you'll want to enable viewing
> of these in explorer folder options.

Not sure how SFC / WFP works in Windows 2003, but my understanding is that
neither ACLs nor deleting files are very effective ways to protect files
against WFP in Windows 2000. Both methods break WFP and cause annoying
error messages. And AFAIK, neither method will prevent the files from
being replaced when a future security patch or service pack containing those
files is installed.



Relevant Pages

  • Re: [Full-Disclosure] Silencing Windows File Protection
    ... Silencing Windows File Protection ... > shutting down, WFP. ... This allows for the replacement ... The second is the dllcache ...
    (Full-Disclosure)
  • Re: Windows File Protection - turning off
    ... The cache used for SFP is here: ... > I'm trying to exempt a file from Windows File Protection. ... > replacing the supplied sound file gm.dls with one of my own. ... I'm told this is WFP but I've never encountered it before. ...
    (microsoft.public.windowsxp.help_and_support)
  • [Full-Disclosure] Silencing Windows File Protection
    ... the best way to bypass Windows File Protection (WFP) was ... The second is the dllcache ...
    (Full-Disclosure)
  • Re: Problem with print services for Unix
    ... Window File Protection prevents programs from replacing critical Windows ... WFP uses the file signatures and catalog files that are generated by code ... How to Disable Windows File Protection in Windows 2000 ...
    (microsoft.public.windows.server.setup)
  • Re: Windows XP Disinformation
    ... Microsoft Windows versions starting with the Microsoft Windows 3.1 operating ... WFP does the ... Event Source: Windows File Protection ... The "winhlp32.exe" file in the system32 folder seems to redirect ...
    (microsoft.public.windowsxp.general)