Write Attributes and Write Extended Attributes

From: Will (westes-usc_at_noemail.nospam)
Date: 10/31/05


Date: Mon, 31 Oct 2005 01:30:29 -0800

Can someone explain to me why many Windows 2000 applications appear to
require that anyone with read and execute permission has "write attributes"
and "write extended attributes" permissions enabled? When I turn on
auditing, I see hundreds of messages in the eventviewer security log for
nearly everyone in the Users group for failing to acquire needed permissions
on cmd.exe, shell32.dll, etc. In examining the permission list that the
users need, the only permissions we have failed to enable for users are
"write attributes" and "write extended attributes". Those permissions
don't seem like something you would want to give users for every file on the
system, and I'm perplexed why Windows would need such permissions on many of
its applications.

-- 
Will


Relevant Pages

  • RE: What server hardening are you doing these days?
    ... permissions on their data, and Microsoft encourages ISVs to minimize ... I've been able to discuss ACLs and other security issues in Windows with ... Control or DAC (which is what you're referring to by the "stupid ...
    (Focus-Microsoft)
  • Re: Unnown process... 5eplorer.exe
    ... do not remove the cause (a "super"-hidden .dll program) but only remove ... symptom files and registry settings. ... It has all permissions but 'copy' denied to everyone, ... then by using the Windows XP Recovery Console. ...
    (microsoft.public.win2000.general)
  • RE: dcom permissions and vista?
    ... user BLAH with Local Activation and Local Launch permissions. ... Windows Vista indeed do some changes in handling DCOM and you may need to ... Windows Vista introduces the notion of Mandatory Access Labels in security ... Microsoft Online Community Support ...
    (microsoft.public.vc.atl)
  • Re: Passwords on Folders
    ... domain computer [there is also a recovery agent for a domain]. ... > Windows under which those permissions were defined. ... use NTFS on your hard drives so you can then EFS ...
    (microsoft.public.win2000.security)
  • RE: SBS 2003 Outoging Fax Problem w/Error 32028 (Cannot send - fatal error)
    ... 1.Reduce the baud rate of the incoming fax modem and see how it goes. ... Click Permissions and verify that the user attempting to fax has at ... 3.If you have configured the fax client on the Windows XP computer ... On the "Additional Server Types" page, ...
    (microsoft.public.windows.server.sbs)