Re: XP file security issue - deletion is possible

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/26/04


Date: Wed, 26 May 2004 02:45:48 -0700

This is because the account you are using has a grant
of Full Control on the containing folder.
Due to Posix compliance requirements Full Control confers
this "hidden delete" over container contents. To change,
use the adv view on the ACE in the NTFS permissions of
the containing folder, and in that advanced view uncheck
the grant of Delete subfolders and files

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"david" <dlacote@msn.com> wrote in message
news:121f001c4426e$be8b1c00$a001280a@phx.gbl...
> On an XP machine, on an NTFS drive, I create a file.
> I then modify the permissions on this file : I disable
> inheritance, I remove all lines and add myself and give
> Read & Execute permissions only.
>
> Why am I still able to delete the file ?
> Even when I logout / log back on again.
> I'm the owner of the file, the effective permissions
> show "read only".
>
> Thanx
>
> David


Relevant Pages

  • Re: can I use GPO for remote folder management?
    ... > that group to have the permissions you want him able ... > to grant to others. ... Folder and subfolders. ... >> we have one stand alone 2003 server. ...
    (microsoft.public.win2000.group_policy)
  • Re: NTFS woes
    ... starting with a grant of Full and subtracting part of it ... gives it and it gets taken away by deny) but this Posix compliance ... On the parent folder I already had unchecked Take Ownership, ... Permissions and Delete. ...
    (microsoft.public.windows.server.security)
  • Re: File/directory permissions
    ... >> projects will have the right permissions by default. ... the requirement that the users not be able to create new subfolders or files ... directly under a project's folder. ... grant List folder contents, and Read to the group of the project. ...
    (microsoft.public.win2000.security)
  • Re: Nested Permissions and Traversing...Best Practice
    ... that is correct....you don't HAVE to grant traverse permissions. ... >> want to allow a people outside the appdev group access to the folder. ...
    (microsoft.public.windows.server.general)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)