NTFS Security Question.



I believe I posted this in the WRONG post - oops.

So:

I have set NTFS perms on the Root of my system volume to EVERYONE: Deny
Write. Yet, I can still create folders and files! I've been an SE for a
longggg time and never saw this before. The perms are at the Root, so there
is nothing to inherit.

This acount that I am using is NOT a member of any supernumery group, just
a plain Jane user account. I logged in with admin rights to check the NTFS
perms and all seems to be OK as follows:

System: CHANGE (not FC),
Everyone Read & Exec, List, Read ((Deny Write),
C.O. : nada,
Administrators: Change,
Users: Read & Exec, List, Read (Deny Write)

One of the reasons for this level of security is to prevent certain web
sites from dropping VB apps in the root and other silly things.

Anyway, just curious as to why I can (as an ordinary user) do this.

If anyone know what is happending that would be good.

Thanks.



.



Relevant Pages

  • Security Question.
    ... I have set NTFS perms on the Root of my system volume to EVERYONE: Deny ... Everyone Read & Exec, List, Read, ...
    (microsoft.public.windowsxp.general)
  • Re: NTFS Security Question.
    ... I've been an SE and MCT for over 20 years) is that DENY means exactly that. ... are testing with a user account that you changed group membership on make ... I have set NTFS perms on the Root of my system volume to EVERYONE: ...
    (microsoft.public.windowsxp.security_admin)
  • AW: UsersDeny except root@myserver
    ... (using Deny first then Allow same as Allow first then Deny) ... We decided not to use Allow/Deny USers and just limt root ... HEX reserves the right to monitor all e-mail communications through its networks. ...
    (SSH)
  • Re: Does Microsoft lie about the Linux features?
    ... >> One way would be for root to take ownership. ... > If no delete privs exist, how would the backup account clean out the old ... Deny rights take precedence over Allow rights. ...
    (comp.os.linux.networking)
  • Re: Does Microsoft lie about the Linux features?
    ... >> One way would be for root to take ownership. ... > If no delete privs exist, how would the backup account clean out the old ... Deny rights take precedence over Allow rights. ...
    (comp.os.linux.misc)