Click here to get back home

Bizarre File Security Issue in Win2003 server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Bizarre File Security Issue in Win2003 server Tom 01-12-2006
Posted by Asher_N on January 12, 2006, 12:11 pm
Please log in for more thread options
Yes. If you only give 'Read' NTFS rights to an object, that's all they
get regardless of the share rights. That is quite common. For example, I
have a share that contains department and company folders. Everybody has
'Modify' and 'Read' rights to the share. I then control access with NTFS
permissions. Furthermore, if you have R2, or install the Access based
enumeration tool on W2K3 SP1, the users only see objects that they have
rights to. ABE can be found here:

http://www.microsoft.com/downloads/details.aspx?FamilyId=04A563D9-78D9-
4342-A485-B030AC442084&displaylang=en


@TK2MSFTNGP12.phx.gbl:

> Hmm... I can check that out. But let me ask this: So say they have
> Change access on the share -BUT- there are files in the share that I do
> NOT want a person to have write access to (such as control files)? If I
> give them change access to the share, can I then restrict that access
> to those particular files in the share?
>
> Asher_N wrote:
>
>> Do they have 'Change' rights on the permissions of the sg=hare?
>> Windows will apply the most restrictive of the share and NTFS rights
>> so even if the user has fukk control of a folder as far as NTFS
>> (Security tab) is concerned, if he only has 'Read' right to the
>> share, he will not be able to do anything but read.
>>
>> @TK2MSFTNGP11.phx.gbl:
>>
>> > Ondrej Sevecek wrote:
>> >
>> >> did you checked the "Sharing" tab of the folder and checked the
>> >> "Permissions" buttong the the tab?
>> >>
>> >> O.
>> >>
>> >>
>> >> > We have a Windows 2003 server which is on our corporate domain. I
>> >> > created a shared folder on one of the server drives, and then
>> >> > created other folders and files within that share area. I then
>> gave >> > an individual read/write/create rights to certain files and
>> folders >> > in that share area. However, that person can read files
>> in that >> > area but cannot seem to update or write to files/folders
>> even >> > though they have been given access to those files/folders!
>> Both the >> > server and the user are on the same domain. I even went
>> so far as >> > to give this individual 'FULL CONTROL' access to the
>> appropriate >> > files/folders, but they still cannot write anything!
>> The ONLY way I >> > can give them access to write to this area is to
>> set them up as >> > local admin users on the server, with is
>> something I do NOT want to >> > do!
>> >> >
>> >> > I know I have done this before, and it is a simple thing to do
>> >> > (using File...Properties...Security tab on the file/folder via
>> >> > Explorer) but for some bizarre reason it isn't working now.
>> Anyone >> > have any ideas as to what is going on here? Thanks.
>> >> >
>> >> > Tom
>> >> >
>> >> >
>> >> >
>> >> > --
>> >
>> > Ondrej: Yes, it is shared properly, and the appropriate people have
>> > been added to the permissions for that share. Again, those who can
>> > access it can read things without any problem; it is just trying to
>> > write or change things that they cannot do (even though they have
>> > access to that folder/file).
>> >
>> > Tom
>> >
>
>
>


Posted by Tom on January 12, 2006, 11:18 am
Please log in for more thread options
One more thing I should mention on this: Not only is this a 'shared'
folder on the server, but it is -also- an IIS virtual folder. This
folder contains web pages and what I am trying to do is allow our
various webmasters to link to the share area and then modify their
particular web pages as they see fit. Again, from their point of view,
this is simply a file share area that contains files; however, from the
servers point of view it is not only that but also an IIS virtual
folder.

Could it be that some of the IIS permissions are 'overriding' the other
permissions? I would think that giving someone full control of a file
would override everything else.

--


Posted by Steven L Umbach on January 12, 2006, 12:39 pm
Please log in for more thread options
I agree with Asher_N that it sounds like an issue with share/NTFS
permissions since they can do what you want when they are a local
administrator. The link below does a pretty good job of explaining
share/NTFS permissions. When tweaking permissions try temporarily elevating
permissions for the group and then when desired access is gained tighten
permissions form there. Also keep in mind that if you change a users group
membership the user needs to logoff and logon again in order to update their
security token with the new group membership. --- Steve

http://www.mcmcse.com/microsoft/guides/ntfs_and_share_permissions.shtml

> One more thing I should mention on this: Not only is this a 'shared'
> folder on the server, but it is -also- an IIS virtual folder. This
> folder contains web pages and what I am trying to do is allow our
> various webmasters to link to the share area and then modify their
> particular web pages as they see fit. Again, from their point of view,
> this is simply a file share area that contains files; however, from the
> servers point of view it is not only that but also an IIS virtual
> folder.
>
> Could it be that some of the IIS permissions are 'overriding' the other
> permissions? I would think that giving someone full control of a file
> would override everything else.
>
> --
>



Similar ThreadsPosted
file server move from win2000 to win2003 April 24, 2008, 9:50 pm
IIS or directory security issue on 2003 E server January 12, 2007, 9:56 pm
Re: Server 2008 Domains - Security issue February 15, 2008, 2:51 am
Win2003 R2: Permission to file is different from what was granted September 25, 2007, 5:08 am
How do I monitor file access rights on Win2003? May 19, 2006, 2:20 am
File Permission Issue Help! September 9, 2005, 8:05 am
Security Config Wiz doesn't run on Win2003 SP2 June 4, 2007, 2:24 am
File Access Audit on File Server June 20, 2007, 4:59 pm
Win2003 Server - 10,000 Entries ! February 9, 2006, 11:28 pm
IPSec tunnels win2003 server January 4, 2006, 8:01 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap