Click here to get back home

bypass traverse checking

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
bypass traverse checking BarbS 08-09-2005
Posted by BarbS on August 9, 2005, 3:35 pm
Please log in for more thread options
What is the recommended user rights setting for "bypass traverse checking"?
Some say "administrators, authenticated users" or no groups at all. I removed
the everyone group. Currently I have the following groups listed:
Administrators, Authenticated Users, Backup Operators, Power Users, Users.

Thank You.


Posted by Roger Abell on August 10, 2005, 3:41 am
Please log in for more thread options
You current setting is pretty much any account expect for anonymous login.
The only rule of thumb I use is that the setting should be custom crafted
based on the use of the machine if it is not left alone (the default is much
like saying there is no such thing as traverse checking).

When I use this, and I do believe this is a great addition to the machine
hardening, I ask : what accounts should be on this machine, and, to what
areas do I want to make sure accounts can access only if they have been
threaded down to the area in the NTFS permissions/
When I use this setting I also will typically use a FileSystem security
configuration editor template to state, set, analyze, and if needed reset
the NTFS permissions.

--
Roger Abell
Microsoft MVP (Windows Security)

> What is the recommended user rights setting for "bypass traverse
checking"?
> Some say "administrators, authenticated users" or no groups at all. I
removed
> the everyone group. Currently I have the following groups listed:
> Administrators, Authenticated Users, Backup Operators, Power Users, Users.
>
> Thank You.




Posted by GeeB on August 10, 2005, 10:52 pm
Please log in for more thread options
You may want to review this KB:
http://support.microsoft.com/default.aspx?scid=kb;en-us;823659

G


> What is the recommended user rights setting for "bypass traverse
> checking"?
> Some say "administrators, authenticated users" or no groups at all. I
> removed
> the everyone group. Currently I have the following groups listed:
> Administrators, Authenticated Users, Backup Operators, Power Users, Users.
>
> Thank You.




Similar ThreadsPosted
Checking group security October 5, 2007, 10:31 am
Different IIS 5 & IIS 6 behavior on checking clients' certificates September 5, 2005, 11:55 pm
IIS 6 behavior on checking clients' certificates (again) September 16, 2005, 4:47 am
IIS 6 behavior on checking clients' certificates (again 2) September 29, 2005, 12:40 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap