Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

Re: Share and NTFS permissions

Subject: Re: Share and NTFS permissions
Date: Tue, 26 Dec 2006 15:06:19 -0800
dubaisans dubai wrote:
I have read that the best way to allocate permissions for shared
folders is -  Share the folder . Give Share-Permissions as " Everyone
Full Control" and give the specific Allow/Deny permissions in the NTFS
tab.

Is there any insecurity in giving Share-permissions as Full control
and only specifying the NTFS permissions accurately ?

If no insecurities , why is Windows giving us the facility to give
permissions in 2 places and making it confusing?

Giving the share Full permissions and controlling access to files/directories with NTFS permissions is a valid way of easing administrative burden, and presents no particular threat, though I'd personally lock down the share permissions by at least removing the Everyone entry and replacing it with a named group, such as Domain Users, or something like that.


Why is it there? AFAICT, it's because of the legacy of Win9x and earlier, which had no concept of file/directory permissions.

Kurt

<Prev in Thread] Current Thread [Next in Thread>