Jump to content

Recommended Posts

Posted

Good Evening,

 

It's just been flagged up to me that a member of staff can view all other members of staff's Windows file Server files on our AD integrated macs - Security on the Windows shared are set correctly - why is it that this user can completely 'bypass' windows security and view these files? and how can I stop this happening?

 

I'd love to know..

Posted

If users on the Macs can access other staff members home drive files then the Windows security permissions are NOT set correctly on the share(s), full stop. The Macs are just revealing an existing security flaw.

 

Now, if they can just SEE the top level folders, but have no access to them that's a bit different.

Posted

Hi..

 

looks like all staff that logon to the macs are given 'read modify' rights in OS X on any folder on our staff shared area - which is a bit of an issue really! Looking at the window server share security in Windows on the folder it reads..

 

creator owner has special permissions

system - full permissions

domain User whose folder it is (eg BloggsJ) - full permissions

Local Administrators (server) - full permissions

Local Users (server) - Read Execute

Posted
I'm connecting using the directory utility mapping the home drive share as specified in AD - I wouldn't doubt that Windows security is the key to this, I'll give the 'effective permissions' tool a go and see what I can find..
Posted
I would remove Local Users from the permissions. Its not needed. Not 100% without checking but i think the group Domain Users is a member of Local Users so that is what could be causing it.
Posted (edited)
Hi..

 

looks like all staff that logon to the macs are given 'read modify' rights in OS X on any folder on our staff shared area - which is a bit of an issue really! Looking at the window server share security in Windows on the folder it reads..

 

creator owner has special permissions

system - full permissions

domain User whose folder it is (eg BloggsJ) - full permissions

Local Administrators (server) - full permissions

Local Users (server) - Read Execute

 

You really shouldn't have "Local Users (server)" with permissions to this share. This is the cause of the issue.

 

EDIT: @FN-GM beat me to it.

Edited by seawolf
Posted
Ok.. I've removed permissions for local users for the share - great that clears up the issue of viewing the folders, but I it has highlighted two other issues - one, users in the AD staff group now cannot access their drives at all and that the Windows Server now cannot browse Active Directory for me to add in the staff group to sharing permissions.
Posted (edited)

What version of Windows server are you using? We don't have local users permissions set on any shares and do not experience these issues, not have I seen them. We are on 2008 R2.

 

Edit: What is the directory structure of your shares? How many levels down from the root of the drive are they?

Edited by seawolf

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...