Jump to content

Recommended Posts

Posted

Hi,

 

I was at a teacher PC the other day and needed to get some software off my main PC (running XP SP3) so I broswed to

\\MyPcName\E$ and all was good.

 

Later, out of interest, I tried this from a non-admin pupil account and it worked and even allowed me to create/delete files !!!

 

Obviously this is a bit of a security hole but I'm not sure of best technique to plug it.

 

I read that you can disable sharing administrative shares but it will be re-anabled on reboot by windows.

 

Also read I could have a startup/login/scheduled batch file to do e.g. NET SHARE E$ /delete

 

Or is there a group policy fix ? (We are running server 2008 R2 Standard)

 

Or maybe better to change security permissions locally for E: etc ?

 

But what about all the other laptops / PCs used in office and by teachers as they will have the same issue.

Don't want to have to manually set permissions on all computers individually ?!!

 

Not sure why these admin shares exist anyway, should I blame Microsoft or the people who originally set up

our network ?

 

Thanks for any advice

Posted

E has permission entries for "Administrators", "Authenticated users", "users" and "SYSTEM"

Of course I could tweak these for my PC but how do I fix similar issues system wide in one fell swoop ?

Posted

Not sure if this is correct - yay for being an apprentice - but wouldn't a combo of permissions on the share and permissions on the actual folder limit this?

Making it so the folder has 'list folder contents' unchecked and the share has no read permission for the student group/s?

Posted

Your network is incorrectly configured. The default administrative shares do not allow normal users to browse them.

 

At a guess, I suspect someone has added a domain group to a local computer group or domain users to a domain group that allows them local administrative access.

 

So check the membership of your domain and local groups.

Posted
The "Authenticated Users" group needs removing. You need to asses what impact this would have on any other files, folder and shares stored on the E: partition before you do though!
Posted

Ok thanks for the info I'll investigate manually for my PC.

 

But what about all the other staff PCs on site, is there any way to automate the investigation and a subsequent fix (like removing authenticated users) ?

 

Also I've got a USB drive plugged in and it is being shared as I$, but I can't set any security permisiions on it.

Maybe as it's formatted as FAT32?

So anyone can browse it, Ouch !!!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...