Jump to content

Jamesy_uk

Members
  • Posts

    4
  • Joined

  • Last visited

Everything posted by Jamesy_uk

  1. Joanne, I understand on the domain users part, just thought I had been clever enough to hide all the access points to that area!, guess not eh well it last 4 months heh. The kid in question fancies himself a bit of a hacker he tries running proxy programs, tor browsers... you name it lol. Teachers just find it funny and don't even sanction him.
  2. Thanks Liam, Problem with xcopy was it was a new DC, new everything, so even if I had I don't think the security identifiers would have married up on the new system even if the student id's were created the same, I might be wrong on that. I have been chasing my tail on some snap decisions I made during that dark time in September that's for sure, in hindsight I should have just told the bosses what they expected wasn't possible on that timescale and took my lumps.
  3. Yes Davit, It was one of the many things I had to quickly bodge through as I had less than 2 weeks to build a totally new network server setup and domain 650 machines before they took our old server hardware away. Not my finest moment but I was sweating bullets and on my own at the time. My problem was the lock, stock folder structure for students data was copied from one server (2003) to another (2008r2) so the old file permissions were wiped and It just inherited to get them up and going asap. Now I need to lock this share root down without affecting users access and I am probably being too paranoid about adjusting anything because I don't fancy manually fixing 1300 users permissions one by one if I do get it wrong lol.
  4. Aloha, I committed a bit of a sin when I found myself having to build a whole new network infrastructure setup during the last summer holiday when we had an unamicable split with our support company. I copied the file structures for old student data straight off the old server onto the new one making a new hidden share folder and setup folder redirections to match the structure. This worked fine however, we are now in a live environment and an enterprising young man has found a way to access the root of the hidden share and as such can see and access all of the folders under that root. I have no idea how he has managed this so far he doesn't have any kind of admin logon as he created a couple of rudely named folders and his account was named as owner, network browsing etc isn't allowed via group policy and I can't work it out I have tried everything I can think of. So back to the problem at hand I need to modify the main share folder structure permissions while keeping all the users accessing their folders as usual but stop this kid (and anyone he tells how he managed it) from browsing the root folder and accessing their work. As a side bonus actually work out how he managed to access the root in the first place as he isn't talking. Currently the structure is \\servername\studentdata$\ (followed by %username%) Currently the folder has: System - full control Administrators - full control Domain users - full control My user - full control Foolishly I assumed as I had prevented network browsing and hard coded the folder redirection I was o.k but this obviously isn't the case as he is somehow accessing the root. I am a bit lost on how to secure this now without manually permissioning every folder to it's users as normally when the system creates the directories they are set up for creator etc whereas in this case I copy and pasted all 1300 user folders and 400gb of data over. Regards James.
×
×
  • Create New...