PC Review


Reply
Thread Tools Rate Thread

disabling simple file sharing+sharing folder gives network full ac

 
 
Jeff
Guest
Posts: n/a
 
      25th Sep 2008

Hello, I'm trying to implement a password protected file share between two
computers on a semi-open network (think college network). Both machines are
Windows XP Pro, but are in a common Workgroup (not domain). They can see
each other and ping just fine. When I create simple shares, the correct
folders are shared out and files are accessible, but they are public. I want
to restrict access to them.

To do this, I turned off simple file sharing. Then I set up a folder for
sharing. It's properly locked down in that when you try to access it via
\\machine\share, it prompts for authentication and responds correctly.
However, all these permissions can be bypassed by going to \\machine\c$ from
any other machine without any credential prompts. As far as I can tell, this
access is unrestricted, as I'm able to access all the server machine's My
Documents folders and files from another machine add/delete files, all with
NO credential prompts (the two machines share user account names, but the
passwords are different. I've rebooted several times to clear any possible
credential caches, but I'm never prompted for creds and full access is still
permitted).

On the root drive (c, I've checked my NTLM permissions - AFAIK "Everyone"
has been removed, users have read-only permissions, Administrators and SYSTEM
have full permissions. I can't change the sharing permissions because when I
do, I get a warning prompt that the folder is shared for administrative
purposes and that even if I disable the share, it will reactivate on reboot.
I've read elsewhere that disabling this is bad anyways.

Does the act of disabling simple file sharing and then sharing out a single
folder really cause your entire machine to be accessible via administrative
shares and bypassing NTLM permissions? Or am I completly misunderstanding
the NTLM security model?
 
Reply With Quote
 
 
 
 
flydio
Guest
Posts: n/a
 
      25th Sep 2008
FYI: Handle change.
FWIW, all local account (except guest) are P/W protected, Network Access:
Sharing and security model for local accounts in mscpol is set to Classic.


"Jeff" wrote:

> Hello, I'm trying to implement a password protected file share between two
> computers on a semi-open network (think college network). Both machines are
> Windows XP Pro, but are in a common Workgroup (not domain). They can see
> each other and ping just fine. When I create simple shares, the correct
> folders are shared out and files are accessible, but they are public. I want
> to restrict access to them.
>
> To do this, I turned off simple file sharing. Then I set up a folder for
> sharing. It's properly locked down in that when you try to access it via
> \\machine\share, it prompts for authentication and responds correctly.
> However, all these permissions can be bypassed by going to \\machine\c$ from
> any other machine without any credential prompts. As far as I can tell, this
> access is unrestricted, as I'm able to access all the server machine's My
> Documents folders and files from another machine add/delete files, all with
> NO credential prompts (the two machines share user account names, but the
> passwords are different. I've rebooted several times to clear any possible
> credential caches, but I'm never prompted for creds and full access is still
> permitted).
>
> On the root drive (c, I've checked my NTLM permissions - AFAIK "Everyone"
> has been removed, users have read-only permissions, Administrators and SYSTEM
> have full permissions. I can't change the sharing permissions because when I
> do, I get a warning prompt that the folder is shared for administrative
> purposes and that even if I disable the share, it will reactivate on reboot.
> I've read elsewhere that disabling this is bad anyways.
>
> Does the act of disabling simple file sharing and then sharing out a single
> folder really cause your entire machine to be accessible via administrative
> shares and bypassing NTLM permissions? Or am I completly misunderstanding
> the NTLM security model?

 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Disabling simple file sharing =?Utf-8?B?RGFuIERlQ291cnNleQ==?= Windows XP General 0 23rd Jun 2006 12:44 PM
Disabling Simple File Sharing WarEagle Windows XP Help 2 4th Dec 2004 03:15 AM
sharing a folder using simple file sharing frank bruno Windows XP Networking 3 5th Jun 2004 06:37 AM
Disabling Simple File Sharing Tony Windows XP Customization 5 2nd Jun 2004 09:47 PM
Disabling simple file sharing Wes Windows XP Networking 0 24th Oct 2003 02:23 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:36 PM.