Sharing folder on desktop shares 'c:\users' everybody full access?

G

Guest

[Bug]
sharing a folder on your desktop will share all files in 'c:\users',
including documents and files from other accounts.
strangely everybody has full access to 'c:\users', but in the security tab
of the 'c:\users' folder you will only see 'administrators', 'system' and
'users' (first 2 have full rights, last one only read access)
NOTE: this works only if you use the 'sharing wizard' (in 'control panel'
(classic view), choose 'folder options', 'view' tab, 'use sharing wizard')

[Reproduce bug]
* create a new folder (egg. 'new folder') on you desktop
* right mouse button on folder, select 'share'

_a new window 'file sharing' appears._
(only my own account was displayed, permission level: owner' (there is only
one normal user account on my pc + administrator))

* (don't change anything) press the 'share' button with the security shield
* you need to give permission to windows, so you get a warning (user account
control), press 'continue'.

_windows is busy for a while_
_ 'file sharing' window appears again_

in the 'file sharing' window you see: New folder
\\localmachine\Users\Username\Desktop\New Folder\

* press 'ok'

[Effect]
* everybody who can access the pc from network ("can see you") or local
machine has full access to all files in 'c:\users' (no need for user name of
password)
* folder icon 'c:\users' has a 'shared' icon (folder with 2 people in it)
* the folder you wanted to share, has no shared icon, appears in
'properties' not shared.
* doing a search 'shared by me' does not return any files (maybe this takes
some time before the indexer has indexed these files)

check sharing permissions: right mouse button on 'c:\users', choose
properties, choose 'sharing' tab. press 'advanced sharing' (press 'continue'
when asked in UAC).
in the new window 'advanced sharing', press 'permissions' button.
in the new window 'administrators' and 'Authenticaed users' have access


[Reverse this security issue]
look at the properties on the new folder on your desktop ('sharing' tab).
it looks as if the folder isn't shared, that's not true because you have to
go further to the root of c:

* right mouse button on 'c:\users' folder, select properties, go to the
'sharing tab', select 'advanced sharing', in the new window deselect 'share
folder', press 'ok'


Please tell me if somebody can reproduce this. my vista is build 5600 rc1,
which was a clean install.
i'm not aware of any changes i did that can cause this, i you do please tell
me.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top