Changing\adding permissions to admin folder
Hi people,im in doubt with something that may lead to a security hole!as advised in other thread i have removed the standard user permissions over the admin folder in c:\users\adminfoldername ....but i noticed and tought that i also could set restriction permissions for some users i would never deal with...then i decided to DENY all permissions for several users such as : remote interactive,remote desktop,guest,guests,IUSERS,IISUSERS,anonymous etc etc......but could that lead to a security threat? is it better to leave it the way it was so i would be more secure or this way looks more secure?thanks in advance,RR
November 13th, 2009 8:42pm
Guess the answer is yes it makes more vulnerable cuz as soon as i first accessed the folder with the admin password all those users were added to security tab and then i could change them to allow as soon as i input the admin password which is totally not desired!!!so even when removing the standard user from permissions as soon as i access the folder with admin rights it would create the allow rules all over again just like the designed behavior...what i did to make it restricted then is to set all deny rules to my standard user then when i try to access it says access denied even inputing the admin password which is the exact behavior i desire then the only way to allow is taking ownership over the folder...so if anyone is intrested in changing permissions the advice is given ^^Kind regards,RRPs: im expecting more people making coments in this thread!!
Free Windows Admin Tool Kit Click here and download it now
November 13th, 2009 8:58pm