Security breach in Windows 2000 ?
#1
Posted 21 July 2001 - 06:10 AM
1. Install Windows 2000 Professional (the same for Windows 2000 standalone server).
2. Logon as Administrator
3. Get all the security updates and SP2, so that your code is up to date.
4. Go to C: and create a test directory, with full access for "Administrators", and "Users" only (remove Everybody else).
5. Now create a test account. Remove all groups from the
"Member Of" list, so that the new accound does not belong
to *any* groups.
6. Now log out and log in with the new account name.
Windows 2000 not only lets you log in, but you can also
modify the test directory created in step 4.
Now login as Administrator and modify the test account to make
it a member of the "Guests" group. Login with the new account name,
you can still modify the test directory.
What is going on ?!!
Do *all* accounts belong to "Users" group by default? How
do you change the account so that it does not belong
to the "Users" group? Am I missing something here?
#2
Posted 28 July 2001 - 02:20 AM
But keep the guest disabled if you ask me.
#3
Posted 28 July 2001 - 06:32 AM
#4
Posted 28 July 2001 - 04:33 PM
#5
Posted 28 July 2001 - 06:11 PM
You know what sucks though, is that I hear the jokes about the paper-MCSEs (Must Consult Someone Experienced), yet they give the competent ones a bad name. Just kinda burns me out when someone doesn't understand something, then proclaims that it's a "problem" with Windows.
test_client, do yourself a favor and pick up a Sybex book (or any of the MCSE grade books will do) on Windows 2000 Server. This will go a LONG way to teaching you the nuances of object-based permissions management (plus you'll pick up some other cool stuff on the way...).
#6
Posted 30 July 2001 - 10:40 PM
I asked for help because it got me confused. You do not have to tell me that you know better, I was hoping that somebody would know better than I did. That is why I submitted the question to this group.
The idea behind removing *all* groups the account belongs to was to strip this account of *all* access rights. Ideally that would let me create a fresh group with unique access rights.
As it turns out Microsoft gives *everybody* User access rights by default, even the guest account will have User rights by default. This happens because the newly created account belongs to INTERACTIVE default group, although this group does not show up in the list of groups the account belongs to. The INTERACTIVE group in its turn belongs to the Users group.
These default groups are very much like ghosts lurking around in the dark granting different users different access rights. And instead of being able to *simply* look up what account belongs to which specific group the administrator has to know what was in the minds of the designers of the operating system.
Reading books is very good and I do thank you for your suggestion. However it would be much better if I simply could look up who belongs to which group in the user manager. (Instead of keeping it in my memory).
Account management does not really have to be so muddled. Make these "ghost" groups grayed out to identify that you cannot remove them, but they should show up in the list. But this is a request for Microsoft rather than a topic for the forum.
It's true that denying access rights will override the granted access rights. However Windows gurus tell you that denying access rather than granting access should be the last resort, so they recommend staying away from denying access (I think this was a white paper on the Microsoft site or on one of the Microsoft CDs).
Thank you all for your feedback.
#7
Posted 30 July 2001 - 11:54 PM
#8
Posted 31 July 2001 - 01:28 AM
#9
Posted 31 July 2001 - 02:49 AM
Here is a piece from Microsoft KnowledgeBase article for your information which warns you about using the "deny" column:
>
>Access permissions are combined from any permissions that are
>assigned directly to the user and those that are assigned to any
>groups of which the user is a member.
>
>The exception to this rule is if there is an explicit Deny
>permission on the folder or file. This occurs because Deny
>permissions are enumerated first when Windows 2000 is determining
>whether or not a particular user can perform a particular task.
>
>Therefore, you should avoid using explicit Deny permissions
>(that is, avoid clicking to select a check box in the Deny column)
>unless there is no other way to achieve the permissions mix that
>you need.
>
Also I noticed that you talk about "decline" in your earlier posts. Do you mean "deny", or is there another set of "decline" permissions I am not aware of? That would be really spooky.
Thanks!
#10
Posted 31 July 2001 - 03:32 AM
As for being a guru, I have no idea. I can tell you this though, most of the more advanced people here have had more than a few years under their respective belts not only using various versions of Windows, but administering them in business situations. Earlier, I wasn't so much attacking you (I am sorry if you got that impression) as illustrating what most people really need to do before they start handling server-class operating systems. When I tried to use Linux, I went through about a dozen "how-tos" before I could get anywhere with it. After a while, I was able to move around in a somewhat pathetic manner
#11
Posted 31 July 2001 - 12:19 PM
It is the multi-os talking. I also use Unix a lot so got the commands confused sometimes
With using deny only problem i can see is having 100 users which all have to be limited etc. But this is not the case with you. I simply told you how to do it. take my advice or not is up to you.;)
About Guru's... As far as i am concerned in order to become one, you have to make random and meaningless comments about all the subjects related to windows (glass, pvc or computer one). And when the solution finally present itself claim very loudly and drawing attention to yourself that this was what you really meant on your earlier remark.
PS. Of course there are some real ones but they do not call themselves guru!
#12
Posted 31 July 2001 - 04:15 PM
#13
Posted 01 August 2001 - 10:46 AM
Come to think of it, it does.
I do not deal with middle low management but i deal with loads of people who think, they know everything about computers
The type that unplugs a Hub because it wastes electricity! Forget to plug it back in and than scream to me on the phone that the network they paid x amount is crap!
Freedom and profits of self employment and consultancy does come with a price.
#14
Posted 09 August 2001 - 09:40 AM
It's not a problem with the security, but rather a lack of understanding how NT security works. When Novell was crying about how admins can get into files even when they were locked out (by reclaiming ownership), they were acting as if it was a flaw. It isn't, it's by design. That account is still going to be a member of "authenticated users" since it is a valid account, and any version of "Guest" should never be enabled. This is something that you would learn either in class, or practice. Too many people obtain copies of major vendor server operating systems, fiddle with it for a while until they are convinced they "know" it, then pass themselves off as being "trained" to work with it so they can get a job. Then, when the company network is comprised (security breach, performance issues, whatever) it's a big shock when "the computer guy" can't fix it.
i wonder if that's the case with code red worm.
#15
Posted 09 August 2001 - 02:31 PM
Code red did not come out last week, it was around (under differnt names) for about 3 months. At least that was the first time my defult sites (which were actually trap
MS released a patch, we all installed it. and sircam etc. did not furt me a bit. Each of the machines just constantly got scanned. which is not a problem in my opinion.
It became the responsibility of the admin the moment IIS patch was released they should have looked, followed what was happening and installed it. Just blaming MS is destructive criticism and does not help anybody.
If admin's do pay real attention worldwide breaches like that will happen a lot less. Of course most of the blame goes to MS!!! Since they can not get anything right.
I am betting if they wrote a batch file to copy files it will have a security leak as well. I know it is not possible but i am sure they can manage
#16
Posted 09 August 2001 - 10:44 PM
(OK, I don't do that work any more so I haven't read gigantic $300 2K bookshelf, but the 3.x books were quite good as with parts of the 4.0 set.)

Help










