Advertisement

09.24.2007 at 09:48AM PDT, ID: 22848759
[x]
Attachment Details

Why external users can access my domain shared folder?

Asked by richtree in Miscellaneous Security, Windows 2000 Server, Active Directory

Tags: domain, folder, shared, access

Hi,
I have Windows 2003 server (FS) running as domain controller (testDomain) and file server too. There is a shared folder called 'test'. I specify 'full control' to 'everyone' group under share permissions, full control to 'administrators' and group 'testers', nothing to the rest.
There is another computer called 'outside-win2k' which is Windows 2000 server and physically connected to my network. 'outside-win2k' is not a member of 'testDomain. There is a local user account called 'outsider' on 'outside-win2k'. 'outsider' login to the local computer of 'outside-win2k'. When he type in \\FS in Windows Explorer, he sees shared folder 'test'. Further more, he is able to create/delete a folder inside 'test' folder.
Q#1. Why 'outsider' is able to see shared folder 'test' even though this user is not a domain (testDomain) user, not a member of 'administrator' or 'testers' group either?
Q#2. Is there a way not to display the share folder 'test' if the user does not even have 'read' permission?
Q#3. Why 'outsider' is able to create folders inside 'test' folder even though he is not supposed to have any permission?
Q#4 Usually the system will prompt the user ('outsider') for domain user name and password when non-domain users try to access the resources on the domain. Is it because such permission is cached in the past? If so, how to clear such cache? Note: I do not have any mapped network drive to FS.
Q#5. What is the easiest and practical way to manage file permissions?
Thanks a lot.Start Free Trial
[+][-]09.24.2007 at 09:50AM PDT, ID: 19949676

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]09.24.2007 at 09:52AM PDT, ID: 19949690

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]09.24.2007 at 10:00AM PDT, ID: 19949751

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.24.2007 at 10:10AM PDT, ID: 19949836

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.24.2007 at 10:17AM PDT, ID: 19949899

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]09.24.2007 at 11:47AM PDT, ID: 19950628

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]09.24.2007 at 12:47PM PDT, ID: 19951189

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Miscellaneous Security, Windows 2000 Server, Active Directory
Tags: domain, folder, shared, access
Sign Up Now!
Solution Provided By: KCTS
Participating Experts: 3
Solution Grade: A
 
 
[+][-]09.25.2007 at 07:14AM PDT, ID: 19955859

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628