Solved

Cant access shares locally on Server 2003.

Posted on 2008-10-06
8
282 Views
Last Modified: 2013-12-04
Hi,
I have a problem which looks like it may be related to this question:
http://www.experts-exchange.com/Security/Operating_Systems_Security/Windows/Q_21212498.html#a12637036

The difference is that I can access the shares and run programs from the shares when this is done over the network but not when logged on locally to the server. I need to be able to do this as we have a database application that needs to access a specific drive letter (X:) and this is to be used by Terminal Services clients. I can run the application direct from the hard drive but as soon as I map the drive as X: and try to run it through the share I get the following: "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item". I have tried copying the location, creating the share from scratch and setting up permissions every way I can think of but no joy.

As per the other question I thought it might be a Security Policy issue but I cant see anything which might be stopping me doing this here either. I have also tried taking ownership and explicitly granting permission to myself and this does not work so I think it must be share related and NTFS permission related. Help!
0
Comment
Question by:plokij5006
  • 5
  • 3
8 Comments
 

Author Comment

by:plokij5006
ID: 22657561
I have now found that this behaviour only seems to apply to .exe and .bat files or similar. For example, if i create a .txt file and put it in the same location and check it has same share and file/folder permissions, I can open it with no problem. exe and bat files in the same folder give me the message described above.

I am beginning to think even more that this may be to do with group policy, any ideas anyone?

Neil
0
 

Author Comment

by:plokij5006
ID: 22657575
If I try the same with a zip file I get the message "Your current security settings do not allow this action".
0
 
LVL 11

Accepted Solution

by:
snoopfrogg earned 500 total points
ID: 22660424
Regarding the "You may not have the appropriate permissions to access the item" message, I've seen something similar when launching an executable from a network drive.  Uninstalling Internet Explorer Enhanced Security Configuration (Add/Remove Programs -> Windows Components) took care of the issue.  

I believe this will take care of the message you're seeing related to the .zip file.  If it doesn't try this:  (in IE) tools, options, security tab. select the Local Intranet zone.  Click Sites Add file://servername.  This adds all file connections to that server to the local intranet zone, including mapped drives to that server.  
0
 

Author Comment

by:plokij5006
ID: 22661175
I think that may be it Snoopfrogg, I added \\servername to the Trusted Sites list and now the .exe runs albeit with a Security Warning. I am presuming that if I un-install IE Enhanced Security Configuration this will get rid of the Security Warning also. problem is, this server is going to have around a dozen users all accessing the application over Terminal Services - I dont know if I want to give them the ability to use IE without the Enhanced Security for obvious reasons. Any idea how to tacklle this so they don't get the Security Warning every time they run the .exe but the server still has IE locked down?
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 
LVL 11

Expert Comment

by:snoopfrogg
ID: 22661621
Ah, valid point.

What is the specific security warning you're seeing?
0
 

Author Comment

by:plokij5006
ID: 22676710
Sorry for the delay in responding, the warning is: "Open File - Security Warning - The Publisher could not be verified, are you sure you want to run this software?" I assume this is because ESC is still installed on this server.
0
 
LVL 11

Expert Comment

by:snoopfrogg
ID: 22702316
Here are a couple of suggestions:  http://techarold.blogspot.com/2006/06/open-file-security-warning-publisher.html.  Notice that the article references the Local Intranet Zone.

Control Panel, Internet Options, Security tab, Local Intranet, Sites, Advanced, add \\Server\share as a website to the "zone".

There is also this option that may help with programs on a local drive:  Control Panel, System, Advanced, Performance Settings, Data Execution Prevention.  You can turn DEP on for everything "except those I select", and manually add them to the list.  Changing the DEP setting requires a reboot.
0
 

Author Comment

by:plokij5006
ID: 22709541
Thanks Snoopfrogg, that seems to work. I will accept both your responses as the solution.

Thanks again!
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now