[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 296
  • Last Modified:

Cant access shares locally on Server 2003.

Hi,
I have a problem which looks like it may be related to this question:
http://www.experts-exchange.com/Security/Operating_Systems_Security/Windows/Q_21212498.html#a12637036

The difference is that I can access the shares and run programs from the shares when this is done over the network but not when logged on locally to the server. I need to be able to do this as we have a database application that needs to access a specific drive letter (X:) and this is to be used by Terminal Services clients. I can run the application direct from the hard drive but as soon as I map the drive as X: and try to run it through the share I get the following: "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item". I have tried copying the location, creating the share from scratch and setting up permissions every way I can think of but no joy.

As per the other question I thought it might be a Security Policy issue but I cant see anything which might be stopping me doing this here either. I have also tried taking ownership and explicitly granting permission to myself and this does not work so I think it must be share related and NTFS permission related. Help!
0
plokij5006
Asked:
plokij5006
  • 5
  • 3
1 Solution
 
plokij5006Author Commented:
I have now found that this behaviour only seems to apply to .exe and .bat files or similar. For example, if i create a .txt file and put it in the same location and check it has same share and file/folder permissions, I can open it with no problem. exe and bat files in the same folder give me the message described above.

I am beginning to think even more that this may be to do with group policy, any ideas anyone?

Neil
0
 
plokij5006Author Commented:
If I try the same with a zip file I get the message "Your current security settings do not allow this action".
0
 
snoopfroggCommented:
Regarding the "You may not have the appropriate permissions to access the item" message, I've seen something similar when launching an executable from a network drive.  Uninstalling Internet Explorer Enhanced Security Configuration (Add/Remove Programs -> Windows Components) took care of the issue.  

I believe this will take care of the message you're seeing related to the .zip file.  If it doesn't try this:  (in IE) tools, options, security tab. select the Local Intranet zone.  Click Sites Add file://servername.  This adds all file connections to that server to the local intranet zone, including mapped drives to that server.  
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 
plokij5006Author Commented:
I think that may be it Snoopfrogg, I added \\servername to the Trusted Sites list and now the .exe runs albeit with a Security Warning. I am presuming that if I un-install IE Enhanced Security Configuration this will get rid of the Security Warning also. problem is, this server is going to have around a dozen users all accessing the application over Terminal Services - I dont know if I want to give them the ability to use IE without the Enhanced Security for obvious reasons. Any idea how to tacklle this so they don't get the Security Warning every time they run the .exe but the server still has IE locked down?
0
 
snoopfroggCommented:
Ah, valid point.

What is the specific security warning you're seeing?
0
 
plokij5006Author Commented:
Sorry for the delay in responding, the warning is: "Open File - Security Warning - The Publisher could not be verified, are you sure you want to run this software?" I assume this is because ESC is still installed on this server.
0
 
snoopfroggCommented:
Here are a couple of suggestions:  http://techarold.blogspot.com/2006/06/open-file-security-warning-publisher.html.  Notice that the article references the Local Intranet Zone.

Control Panel, Internet Options, Security tab, Local Intranet, Sites, Advanced, add \\Server\share as a website to the "zone".

There is also this option that may help with programs on a local drive:  Control Panel, System, Advanced, Performance Settings, Data Execution Prevention.  You can turn DEP on for everything "except those I select", and manually add them to the list.  Changing the DEP setting requires a reboot.
0
 
plokij5006Author Commented:
Thanks Snoopfrogg, that seems to work. I will accept both your responses as the solution.

Thanks again!
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

  • 5
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now