Solved

Cant access shares locally on Server 2003.

Posted on 2008-10-06
8
288 Views
Last Modified: 2013-12-04
Hi,
I have a problem which looks like it may be related to this question:
http://www.experts-exchange.com/Security/Operating_Systems_Security/Windows/Q_21212498.html#a12637036

The difference is that I can access the shares and run programs from the shares when this is done over the network but not when logged on locally to the server. I need to be able to do this as we have a database application that needs to access a specific drive letter (X:) and this is to be used by Terminal Services clients. I can run the application direct from the hard drive but as soon as I map the drive as X: and try to run it through the share I get the following: "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item". I have tried copying the location, creating the share from scratch and setting up permissions every way I can think of but no joy.

As per the other question I thought it might be a Security Policy issue but I cant see anything which might be stopping me doing this here either. I have also tried taking ownership and explicitly granting permission to myself and this does not work so I think it must be share related and NTFS permission related. Help!
0
Comment
Question by:plokij5006
  • 5
  • 3
8 Comments
 

Author Comment

by:plokij5006
ID: 22657561
I have now found that this behaviour only seems to apply to .exe and .bat files or similar. For example, if i create a .txt file and put it in the same location and check it has same share and file/folder permissions, I can open it with no problem. exe and bat files in the same folder give me the message described above.

I am beginning to think even more that this may be to do with group policy, any ideas anyone?

Neil
0
 

Author Comment

by:plokij5006
ID: 22657575
If I try the same with a zip file I get the message "Your current security settings do not allow this action".
0
 
LVL 11

Accepted Solution

by:
snoopfrogg earned 500 total points
ID: 22660424
Regarding the "You may not have the appropriate permissions to access the item" message, I've seen something similar when launching an executable from a network drive.  Uninstalling Internet Explorer Enhanced Security Configuration (Add/Remove Programs -> Windows Components) took care of the issue.  

I believe this will take care of the message you're seeing related to the .zip file.  If it doesn't try this:  (in IE) tools, options, security tab. select the Local Intranet zone.  Click Sites Add file://servername.  This adds all file connections to that server to the local intranet zone, including mapped drives to that server.  
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 

Author Comment

by:plokij5006
ID: 22661175
I think that may be it Snoopfrogg, I added \\servername to the Trusted Sites list and now the .exe runs albeit with a Security Warning. I am presuming that if I un-install IE Enhanced Security Configuration this will get rid of the Security Warning also. problem is, this server is going to have around a dozen users all accessing the application over Terminal Services - I dont know if I want to give them the ability to use IE without the Enhanced Security for obvious reasons. Any idea how to tacklle this so they don't get the Security Warning every time they run the .exe but the server still has IE locked down?
0
 
LVL 11

Expert Comment

by:snoopfrogg
ID: 22661621
Ah, valid point.

What is the specific security warning you're seeing?
0
 

Author Comment

by:plokij5006
ID: 22676710
Sorry for the delay in responding, the warning is: "Open File - Security Warning - The Publisher could not be verified, are you sure you want to run this software?" I assume this is because ESC is still installed on this server.
0
 
LVL 11

Expert Comment

by:snoopfrogg
ID: 22702316
Here are a couple of suggestions:  http://techarold.blogspot.com/2006/06/open-file-security-warning-publisher.html.  Notice that the article references the Local Intranet Zone.

Control Panel, Internet Options, Security tab, Local Intranet, Sites, Advanced, add \\Server\share as a website to the "zone".

There is also this option that may help with programs on a local drive:  Control Panel, System, Advanced, Performance Settings, Data Execution Prevention.  You can turn DEP on for everything "except those I select", and manually add them to the list.  Changing the DEP setting requires a reboot.
0
 

Author Comment

by:plokij5006
ID: 22709541
Thanks Snoopfrogg, that seems to work. I will accept both your responses as the solution.

Thanks again!
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question