Solved

Bypass Traverse Checking Security

Posted on 2012-03-27
6
1,287 Views
Last Modified: 2012-06-22
Can someone please tell me if Backup Operators and Users groups actually need to be given this right?  We follow DISA Stigs and this was a finding.  We need to know if they can be removed safely and if not, sound justification.  Thanks in advance.
0
Comment
Question by:BrianRB
  • 3
  • 2
6 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 250 total points
ID: 37771582
It should give you some performance gains on long/deep folders, because the account can traverse the path.  Having said that I don't have stats to know how noticeable the gain would be.

Is this a CAT I, II, or III finding (for those not familiar with the DISA stigs CAT1 is most critical)

Thanks

Mike
0
 
LVL 2

Author Comment

by:BrianRB
ID: 37771629
3 I believe.  I'll confirm.  Do you see why Backup Ops and the users groups need to be added?
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 37771637
I could see the case for backup ops as accounts used to backup do have to go through the entire directory.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 2

Author Comment

by:BrianRB
ID: 37771647
V-26475      STIG.DOD.MIL      WINUR-000008      Automated      CAT III      Unauthorized accounts will not have the "Bypass traverse checking" user right      "Inappropriate granting of user rights can provide system, administrative, and other high level capabilities.

Accounts with the ""Bypass traverse checking"" right can pass through folders when browsing even if they do not have the Traverse Folder access permission. They could potentially view sensitive file and folder names. They would not have additional access to the files and folders unless it is granted through permissions"      "Analyze the system using the Security Configuration and Analysis snap-in.
Expand the Security Configuration and Analysis tree view.
Navigate to Local Policies -> User Rights Assignment.

If any accounts or groups other than the following are granted the “Bypass traverse checking” right, this is a finding:

Administrators
Authenticated Users
Local Service
Network Service"
0
 
LVL 39

Accepted Solution

by:
Adam Brown earned 250 total points
ID: 37772067
Heh. That's hilarious. It's barking about the Backup Operators group having Bypass Traverse checking, but that explanation says it's okay for the Authenticated Users group to have it. That means everyone is going to have it anyway.

Generally it's safe to remove the Bypass right from the Backup Operators group, particularly if it is already assigned to the Authenticated Users group. Again, if you're not using the Backup Operators group, this finding is mostly mitigated by that. The end result of removing the right from that group is that backup processes that use accounts in the Backup Operators group for authentication (not particularly common) will not be able to read the entire file structure if they are not granted permission to do so. This will affect those backups. It's generally a better idea to configure backup services to run using the local service or a highly secured specialized administrative account with no local or remote login rights.
0
 
LVL 2

Author Closing Comment

by:BrianRB
ID: 37772188
You guys are the best.  Thx.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
NTFS Permissions 6 48
Mysterious disks wanting to be formatted 6 41
MS Endpoint Protection 2 25
Apply Unique Local Admin password for all Computer through GPO 34 47
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question