Solved

Shares as entry points

Posted on 2012-03-28
3
317 Views
Last Modified: 2012-03-29
I found http://technet.microsoft.com/en-us/library/cc526440.aspx

And it says


"Remove All Unnecessary File Shares
Remove all unnecessary file shares on the system to prevent possible information disclosure and to prevent malicious users from using the shares as an entry to the local system"

I am aware that shares can be "shared" to groups like everyone/domain users etc and ift theres senstivie data resident then that can be accessed.

But it hints at shares as an entry point:


"from using the shares as an entry to the local system"

To perhaps gain access to admin areas of the system?

So is that possible, or theoretical? A non admin share shared to the everyone group could actually open up the server to compromise so the user can get access to the admin area of the server?
0
Comment
Question by:pma111
  • 2
3 Comments
 
LVL 5

Accepted Solution

by:
9660kel earned 500 total points
ID: 37776104
It's possible, but it would require access to the server, (authenticated user) and some fairly sophisticated understanding of the file system and some fancy command line and batch files.

Not very likely, but it's generally better to assign permissions to groups than just everyone. Also, just because they have access to the share, doesn't mean they have any permissions to the folders and files contained in the share, that's separate. (the security tab)

For general access, I use the domain users group.
0
 
LVL 3

Author Comment

by:pma111
ID: 37776120
Ok thanks for the reply

When you say "access to the server", hwo do you mean. SAy for example

\\server\share\dir\file.xls (shared to everyone - so a random user navigates to that file/folder), does that quantify as access to the server?
0
 
LVL 5

Expert Comment

by:9660kel
ID: 37776140
They would need a user account that has access to the share. Essentially it COULD make it easier to escalate privileges on the server, although with the type of skills needed, they could probably do that anyway, it just leaves fewer doors open to use the domain users group.

Really the main problem with open shares is virus infections spreading via the share.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 10 4 55
Google Play app store not being blocked from smartphones 4 51
md5 password 3 60
Current Mac OS X Network Profiles and Firewall 5 51
Pop culture is prime bait for hackers seeking to infect user’s computers and mobile devices with malicious malware. Hackers know exactly what the latest trends are online and know how to use them to their advantage.
With healthcare moving into the digital age with things like Healthcare.gov, the digitization of patient records and video conferencing with patients, data has a much greater chance of being exposed than ever before.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now