Solved

Shares as entry points

Posted on 2012-03-28
3
310 Views
Last Modified: 2012-03-29
I found http://technet.microsoft.com/en-us/library/cc526440.aspx

And it says


"Remove All Unnecessary File Shares
Remove all unnecessary file shares on the system to prevent possible information disclosure and to prevent malicious users from using the shares as an entry to the local system"

I am aware that shares can be "shared" to groups like everyone/domain users etc and ift theres senstivie data resident then that can be accessed.

But it hints at shares as an entry point:


"from using the shares as an entry to the local system"

To perhaps gain access to admin areas of the system?

So is that possible, or theoretical? A non admin share shared to the everyone group could actually open up the server to compromise so the user can get access to the admin area of the server?
0
Comment
Question by:pma111
  • 2
3 Comments
 
LVL 5

Accepted Solution

by:
9660kel earned 500 total points
ID: 37776104
It's possible, but it would require access to the server, (authenticated user) and some fairly sophisticated understanding of the file system and some fancy command line and batch files.

Not very likely, but it's generally better to assign permissions to groups than just everyone. Also, just because they have access to the share, doesn't mean they have any permissions to the folders and files contained in the share, that's separate. (the security tab)

For general access, I use the domain users group.
0
 
LVL 3

Author Comment

by:pma111
ID: 37776120
Ok thanks for the reply

When you say "access to the server", hwo do you mean. SAy for example

\\server\share\dir\file.xls (shared to everyone - so a random user navigates to that file/folder), does that quantify as access to the server?
0
 
LVL 5

Expert Comment

by:9660kel
ID: 37776140
They would need a user account that has access to the share. Essentially it COULD make it easier to escalate privileges on the server, although with the type of skills needed, they could probably do that anyway, it just leaves fewer doors open to use the domain users group.

Really the main problem with open shares is virus infections spreading via the share.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now