Solved

AccessChk

Posted on 2013-06-10
7
1,237 Views
Last Modified: 2013-06-14
Has anyone every run the AccessChk utility from Sys internals?

I am a bit perplexed by the findings?

I've run accesschk "domain users" across my H:\profile\desktop folder, and it returns lots of entries (i.e. indicating domain users can access my H:\profile\desktop folder".

It I run CACLS over the same folder, theres no entry for "domain users", so all I can imagine is CACLS is purely NTFS (directory) permissions, whereas accesschk is a cumulative of share/directory permissions?

Any ideas?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 55

Expert Comment

by:McKnife
ID: 39235120
> i.e. indicating domain users can access my H:\profile\desktop folder
Oh yeah? So how does it indicate that? accesscheck would list the permission type to the left of the filename (like "R" for read).
0
 
LVL 3

Author Comment

by:pma111
ID: 39235153
My impression was it only lists results where the user or group has permission on a specific file/folder? Is this not true? Does it also cover 'list folder contents' only entries? Or only read and write?
0
 
LVL 3

Author Comment

by:pma111
ID: 39235161
It seems a bit pointless if you have to supply a username or group over a directory your interested in (say 200 files) and you have to view each file to see what's to the left of the file name. Is there no way to filter down to only those files or directories a user or group can actually access ?
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 55

Expert Comment

by:McKnife
ID: 39235358
Did you look at the parameters? There are P's for all your needs.
0
 
LVL 3

Author Comment

by:pma111
ID: 39235374
Can you provide some example syntax to just list files that a specific user can access in a specific directory (and leave out those they can't ? )
0
 
LVL 55

Accepted Solution

by:
McKnife earned 500 total points
ID: 39235392
For example this shows all files with read or write access
accesschk -rw username path
0
 
LVL 3

Author Comment

by:pma111
ID: 39235410
Many thanks
0

Featured Post

Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Know what services you can and cannot, should and should not combine on your server.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question