cant write to Windows hosts file

Posted on 2013-11-27
Last Modified: 2013-11-29
Hello EE,

I am signed in as a local admin on a windows 7 computer.  I am not signed as THE local admin though.  I am trying to update the hosts file for accessing other websites from another domain.  This is working on other computers currently that I have adjusted for these websites.  if I log on as THE local admin I can make the change.  If I logon as one of the other local admin accounts that are part of the local administrators group it doesnt work.  I have even gone as far as putting one of the local admin accounts as owner of the hosts file and yet when logged on as that account still can not make change to hosts file.  what can i do to correct this problem?  Thanks for your help!
Question by:12string
LVL 36

Accepted Solution

Mahesh earned 500 total points
ID: 39681644
Try below

open cmd with run as administrator

then change directory to C:\windows\system32\drivers\etc

then type "notepad hosts" and enter

Now make your modifications and save and close

LVL 44

Expert Comment

ID: 39681751
By default, everything in %windir% and deeper is owned by "TrustedInstaller"

Take Ownership of the %windir%\System32\etc\drivers\etc folder, then give the new owner (I suggest giving ownership to the Administrators group) Full Control on the Permissions tab.Permissions - Administrators - Full Control (click for larger)
THEN running notepad as administrator will be able to save changes there.

Author Comment

ID: 39681755
Thank you MaheshPM that is another option but how do I change that back so that one doesnt have to do that step?  if the account is in local administrators and local admins have that ability then why does this happen?
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

LVL 36

Assisted Solution

Mahesh earned 500 total points
ID: 39681784
The User Access Control are still enabled on Windows 7 machine by default....which forces you to open cmd \ applications with run as administrator

You can disable these controls through Control Panel \ user accounts \ change user account settings  and just pull the slider to complete bottom (Never Notify)

OR you can disable all UAC through gpedit.msc under computer configuration\windows settings\security settings\local polices\security options, you need to disable those settings starting from user access control (specifically admin approval modes)

OR you can use domain level GPO to disable above these settings

OR you can just disable through registry also.

Its not recommended to modify NTFS security on System folders


Author Closing Comment

ID: 39682033
Thank you Mahesh I was wondering whether I would have to use gpedit but didnt want to waste the time looking the exact location.

Also Thanks Darr247 I did do that as well, before I came to EE, but still got same problem.  took ownership using a specific local acct and then logged on as that acct.
LVL 54

Expert Comment

ID: 39682413
Let me add something about the stuff behind this "effect".
First: UAC introduced these type of effects and UAC came with vista. How come that after 7 years, this problem is still not fully understood by anyone? :))

1. You are logged in as some admin, not as the account "administrator". With default settings, the UAC is off for the account "administrator" even when it's on for the rest. That's why it works with the admin called “administrator” and not with any others.

2. If, as in this case, the ACL of a file does hold the group "administrators" with at least change permissions and NOT everyone AND NOT authenticated users [and not your own account] - then you CANNOT modify the file EVEN when you are a member of the admins group. [By the way: the ownership does not matter]
Why is that so? Because of the UAC. The UAC introduced the concept of elevation [see 3.]. Without "elevating", members of the admin group are treated as weak, restricted users. From the perspective of the ACL, they don't even belong to the group administrators!

3.How to elevate? Now for the most important part...
The host file is usually opened with notepad. Microsoft, in their enormous generosity, has been providing this square and simple program for ages. Problem: it is NOT UAC-aware! It won't TRIGGER elevation. The process of elevating (after "dimming the screen") would need you to click ok on a dialogue that asks for consent, that's all. But notepad is too simple to provide that :) It has not been made compatible with MS’ own technology. Too bad. By the way: task manager is another program that misses to trigger elevation under some circumstances. Poor work.
What can we do? We can…
-modify the ACL of the file to simply hold hold our own account name! or…
-elevate the viewer (notepad) manually by right clicking notepad.exe and selecting “run as administrator”. Or…
-use runas on notepad providing the credentials of the “real” administrator. Or…
-save the file somewhere else and later, push it over to its final destination using explorer! Explorer is UAC aware and will trigger elevation while we move that file and overwrite the old one.
Turning off UAC is not the way to go, believe me.

4. There is even more to it: there is a little known security feature called “mandatory integrity controls/levels” (“MIC”/”MIL”) that can also cross your plans! Think of it as some kind of extra security layer next to the NTFS ACL. If some files/folders are set to have an MIL of “high”, then only elevated processes may write to it. Writing to the root of c:\ is such an example, too.
ILs can be read out and modified by tools like chml.exe

Spread the word

Author Comment

ID: 39685552
Thanks McKnife for the explanation.  To answer your question:

<How come that after 7 years, this problem is still not fully understood by anyone?>

My customers were more win xp than win vista, there was very little need to know or work with win vista ergo the need to ask why this problem exists.

Thanks for the insight and yes I will pass the info on, I know quite a few people will be interested in this answer

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question