Severe Security Issue with Sharing Permissions and Windows

I recently discovered a severe Security issue with the windows sharing an permission settings:
I have two users, an admin user and a parental controlled user. On my mac mini, i have a external harddrive connected. On the harddrive, i have three folders, Itunes, Iphoto (Package) and a Temp Folder. I want to share the Harddrive RW for the admin, but only R for the parental user. But the Temp folder should be accessible for RW for the parental as well.
1. I set the Drive checkbox "ignore ownership" off.
2. I set the permissions of the drive to admin RW, parental R and Everyone to "no access"
3. I apply to enclosed Items
4. I set the permission of the Temp folder to admin RW, parental RW and Everyone to "no access"
5. I apply to enclosed Items
6. I go to "File Sharing" in the Preferences and activate SMB sharing for both users
7. I delete all previous shares
8. I add the Disk and use the proposed permissions which are admin RW, parental R, Everyone "no access"
9. I add the Temp folder and use the proposed permissions which are admin RW, parental RW, Everyone "no access" - Funny, there is a new Group called "Temp" created which has custom access on both sharepoints
10. I connect to the mac over a Windows machine (NTLM auth set appropriatly). Now I try to create a folder on the root of the Disk share, I get a denied message.
BUT WHEN I GO INTO A SUBFOLDER (eg. ITUNES or IPHOTO), WHICH HAS ALSO JUST "R" PERMISSION FOR THE PARENTAL USER, I AM ABLE TO RW, DELETE AND DO EVERYTHING!!!
TO RECAPITULATE: THE SHARING PERMISSIONS ARE "R", AND THE FILE PERMISSIONS IN THE RESPECTIVE FOLDERS FOR THE RESPECTIVE USER ARE ALSO JUST "R". BUT THE USER CAN DO EVERYTHING IN THE SUBFOLDERS!!!

I recently discovered a severe Security issue with the windows sharing an permission settings:
I have two users, an admin user and a parental controlled user. On my mac mini, i have a external harddrive connected. On the harddrive, i have three folders, Itunes, Iphoto (Package) and a Temp Folder. I want to share the Harddrive RW for the admin, but only R for the parental user. But the Temp folder should be accessible for RW for the parental as well.
1. I set the Drive checkbox "ignore ownership" off.
2. I set the permissions of the drive to admin RW, parental R and Everyone to "no access"
3. I apply to enclosed Items
4. I set the permission of the Temp folder to admin RW, parental RW and Everyone to "no access"
5. I apply to enclosed Items
6. I go to "File Sharing" in the Preferences and activate SMB sharing for both users
7. I delete all previous shares
8. I add the Disk and use the proposed permissions which are admin RW, parental R, Everyone "no access"
9. I add the Temp folder and use the proposed permissions which are admin RW, parental RW, Everyone "no access" - Funny, there is a new Group called "Temp" created which has custom access on both sharepoints
10. I connect to the mac over a Windows machine (NTLM auth set appropriatly). Now I try to create a folder on the root of the Disk share, I get a denied message.
BUT WHEN I GO INTO A SUBFOLDER (eg. ITUNES or IPHOTO), WHICH HAS ALSO JUST "R" PERMISSION FOR THE PARENTAL USER, I AM ABLE TO RW, DELETE AND DO EVERYTHING!!!
TO RECAPITULATE: THE SHARING PERMISSIONS ARE "R", AND THE FILE PERMISSIONS IN THE RESPECTIVE FOLDERS FOR THE RESPECTIVE USER ARE ALSO JUST "R". BUT THE USER CAN DO EVERYTHING IN THE SUBFOLDERS!!!

Similar Messages

  • Issues with illustrator 10 and windows 8

    any known issues with illustrator 10 and windows 8...version worked fine on windows xp....new computer with windows 8....now cannot seem to operate. Loads, and shows access but will NOT start up. help ! thanx ttp74

    AI 10 is now 10 years or so old and was never tested on nor designed for Win 7 or Win 8. You should simply assume it's not compatible and will never run properly. feel free to spend your time with the compatibility modes and al lsorts of hacking with the security stuff and otehr settings, but to be honest, it will probably be a waste of time.
    Mylenium

  • I have an issue with the tabs and windows disappearing....?

    I have a constant problem with Firefox now. I notice that with Firefox 4 and 5 there has been a reoccurring problem with the tabs and windows closing on their own. If I have more than one window open, one of them will suddenly disappear and I wont see the tab at the bottom anymore until I click out of the one I am currently on. It is very annoying and only when I get out of Firefox completely will it sometimes reappear. Even more frightening is the fact that when I move the mouse downward to the bottom of the page the page shuts out as if I clicked out of it.
    I am wondering if this is a security issue meaning some type of malware or virus that is manipulating my browser or is this a common issue that has some unknown cause? I would like to know what the cause is and how it can be fixed because it annoys me all the time. Please help!!

    No Issue with the voltage in general. iPad is being charged via USB.
    1. If you connect it directly to the computer - no problem.
    2. If you want to charge it directly from the power socket you will need this:
    http://store.apple.com/uk/product/MB706B/B/apple-usb-power-adapter
    TZ

  • Adobe Acrobat 8 Standard compatibility issues with Office 2007 and Windows 7

    I just updated my platform to Windows 7 and upgraded from Microsoft Office 2003 to Microsoft Office 2007.  The PDF printer did not download and realized that there are compatibility issues with Office 2007.  How could I get this fixed?

    Buy Acrobat 11.

  • Wireless Router issues with MacBook Pro and Windows XP laptops

    hello,
    I have a d-link wireless router and I have a MacBook Pro and a Windows XP laptops. My issue is that I have to keep rebooting either the router or the modem (which I both replaced) and it still does not work right. Now can mac and windows work simultaneously through a wireless router (d-link) with no issues?

    My problem is that every time I log off either computer, and when I start it back up up again I have to reconfigure all over again for both laptops to get connected to the internet. I called the d-link people and they pretty much said if i still had problem to go their web sites and download their firmware (which I have that version) so I am running out of options because I just can't turn either of them on with out reconfiguring it. Now I am using WPA on them. Could that be the issue? But right now I do not know. This is my first mac and I am getting a little irritated by this. Overall I like the mac except for this little issue. Does that help?

  • Security issue with a website and java

    I am having trouble getting Java to work on a website, the message tells me that I have a security issue  but I don't know how to fix it??

    The site may be sending Firefox for Android a page that is not correctly formed.
    We have a feature in Firefox 39 which will allow the request desktop site menu item to show the full desktop site.

  • Dual monitor issue with 10.8 and Windows 7 (bootcamp)

    I've a read a lot of threads here about people having nightmare-ish problems after upgrading.  Thankfully, this isn't one of them, just a frustration that I'd like advice on.
    My system:  2010 13" MBP, 2.4GHz Intel Core 2 Duo, 8GB RAM, 320GB HD.  Work setup has external 17" Dell Widescreen monitor connected with VGA to miniDisplay adapter.  Home theater setup has 23" Dell monitor connected with HDMI to miniDisplay cable.
    I upgraded from 10.6.8 to 10.8, as I like to stay up to date and it seemed ML fixed many of the Lion issues.  After finding out Front Row is completely gone I just about reverted (my laptop doubles as my home theater control).  I found XBMC, and it works, sort of (anyone with news on whether Front Row will be returned to us, let me know!).
    Enough babbling, my issue:
    When I switch from bootcamp windows 7 back to OS X, my second monitor's resolution is all screwed up (very low) and the dock and menu bar are BOTH on the second (Dell 17") screen, though it's not in a mirror mode.
    Usually the dock is on the laptop screen, and the menu bar is on the second.
    All I have to do is unplug the miniDisplay port and plug it back in, but is there a setting I'm missing to keep me from having to do this?  Also, I've never used Windows at home, so I've never had to switch with the 23 inch monitor connected.  Don't really want to try as that system is working quite well right now.
    Thanks!
    -Rob

    It's NVidia GeForce 320M.
    Just checked the drivers page and the Mac side only lists up to 10.6.8
    Should I assume that the update needs to be on the Windows 7 side?  At one point last November I tried to update on the Windows side and it caused all sorts of **** on my system causing me to have to reinstall both OS X and 7.
    May be worth another try?
    -Rob

  • Security issue with the SGA and multiple installation group.

    Hi,
    Documentation ARE WRONG:
    http://download.oracle.com/docs/cd/E11882_01/rac.112/e10743/preparing.htm#TDPRC131
    # useradd -u 1100 –g oinstall -G dba -d /home/oracle -r oracle
    http://download.oracle.com/docs/cd/E11882_01/install.112/e10816/typinstl.htm#CWSOL156
    # useradd -u 1100 -g oinstall -G dba oracle
    The "-g" and "-G" must be exchange!
    In an advanced installation with multiple Oracle users call them ( ora1, ..., orai, ..., oran )
    with multiple OSdba group defined users call them ( dba1, ..., dbai, ..., dban)
    Associate each oracle user to a dba group with the same number and the install group as oracle told it.
    User ora1 group dba1
    User orai group dbai
    User oran group dban
    Now make the software installationS with the group OSinstall ( install) as written in the documentation, in 3 Oracle_home
    Call the oracle_home1, oracle_home2, oracle_home3
    Now check semaphores, Sharedmemory and files!
    ipcs -msa
    IPC status from <running system> as of Thu Apr 29 12:14:06 CEST 2010
    T ID KEY MODE OWNER GROUP CREATOR CGROUP NATTCH SEGSZ CPID LPID ATIME DTIME CTIME
    Shared Memory:
    m 16777246 0x6525858 rw-rw-- oracle2 install oracle2 install 36 5368725504 3479 4298 12:10:01 12:10:31 16:30:45
    T ID KEY MODE OWNER GROUP CREATOR CGROUP NSEMS OTIME CTIME
    Semaphores:
    s 50331701 0xb7892c1a ra-ra-- oracle2 install oracle2 install 202 16:30:47 16:30:45
    s 50331700 0xb7892c19 ra-ra-- oracle2 install oracle2 install 202 no-entry 16:30:45
    s 50331699 0xb7892c18 ra-ra-- oracle2 install oracle2 install 202 12:13:48 16:30:45
    ls -l $OSD/oradata/*/*/* | sed s/oracle/oracle2/
    -rw-r----- 1 oracle2 install 11600384 Apr 14 18:30 /app1/oracle/admin/ora11g/oradata/ORA11G/changetracking/o1_mf_5wcsdcfh_.chg
    -rw-r----- 1 oracle2 install 11600384 Apr 15 15:08 /app1/oracle/admin/ora11g/oradata/ORA11G/changetracking/o1_mf_5wf7787k_.chg
    -rw-r----- 1 oracle2 install 11600384 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/changetracking/o1_mf_5wg8jggf_.chg
    -rw-r----- 1 oracle2 install 16695296 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/controlfile/o1_mf_5wg4j9go_.ctl
    -rw-r----- 1 oracle2 install 524296192 Apr 29 03:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_aud__dol_5wg4mntr_.dbf
    -rw-r----- 1 oracle2 install 104865792 Apr 29 03:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_aud__dol_5wg4mp3v_.dbf
    -rw-r----- 1 oracle2 install 209723392 Apr 29 03:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_example_5wg4ml5z_.dbf
    -rw-r----- 1 oracle2 install 419438592 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_stat_dba_5wg4mmhg_.dbf
    -rw-r----- 1 oracle2 install 2097160192 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_sys_undo_5wg4kf8n_.dbf
    -rw-r----- 1 oracle2 install 2097160192 Apr 29 03:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_sys_undo_5wg4lss2_.dbf
    -rw-r----- 1 oracle2 install 1363156992 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_sysaux_5wg4k1xf_.dbf
    -rw-r----- 1 oracle2 install 1048584192 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_system_5wg4jp26_.dbf
    -rw-r----- 1 oracle2 install 209723392 Apr 28 22:01 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_temp0_5wg4l302_.tmp
    -rw-r----- 1 oracle2 install 209723392 Apr 15 16:06 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_temp1_5wg4lsod_.tmp
    -rw-r----- 1 oracle2 install 104865792 Apr 29 03:05 /app1/oracle/admin/ora11g/oradata/ORA11G/datafile/o1_mf_users_5wg4l33f_.dbf
    -rw-r----- 1 oracle2 install 104858112 Apr 29 13:05 /app1/oracle/admin/ora11g/oradata/ORA11G/onlinelog/o1_mf_1_5wg4jb44_.log
    -rw-r----- 1 oracle2 install 104858112 Apr 28 21:00 /app1/oracle/admin/ora11g/oradata/ORA11G/onlinelog/o1_mf_2_5wg4jdn6_.log
    -rw-r----- 1 oracle2 install 104858112 Apr 28 22:00 /app1/oracle/admin/ora11g/oradata/ORA11G/onlinelog/o1_mf_3_5wg4jgw8_.log
    -rw-r----- 1 oracle2 install 104858112 Apr 29 03:00 /app1/oracle/admin/ora11g/oradata/ORA11G/onlinelog/o1_mf_4_5wg4jk64_.log
    -rw-r----- 1 oracle2 install 104858112 Apr 29 13:01 /app1/oracle/admin/ora11g/oradata/ORA11G/onlinelog/o1_mf_5_5wg4jmcd_.log
    ls -l $OH/bin/oracle | sed s/oracle/oracle2/
    -rwsr-s--x 1 oracle2 install 256263032 Apr 14 13:54 /app1/oracle/product/11.2.0_64/db_1/bin/oracle*
    That the evidence the documentation provide you a wrong way to do it!
    François LANGE

    The right document syntax for this is:
    UNIX: Do I Need To Use The "oinstall" Group? (Doc ID 463052.1)
    FRançois

  • Security issue with NetStream.appendBytes() and BitmapData.draw()

    Iuse appendBytes to continuously and seamlessly stream video data into a netStream. since we're NOT playing the video files directly from a web domain, there is no meaning to the checkPolicyFile property of our netStream object and therefore - we cannot BitmapData.draw() our Video instance with the netStream attached.
    Is there any possibility to get images from the netStream in order to manipulate them on-the-fly?

    I ran into the same problem.  Have you managed to find a solution to get around the security violation?

  • Has anyone seen issues with NI products and Windows XP SP2?

    Our IT dept is talking about the above update.
    Since I support everything NI produces, I am looking for any issues that may be related.
    Thanks in advance for helping me out on this!
    Ben
    Ben Rayner
    I am currently active on.. MainStream Preppers
    Rayner's Ridge is under construction

    Windows XP SP2 is a major update with a lot of changes especially in the area of network security. As most of NI's software products were released before this service pack we haven't been able to test our software with this maintenance release so some issues may exist.
    Currently we are testing all of our software products on XP SP2 systems documenting all issues we find in the KnowledgeBase. Please search the KB for the keywords XP SP2.
    Currently you should find at least three documented issues there.
    Best regards,
    Jochen
    NI-Germany

  • Mapping issues with Server 2003 and windows 8.1 machine

    We are running Windows Server 2003 and trying to map network drives through a GPO script on a Windows 8.1 machine.  The drives don't get mapped and if they do, it takes them 10minutes or more to show up.  The Folder Redirection is not working
    as well.  Any suggestions?

    Hi,
    This is because
    by default, on client computers, Group
    Policy processing is not synchronous, that is client computers typically do
    not wait for the network for GPO settings to be fully initialized at startup and logon. 
    Solution:
    Enable the
    policy setting Always
    wait for the network at computer startup and logon to set the client computers wait
    for the network for GPO settings to be fully initialized during computer startup and user logon.
    Steps to enable the Policy Setting
    - Open Group Policy Management Console (start -> Run -> Type GPMC.MSC).
    - Edit the required GPO and navigate to
    Computer Configuration/Administrative Templates/System/Logon and enable the option Always
    wait for the network at computer startup and logon 
    Checkout the below thread on similar problem and solution,
    http://social.technet.microsoft.com/Forums/en-US/285e5a93-a5c8-4725-9067-af48bcde5c78/user-home-folder-problem?forum=winserverfiles
    Regards,
    Gopi
    JiJi
    Technologies

  • S7-392 issue with Hyper-V and Windows 10

    Hi, I upgraded my S7-392 to Windows 10, and as soon as I enable Hyper-V in Windows 10 and reboot, the screen gets stuck at the boot logo. The progress ring is spinning and nothing happens after that. I can login in safe mode and disable the Hyper-V, and the system boots normally. I tried this many times. Everytime I enable Hyper-V, I am unable to boot into windows again (until I disable Hyper-V). I also performed a clean install of Windows 10 pro on my S7-392, and the same problem persists. Any solution to this. This is really urgent and important. This is my primary development machine, and I need to run Windows Phone Emulators in Visual Studio. Thanks and appreciate quick help. Naweed

    found this:http://mou.me.uk/2012/08/27/windows-wont-boot-after-activating-hyper-v-in-windows-8/ yes it's for windows 8 but...can be a good suggestion, so if you didn't already installed updated Intel chipset drivers, give it a try:http://global-download.acer.com/GDFiles/Driver/Chipset/Chipset_Intel_10.1.1.8_W10x64_A.zip?acerid=635730682896833407&Step1=ULTRA-THIN&Step2=ASPIRE&Step3=ASPIRE%20S7-392&OS=10M1&LC=en&BC=ACER&SC=PA_6

  • Security Issues with 8.1 Pro

    I have had several security issues with Windows 8.1 Pro.
    I am curious if the following apps should be loaded by default:
    CheckPoint.VPN
    JuniperNetworks.JunosPulseVpn
    SonicWALL.MobileConnect
    F.vpn.client
    These programs are installed on a fresh install of Windows 8.1 Pro but I do not think they should be.  They are present prior to the install of any 3rd party programs or apps.
    Thanks

    I found them in my firewall list on my Windows 8.1 Pro installation and posted a question on a forum as well, though I don't think it was here.  I don't believe anyone ever answered.
    It looks as though these are parts of the bundled virtual private networking clients.
    Note, for example, the "distributed by Microsoft as part of Windows 8.1" wording on this page:
    http://www.sonicwall.com/app/projects/file_downloader/document_lib.php?t=PG&id=605
    -Noel
    Detailed how-to in my eBooks:  
    Configure The Windows 7 "To Work" Options
    Configure The Windows 8 "To Work" Options

  • Any security issues with My MSN or outlook bookmarks

    any security issues with My Msn and Outlook as bookmarks

    Your question is not quite clear, and no Mac can iOS, but anything and everything made by or for Microsoft carries a security risk.
    Which is why most sensible people run Apple OS X.

  • No issues, but curious..why do I always get permissions repaired when I click on 'repair permissions in Disk Utility......it usually has to do with core permissions and it's happened since i got this MacBook Pro in 3/11..it continues with 10.7

    No issues, but curious..why do I always get permissions repaired when I click on 'repair permissions' in Disk Utility ??......it usually has to do with core permissions and it's happened since i got this MacBook Pro in 3/11..I'll try this every 2/3 wks and always get repairs.....yet, I don't really have issues....it's been weird.......it continues with 10.7 and the update to 10.7.1.. a sample:
    Permissions differ on “System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Support/Rem ote Desktop Message.app/Contents/Resources/da.lproj/UIAgent.nib”; should be -rw-r--r-- ; they are drw-r--r-- .
    Repaired “System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Support/Rem ote Desktop Message.app/Contents/Resources/da.lproj/UIAgent.nib”
    Permissions differ on “System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Su pport/LockScreen.app/Contents/Resources/da.lproj/MainMenu.nib”; should be -rw-r--r-- ; they are drw-r--r-- .
    Repaired “System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Su pport/LockScreen.app/Contents/Resources/da.lproj/MainMenu.nib”
    Permissions differ on “System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Su pport/LockScreenLeopard386.app/Contents/Resources/da.lproj/MainMenu.nib”; should be -rw-r--r-- ; they are drw-r--r-- .
    Repaired “System/Library/CoreServices/RemoteManagement/AppleVNCServer.bundle/Contents/Su pport/LockScreenLeopard386.app/Contents/Resources/da.lproj/MainMenu.nib”
    Group differs on “Library/Preferences/com.apple.alf.plist”; should be 80; group is 0.
    Repaired “Library/Preferences/com.apple.alf.plist”
    Warning: SUID file “System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/MacOS/ARDAg ent” has been modified and will not be repaired.

    As described in this article, don't worry about it:
    http://support.apple.com/kb/TS1448?viewlocale=en_US

Maybe you are looking for

  • PIE Chart Color Highlight - setting colors

    Hi PIE Chart showing default colors even after setting the diffent colors to OIE chart slices from Color Highlight tab. PIE chart is showing only one slice when I select Data for the PIE Char is "For all records". Could you please let me know how to

  • BPM help please

    Hi Gurus, I tried to search on SDN about BPM design for raising exceptions, but there are not many blogs on it. I am calling a third party synchronous webservice in BMP. The WSDL has 3 messages in it, a request, a response and an exception message. I

  • Error Generating Form against external application database

    I'm hoping the answer to this is simple, as others in the office can do this without any trouble, but can't remember how they made it work... My client has their repository and application schemas in separate databases. When I try and generate a form

  • Parsing Options Data from Files

    With the help of the folks on this discussion board, I now have a directory filled with daily options data for all traded options. What I would like to do now is parse the data out so that I have one file with all the options data for one or two stoc

  • Web Enabled SAP environments

    I would be interested to know why people have chosen to use PHP in a SAP environment. I started using PHP with SAP because the clients I worked for did not have a SAP environment with any web functionality. Therefore without PHP it would be quite dif