Huge Bug in security Filesystem of NTFS ?

Posted: 03-13-2008, 03:11 PM
Hi people,

on my Vista Ultimate I have just create another user account, (for a friend
of my) how is only members of USERS

on my HDD E:\ the security rights are those:

Authenticated users = ~Full control
SYSTEM = ful control
Administrators = full control
and
Users = Read & execute, List folder contents, Read

but with this new account I can still remove thing on E:\ !!!!!!!!

(the security settings of the delete test file are the same as the root
Disk)

So what happen ??



Huge Bug in security Filesystem of NTFS ?


Responses to "Huge Bug in security Filesystem of NTFS ?"

Max
Guest
Posts: n/a
 
Re: Huge Bug in security Filesystem of NTFS ?
Posted: 03-13-2008, 03:22 PM

ok now I have remove the "Authenticated users" privilege on a file to test
and now it working he cannot delete this file,

but what is this new group under Vista ? and why "simple Users" by default
can delete file !!!!
and why under managing Local Users & Groups I can't see the group
Authenticated users ??

thx people

Mike Brannigan
Guest
Posts: n/a
 
Re: Huge Bug in security Filesystem of NTFS ?
Posted: 03-13-2008, 03:39 PM
"Max" <twinsen24@hotmail.com> wrote in message
news:9317D38F-B72D-4AA1-B1B5-972B15F55A74@microsoft.com...
>
> ok now I have remove the "Authenticated users" privilege on a file to
> test and now it working he cannot delete this file,
>
> but what is this new group under Vista ? and why "simple Users" by default
> can delete file !!!!
> and why under managing Local Users & Groups I can't see the group
> Authenticated users ??
>
> thx people
You cannot see Authenticated Users under Local Users & Groups as it not a
group you can add or remove anyone from.
It is a computed group that represents all accounts that are currently
correctly authenticated by the local security subsystem on that device.

--

Mike Brannigan

Jesper
Guest
Posts: n/a
 
Re: Huge Bug in security Filesystem of NTFS ?
Posted: 03-14-2008, 05:22 PM
The dynamic group "Authenticated Users" was added in Windows NT 4.0 Service
Pack 4. It is hardly new.
---
Your question may already be answered in Windows Vista Security:
http://www.amazon.com/gp/product/047...otectyourwi-20


"Mike Brannigan" wrote:
> "Max" <twinsen24@hotmail.com> wrote in message
> news:9317D38F-B72D-4AA1-B1B5-972B15F55A74@microsoft.com...
> >
> > ok now I have remove the "Authenticated users" privilege on a file to
> > test and now it working he cannot delete this file,
> >
> > but what is this new group under Vista ? and why "simple Users" by default
> > can delete file !!!!
> > and why under managing Local Users & Groups I can't see the group
> > Authenticated users ??
> >
> > thx people
>
> You cannot see Authenticated Users under Local Users & Groups as it not a
> group you can add or remove anyone from.
> It is a computed group that represents all accounts that are currently
> correctly authenticated by the local security subsystem on that device.
>
> --
>
> Mike Brannigan
>
Mike Brannigan
Guest
Posts: n/a
 
Re: Huge Bug in security Filesystem of NTFS ?
Posted: 03-14-2008, 06:11 PM
I never said it was new - maybe you meant to reply to the original poster.

--

Mike Brannigan
"Jesper" <Jesper@discussions.microsoft.com> wrote in message
news:977D3F5C-BCC3-4149-8343-75E2C747708F@microsoft.com...
> The dynamic group "Authenticated Users" was added in Windows NT 4.0
> Service
> Pack 4. It is hardly new.
> ---
> Your question may already be answered in Windows Vista Security:
> http://www.amazon.com/gp/product/047...otectyourwi-20
>
>
> "Mike Brannigan" wrote:
>
>> "Max" <twinsen24@hotmail.com> wrote in message
>> news:9317D38F-B72D-4AA1-B1B5-972B15F55A74@microsoft.com...
>> >
>> > ok now I have remove the "Authenticated users" privilege on a file to
>> > test and now it working he cannot delete this file,
>> >
>> > but what is this new group under Vista ? and why "simple Users" by
>> > default
>> > can delete file !!!!
>> > and why under managing Local Users & Groups I can't see the group
>> > Authenticated users ??
>> >
>> > thx people
>>
>> You cannot see Authenticated Users under Local Users & Groups as it not a
>> group you can add or remove anyone from.
>> It is a computed group that represents all accounts that are currently
>> correctly authenticated by the local security subsystem on that device.
>>
>> --
>>
>> Mike Brannigan
>>
 
LinkBack Thread Tools Display Modes
 


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


Similar Threads
Thread Thread Starter Forum Replies Last Post
Huge WMI / DCOM / Security problem.. Jonas Haggren Windows XP WMI 6 04-18-2006 07:14 AM
WINDOWS XP: NTFS files sytems changes to RAW filesystem with 0 bytes Numero Uno Windows XP Help & Support 1 10-01-2003 02:46 AM
WINDOWS XP: NTFS files sytems changes to RAW filesystem with 0 bytes Numero Uno Windows XP Setup 1 10-01-2003 02:46 AM
WINDOWS XP: NTFS files sytems changes to RAW filesystem with 0 bytes Numero Uno Windows XP Hardware 2 10-01-2003 02:46 AM
winXP boot disk for NTFS filesystem ? Rct. Tsoul Windows XP Network & Web 2 08-15-2003 06:40 PM