M
Malcolm Dew-Jones
Hello.
This is on XP home edition. (Suggestions for a better group to post in
would be welcome.)
I was cleaning up a system that had the W32.Chod.D worm. Using cacls.exe
I notice that files in \windows\system32 all seem to have the wrong
permissions. For example
cd C:\WINDOWS\SYSTEM32
cacls wuauclt.exe
outputs =>
C:\WINDOWS\SYSTEM32\wuauclt.exe NT AUTHORITY\SYSTEM:F
Everyone:F
I assume that the "Everyone:F" must be wrong, presumably these files must
be read-only for most people, but I don't work with NT enough to know for
sure what is correct or not.
QUESTION: is there a list of the normal correct permissions for the
windows system files that I can get from somewhere?
QUESTION: also, is there a GUI tool on XP that I could use to reset the
acls, instead of using cacls?
I downloaded a thing called "Microsoft Baseline Security Analyzer 2.0"
but it didn't complain about any file permissions, so I assume that it
must not check them (?).
Feedback welcomed, thanks.
This is on XP home edition. (Suggestions for a better group to post in
would be welcome.)
I was cleaning up a system that had the W32.Chod.D worm. Using cacls.exe
I notice that files in \windows\system32 all seem to have the wrong
permissions. For example
cd C:\WINDOWS\SYSTEM32
cacls wuauclt.exe
outputs =>
C:\WINDOWS\SYSTEM32\wuauclt.exe NT AUTHORITY\SYSTEM:F
Everyone:F
I assume that the "Everyone:F" must be wrong, presumably these files must
be read-only for most people, but I don't work with NT enough to know for
sure what is correct or not.
QUESTION: is there a list of the normal correct permissions for the
windows system files that I can get from somewhere?
QUESTION: also, is there a GUI tool on XP that I could use to reset the
acls, instead of using cacls?
I downloaded a thing called "Microsoft Baseline Security Analyzer 2.0"
but it didn't complain about any file permissions, so I assume that it
must not check them (?).
Feedback welcomed, thanks.