S
sv
Hi Everybody,
I am not a pro in Windows security and permissions and would really
appreciate if somebody have encountered same problem before.
We have Windows 2003 domain and there are some network shares that
need to be protected.
For example, only Managers group should has full access to folder
"Secret stuff"., that is owned by OurDomain\Administrators.
Permissions are not inherited from the upper directory structure and do
not propagate to child objects for this folder and no other
users/groups are mentioned in ACL.
Here comes the weird stuff.
I logon to my Windows 2000 workstation as member of Domain
Administrators (I am not in Managers group, however!) and I can
traverse this 'secret' folder, seeing filenames and directories
structure.I cannot see objects security properties.
When I logon to another Windows 2000 or Windows 2003 machine,both
members of the same domain, all I get is "Access denied message",
exactly what is expected with this kind of permissions.
Am I missing something very basic or my computer is possesed by dark
forces?
Please let me know what directions I should look to, any advice will be
gratly appreciated!
I am not a pro in Windows security and permissions and would really
appreciate if somebody have encountered same problem before.
We have Windows 2003 domain and there are some network shares that
need to be protected.
For example, only Managers group should has full access to folder
"Secret stuff"., that is owned by OurDomain\Administrators.
Permissions are not inherited from the upper directory structure and do
not propagate to child objects for this folder and no other
users/groups are mentioned in ACL.
Here comes the weird stuff.
I logon to my Windows 2000 workstation as member of Domain
Administrators (I am not in Managers group, however!) and I can
traverse this 'secret' folder, seeing filenames and directories
structure.I cannot see objects security properties.
When I logon to another Windows 2000 or Windows 2003 machine,both
members of the same domain, all I get is "Access denied message",
exactly what is expected with this kind of permissions.
Am I missing something very basic or my computer is possesed by dark
forces?
Please let me know what directions I should look to, any advice will be
gratly appreciated!