Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - UAC: Bug or just poor error message?

Reply
 
Old 01-17-2007   #1 (permalink)
Marco Peretti


 
 

UAC: Bug or just poor error message?

Hi Everyobdy,

If you try to copy files from a network location to a local one where only
the TrustedInstaller user has write access then you get an error message
stating that your mapped drive refers to a location that is unavailable --
which is not true. In my opinion it should give an Access Denied error
message.

More details and a couple of screen shots can be found here:
http://leastprivilege.blogspot.com/2007/01/uac-unc.html


cheers,

Marco

--
mperetti [at] beyondtrust [dot] com
www.beyondtrust.com




My System SpecsSystem Spec
Old 01-17-2007   #2 (permalink)
Paul Adare


 
 

Re: UAC: Bug or just poor error message?

In article <eJZuMHhOHHA.3552@TK2MSFTNGP03.phx.gbl>, in the
microsoft.public.windows.vista.security news group, <"Marco
Peretti" <marco alla neovalens dot com>> says...

> If you try to copy files from a network location to a local one where only
> the TrustedInstaller user has write access then you get an error message
> stating that your mapped drive refers to a location that is unavailable --
> which is not true. In my opinion it should give an Access Denied error
> message.


TrustedInstaller is a service, not a user.

>
> More details and a couple of screen shots can be found here:
> http://leastprivilege.blogspot.com/2007/01/uac-unc.html


Your blog entry indicates that you're running Explorer elevated.
My understanding is that you can't do this. How are you running
it elevated?

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld

My System SpecsSystem Spec
Old 01-17-2007   #3 (permalink)
Marco Peretti


 
 

Re: UAC: Bug or just poor error message?

> TrustedInstaller is a service, not a user.

I know that, but the identity used is the TrustedInstaller SID,

> Your blog entry indicates that you're running Explorer elevated.
> My understanding is that you can't do this. How are you running
> it elevated?


have simply navigated to Accessories->Explorer and have chosen Run
Elevated.

cheers,

Marco

--
mperetti [at] beyondtrust [dot] com
http://leastprivilege.blogspot.com
http://www.beyondtrust.com


My System SpecsSystem Spec
Old 01-17-2007   #4 (permalink)
Paul Adare


 
 

Re: UAC: Bug or just poor error message?

In article <OqozLvhOHHA.3552@TK2MSFTNGP03.phx.gbl>, in the
microsoft.public.windows.vista.security news group, <"Marco
Peretti" <marco alla neovalens dot com>> says...

>
> > TrustedInstaller is a service, not a user.

>
> I know that, but the identity used is the TrustedInstaller SID,


Right, just being precise here.

>
> > Your blog entry indicates that you're running Explorer elevated.
> > My understanding is that you can't do this. How are you running
> > it elevated?

>
> have simply navigated to Accessories->Explorer and have chosen Run
> Elevated.


That doesn't actually get you an elevated instance of Explorer.

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld

My System SpecsSystem Spec
Old 01-17-2007   #5 (permalink)
David Hearn


 
 

Re: UAC: Bug or just poor error message?

Paul Adare wrote:
> In article <OqozLvhOHHA.3552@TK2MSFTNGP03.phx.gbl>, in the
> microsoft.public.windows.vista.security news group, <"Marco
> Peretti" <marco alla neovalens dot com>> says...
>
>>> TrustedInstaller is a service, not a user.

>> I know that, but the identity used is the TrustedInstaller SID,

>
> Right, just being precise here.
>
>>> Your blog entry indicates that you're running Explorer elevated.
>>> My understanding is that you can't do this. How are you running
>>> it elevated?

>> have simply navigated to Accessories->Explorer and have chosen Run
>> Elevated.

>
> That doesn't actually get you an elevated instance of Explorer.


What if you have the option "Launch folder windows in a separate
process" ticked? The issue I've heard is that all Explorer windows run
under the same process and therefore you cannot elevate just 1 window.
However, I've also heard it suggested that having separate processes
enabled means that you can elevate a new explorer window.

D
My System SpecsSystem Spec
Old 01-17-2007   #6 (permalink)
Marco Peretti


 
 

Re: UAC: Bug or just poor error message?

>> > Your blog entry indicates that you're running Explorer elevated.
>> > My understanding is that you can't do this. How are you running
>> > it elevated?

>>
>> have simply navigated to Accessories->Explorer and have chosen Run
>> Elevated.

>
> That doesn't actually get you an elevated instance of Explorer.


Don't have access to Vista today. I'll double-check tomorrow and report
here.

Marco


My System SpecsSystem Spec
Old 01-17-2007   #7 (permalink)
Paul Adare


 
 

Re: UAC: Bug or just poor error message?

In article <#ZDpWCiOHHA.1872@TK2MSFTNGP04.phx.gbl>, in the
microsoft.public.windows.vista.security news group, David Hearn
<david.hearn@newsgroup.nospam> says...

> What if you have the option "Launch folder windows in a separate
> process" ticked? The issue I've heard is that all Explorer windows run
> under the same process and therefore you cannot elevate just 1 window.
> However, I've also heard it suggested that having separate processes
> enabled means that you can elevate a new explorer window.
>


That seems to do the trick, yes, thanks for the reminder!

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld

My System SpecsSystem Spec
Old 01-17-2007   #8 (permalink)
Paul Adare


 
 

Re: UAC: Bug or just poor error message?

In article <eOtkxKiOHHA.3944@TK2MSFTNGP06.phx.gbl>, in the
microsoft.public.windows.vista.security news group, <"Marco
Peretti" <marco alla neovalens dot com>> says...

> >> > Your blog entry indicates that you're running Explorer elevated.
> >> > My understanding is that you can't do this. How are you running
> >> > it elevated?
> >>
> >> have simply navigated to Accessories->Explorer and have chosen Run
> >> Elevated.

> >
> > That doesn't actually get you an elevated instance of Explorer.

>
> Don't have access to Vista today. I'll double-check tomorrow and report
> here.
>


I've tested it. Unless, as David points out, you run folder
windows in a separate process you don't actually get an elevated
instance.

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld

My System SpecsSystem Spec
Old 01-18-2007   #9 (permalink)
Marco Peretti


 
 

Re: UAC: Bug or just poor error message?

Paul,

> I've tested it. Unless, as David points out, you run folder
> windows in a separate process you don't actually get an elevated
> instance.


I have checked the machine setting and, since it was a new box, it did not
have that option set yet and I just made the mistake of assuming it was.
When I try to copy to a protected folder, from an elevated process, I get a
proper access denied dialog.


--
Cheers,

Marco

mperetti [at] beyondtrust [dot] com
http://leastprivilege.blogspot.com
http://www.beyondtrust.com
--


My System SpecsSystem Spec
Old 01-18-2007   #10 (permalink)
Marco Peretti


 
 

Re: UAC: Bug or just poor error message?

just one more info: when I try to copy to a protected location from a
regular exe ( no privs ) and elevate when prompted, I get an error message
about my share drive being unavailable instead of an access denied. that,
IMHO, is wrong.
--
Cheers,

Marco

mperetti [at] beyondtrust [dot] com
http://leastprivilege.blogspot.com
http://www.beyondtrust.com
--

"Marco Peretti" <tired_of_spam@hotmail.com> wrote in message
news:%23oiUn5tOHHA.3872@TK2MSFTNGP06.phx.gbl...
> Paul,
>
>> I've tested it. Unless, as David points out, you run folder
>> windows in a separate process you don't actually get an elevated
>> instance.

>
> I have checked the machine setting and, since it was a new box, it did not
> have that option set yet and I just made the mistake of assuming it was.
> When I try to copy to a protected folder, from an elevated process, I get
> a proper access denied dialog.
>
>
> --
> Cheers,
>
> Marco
>
> mperetti [at] beyondtrust [dot] com
> http://leastprivilege.blogspot.com
> http://www.beyondtrust.com
> --
>
>



My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
new message window uploading photos error message Live Mail
Windows Mail Error Sending a Message - Non-specific Error Message Vista mail
Poor OS means poor sales, says Acer boss Vista General
Vista: poor error handling, confusing UI - Tell me I'm wrong Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46