Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Cannot access local shares via the Network window

Closed Thread
 
Thread Tools Display Modes
Old 06-11-2007   #1 (permalink)
David Dickinson
Guest


 

Cannot access local shares via the Network window

Hello,

I am logged in as a sub-administrator (not as the "super" administrator)
into Vista Biz. I've created a folder, "Test" and shared it only with the
Administrators group (of which my login account is a member -- it is NOT a
member of the Users group). (I've turned off the Sharing Wizard and set up
the shares via the Advanced Sharing button).

I can access the folder in by it's path in Explorer, i.e., D:\Test. I have
full NTFS permissions as a member of the Administrators group.

If I open another Explorer window on this computer and navigate to this
computer under the Network item in the folder tree and try to access the
folder via it's share, I receive a "Permission Denied" error.

However, if I go to another machine on this peer-to-peer network and log in
with the same credentials, I can access the share as I expect.

I am confused by this. Is this a bug or another "feature".

--
David Dickinson
eveningstar at die-spammer-die dash mvps dot org
Please reply only to the newsgroup, not by email.

Old 06-11-2007   #2 (permalink)
Jimmy Brush
Guest


 

Re: Cannot access local shares via the Network window

David Dickinson wrote:
> Hello,
>
> I am logged in as a sub-administrator (not as the "super" administrator)
> into Vista Biz. I've created a folder, "Test" and shared it only with
> the Administrators group (of which my login account is a member -- it is
> NOT a member of the Users group). (I've turned off the Sharing Wizard
> and set up the shares via the Advanced Sharing button).
>
> I can access the folder in by it's path in Explorer, i.e., D:\Test. I
> have full NTFS permissions as a member of the Administrators group.
>
> If I open another Explorer window on this computer and navigate to this
> computer under the Network item in the folder tree and try to access the
> folder via it's share, I receive a "Permission Denied" error.
>
> However, if I go to another machine on this peer-to-peer network and log
> in with the same credentials, I can access the share as I expect.
>
> I am confused by this. Is this a bug or another "feature".
>
> --
> David Dickinson
> eveningstar at die-spammer-die dash mvps dot org
> Please reply only to the newsgroup, not by email.
>


That's strange.

Do non-admins have read access to the folder?

--
-JB
Microsoft MVP - Windows Shell/User
Windows Vista Support FAQ - http://www.jimmah.com/vista/
Old 06-11-2007   #3 (permalink)
David Dickinson
Guest


 

Re: Cannot access local shares via the Network window

"Jimmy Brush" <jb@mvps.org> wrote in message
news:%23vOQEGBrHHA.500@TK2MSFTNGP02.phx.gbl...
> That's strange.
>
> Do non-admins have read access to the folder?


Hi, Jimmy,

No. I removed the Everyone group from the share permissions because I want
ONLY the Administrators group to be able to access the folder over the
network. However, the NTFS permissions are the "standard" inherited ones
from the root of the drive, i.e., Authenticated Users, Administrators,
SYSTEM, and Users all have their usual NTFS permissions.

--
David Dickinson
eveningstar at die-spammer-die dash mvps dot org
Please reply only to the newsgroup, not by email.

Old 06-13-2007   #4 (permalink)
Jimmy Brush
Guest


 

Re: Cannot access local shares via the Network window

David Dickinson wrote:
> "Jimmy Brush" <jb@mvps.org> wrote in message
> news:%23vOQEGBrHHA.500@TK2MSFTNGP02.phx.gbl...
>> That's strange.
>>
>> Do non-admins have read access to the folder?

>
> Hi, Jimmy,
>
> No. I removed the Everyone group from the share permissions because I
> want ONLY the Administrators group to be able to access the folder over
> the network. However, the NTFS permissions are the "standard" inherited
> ones from the root of the drive, i.e., Authenticated Users,
> Administrators, SYSTEM, and Users all have their usual NTFS permissions.
>
> --
> David Dickinson
> eveningstar at die-spammer-die dash mvps dot org
> Please reply only to the newsgroup, not by email.
>


I have verified this behavior.

This seems to be some sort of security protection feature, most likely
to prevent unelevated programs from bypassing UAC restrictions by
accessing administrative shares/named pipes meant for remote
administration from the local machine.

I am not aware of how Windows is accomplishing this or any way to
disable this, but if I find out anything else I will let you know.

I can say that if you access the share from an elevated app, then the
restrictions disappear.

Unfortunately, you cannot easily (or safely) elevate an explorer window.

--
-JB
Microsoft MVP - Windows Shell/User
Windows Vista Support FAQ - http://www.jimmah.com/vista/
Old 06-13-2007   #5 (permalink)
David Dickinson
Guest


 

Re: Cannot access local shares via the Network window

"Jimmy Brush" <jb@mvps.org> wrote:
> This seems to be some sort of security protection feature, most likely to
> prevent unelevated programs from bypassing UAC restrictions by accessing
> administrative shares/named pipes meant for remote administration from the
> local machine.


Yeah. It's not a big deal (I just got used to being lazy in every older
version of Windows), and may even be a good idea.

> I can say that if you access the share from an elevated app, then the
> restrictions disappear.


Hmm... sort of defeats the purpose, if it is a security protection feature.

David

Old 06-13-2007   #6 (permalink)
Jimmy Brush
Guest


 

Re: Cannot access local shares via the Network window

David Dickinson wrote:
>> I can say that if you access the share from an elevated app, then the
>> restrictions disappear.

>
> Hmm... sort of defeats the purpose, if it is a security protection feature.
>


Well, if the app is already elevated, it can already do anything it
wants, so there's no point in blocking access at that point.


--
-JB
Microsoft MVP - Windows Shell/User
Windows Vista Support FAQ - http://www.jimmah.com/vista/
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
access to network shares denied Andreas Münster Vista account administration 0 05-15-2008 02:33 AM
Can't access LOCAL (LAN) shares when VPN established Oscar Fowler Vista networking & sharing 1 04-09-2007 07:19 PM
Vista VPN causes local network shares to disconnect t_jahns@yahoo.com Vista networking & sharing 1 03-14-2007 03:54 PM
Vista VPN causes local network shares to disconnect t_jahns@yahoo.com Vista networking & sharing 4 03-08-2007 11:43 PM
No access to WAN network shares over VPN Robert Fischer Vista networking & sharing 1 01-01-2007 02:29 PM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50