Exetools  

Go Back   Exetools > General > Community Tools

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #6  
Old 02-20-2020, 19:34
DavidXanatos DavidXanatos is offline
Family
 
Join Date: Jun 2018
Posts: 183
Rept. Given: 3
Rept. Rcvd 47 Times in 33 Posts
Thanks Given: 59
Thanks Rcvd at 363 Times in 120 Posts
DavidXanatos Reputation: 47
This workaround driver only allows to access files and folders on local partitions with disregard of ACL's.
So it won't allow the user to access remote resources he is not permitted to access.

The driver does not mess with ACL's it just makes them ineffective. So nothing to be restored and it should not break anything eider.

Adding some sort of white-list to not fully compromise the security is a good idea, although I would probably try to go for checking if a process having admin privileges instead of a static list.

IMHO when we start i.e. cmd.exe "as administrator" we deserve to be able to access anything everywhere, so this would be a reasonable approach.


For me the main motivation behind this driver is that even as SYSTEM/TrustedInstaller I couldn't modify files under C:\Program Files\WindowsApps, the most strange thing was that even after taking ownership and removing all ACL entries except my user having all permission I still couldn't modify those files.

Even when the partition in question was not the running windows but one that was offline. Trying to access it from windows 10 was enough to make it inaccessible.
Doing the same with a windows 7 as host allowed me full access.

Duno what MSFT exactly set on this directories but actually it seams pretty clear that its something different than ACL's
Even taking ownership under windows 7 removing all ACL entries, adding new once to grant full access to the administrators and everyone group, does not allow me to access this files when using a windows 10 host.

Anyone have any idea what they may have did here?
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Driver Signing on x64 Windows _MAX_ x64 OS 7 10-22-2012 15:47
WDF (Windows Driver Foundation) vodu General Discussion 2 06-29-2005 06:06
Help - Windows Device Driver Programming psychedelic_fur General Discussion 7 06-29-2004 22:27
Windows 2000 Device Driver Book + Inside Windows 2000 at FTP dynio General Discussion 16 09-19-2003 23:21


All times are GMT +8. The time now is 19:54.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )