Security Basics mailing list archives

RE: Prevent use of Open Share


From: "Kalra, Mohit (Corporate, Consultant)" <mohit.kalra () ge com>
Date: Wed, 24 Aug 2005 21:54:31 -0400


If u add some group_names or user_names in "Create permanent shared objects" policy in User rights assignment under 
domain level policy settings...then only that particular user or group members will able to make shares.....

I have not tried this on my domain....but it might work....pls let me know the output.....

With best regards
Mohit Kalra
Security Support Engineer

-----Original Message-----
From: Alex Harasic Gil [mailto:alharasic () mi cl]
Sent: Thursday, August 25, 2005 12:26 AM
To: security-basics () securityfocus com
Subject: Prevent use of Open Share


Hi, the company I'm working for has over 8,000 PCs 
connected to the corporate LAN. We need to find a way to 
prevent users from creating Open Shares with full-access 
permissions on the Windows 2000 network.

Basic users, don't know how to apply control access to the 
shares they're sharing. So, there's also an education 
process we need to carry on.

But for a first instance, how can I do to lock the use of 
public open shares on the windows 2000 Domain? Domain 
Policy, GPO?, is there any way to detect the use of them 
other than scanning for open shares?.

Regards

Alex S. Harasic
alharasic () mi cl


Current thread: