21716878-Hacker-s-Desk-Reference

Page 161

Now, true, remote registry editing is not allowed in NT4, but this rule does not apply to Administrator (or perhaps other users in the Administrators group.. ::grin::).

Ok, so far we've covered some pretty good information, but lets go into that new product that microsoft loves so much. The product they really hyped.. NTFS (NewTechnologiesFileSystem). First of all, NTFS is a rip off of the OS/2 file system, HPFS. No biggie, lets not get picky. Anyhow, NTFS is actually a beautiful thing, if used properly. NTFS allows administrator to not only put access permissions on folders, but it also allows for access permissions on individual files within that folder.

Example: Jane and Ralph both have access to the folder 'Shoes'. Theres only one file within the 'shoes' folder. Only jane has access to this one file, Ralph does not. So when Ralph opens the 'shoe' folder, it appears empty, but when Jane opens the 'shoe' folder, the file is there.

Now, If an administrator does not set permissions on files within a folder but you know the exact path to the file, you can copy the file out of the folder onto a FAT (File Allocation Table) system, successfully bypassing the security. Example:

The folder 'Shoes' has permissions on it. You do not have access permission to the folder, BUT if you typed:

copy c:\shoes\secure.txt a:\

It would allow you to copy the file. Pretty neat huh?

I have heard that the latest NT4 patches have corrected this problem, I will let ya know when I get a chance to test it out.


Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.