<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bypassing file system security in Windows with no hooking or patching</title>
	<atom:link href="http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/</link>
	<description>Thoughts about software and Windows internals</description>
	<lastBuildDate>Mon, 16 Aug 2010 10:11:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ron</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-1649</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Sun, 21 Feb 2010 15:27:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-1649</guid>
		<description>NTFS &quot;security&quot; is a joke anyway. I have just began testing NTFS security on Server 2008 and have found that if you give a non-admin modify rights to a folder, then remove their modify rights. Then have an admin create a file in that folder the non-admin can delete the file even though you can look at the permission levels and they clearly show that user should not be able to.</description>
		<content:encoded><![CDATA[<p>NTFS &#8220;security&#8221; is a joke anyway. I have just began testing NTFS security on Server 2008 and have found that if you give a non-admin modify rights to a folder, then remove their modify rights. Then have an admin create a file in that folder the non-admin can delete the file even though you can look at the permission levels and they clearly show that user should not be able to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daryll</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-954</link>
		<dc:creator>Daryll</dc:creator>
		<pubDate>Wed, 30 Sep 2009 12:14:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-954</guid>
		<description>Would it be okay if I just copy and paste the .sys file into windows system path without executing the .inf file? Let&#039;s say in a Network.</description>
		<content:encoded><![CDATA[<p>Would it be okay if I just copy and paste the .sys file into windows system path without executing the .inf file? Let&#8217;s say in a Network.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-953</link>
		<dc:creator>Bogdan</dc:creator>
		<pubDate>Wed, 30 Sep 2009 08:37:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-953</guid>
		<description>Yes, it should work the same way although FAT32 doesn&#039;t implement any kind of file security (as NTFS does).</description>
		<content:encoded><![CDATA[<p>Yes, it should work the same way although FAT32 doesn&#8217;t implement any kind of file security (as NTFS does).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daryll</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-951</link>
		<dc:creator>Daryll</dc:creator>
		<pubDate>Wed, 30 Sep 2009 00:29:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-951</guid>
		<description>I see, by the way does this tool work with fat32 file system?</description>
		<content:encoded><![CDATA[<p>I see, by the way does this tool work with fat32 file system?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-947</link>
		<dc:creator>Bogdan</dc:creator>
		<pubDate>Tue, 29 Sep 2009 06:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-947</guid>
		<description>Hi Daryll,

The tool doesn&#039;t currently work on 64bit systems as the driver is not signed. You can however disable Driver SIgnature Enforcement by pressing F8 at boot time and it should work.

Moreover, this is only a proof of concept so it is not intended for commercial/production environments.

One of the limitations would be the fact that it facilitates opening any file but not creating files anywhere (e.g: you can not create a file in a read-only folder).</description>
		<content:encoded><![CDATA[<p>Hi Daryll,</p>
<p>The tool doesn&#8217;t currently work on 64bit systems as the driver is not signed. You can however disable Driver SIgnature Enforcement by pressing F8 at boot time and it should work.</p>
<p>Moreover, this is only a proof of concept so it is not intended for commercial/production environments.</p>
<p>One of the limitations would be the fact that it facilitates opening any file but not creating files anywhere (e.g: you can not create a file in a read-only folder).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daryll</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-943</link>
		<dc:creator>Daryll</dc:creator>
		<pubDate>Tue, 29 Sep 2009 00:25:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-943</guid>
		<description>What are the limitation(s) of this tool?</description>
		<content:encoded><![CDATA[<p>What are the limitation(s) of this tool?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twindows Internals : Cum sa scapi de securitatea din NTFS</title>
		<link>http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/comment-page-1/#comment-2</link>
		<dc:creator>Twindows Internals : Cum sa scapi de securitatea din NTFS</dc:creator>
		<pubDate>Wed, 14 Jan 2009 09:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.hobeanu.com/blog/?p=21#comment-2</guid>
		<description>[...] detalii tehnice, puteti accesa post-ul in limba engleza ce contine un video si un document PDF:http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/ Aceasta metoda nu este considerata o gaura de securitate deoarece necesita incarcarea unui driver. [...]</description>
		<content:encoded><![CDATA[<p>[...] detalii tehnice, puteti accesa post-ul in limba engleza ce contine un video si un document PDF:http://www.hobeanu.com/blog/bypassing-file-system-security-in-windows/ Aceasta metoda nu este considerata o gaura de securitate deoarece necesita incarcarea unui driver. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
