Auditing Attempted Shared Folder Access

Auditing Attempted Shared Folder Access

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Auditing Attempted Shared Folder Access keith c 03-05-2007
Posted by =?Utf-8?B?a2VpdGggYw==?= on March 5, 2007, 10:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have Success/Failure turned on in the following Local Security Settings:
Audit Acct logon events
Audit Acct Management
Audit Directory Service Access
Audit Logon Events
Audit Policy Change

I have a shared folder on the server that has the following permissions set
on it:
Security (local NTFS): Everyone Full Control
Sharing permissons: TestUser1 - Read Only

I have auditing set for "Everyone" of Type: Failure on the folder.

When TestUser2 (who doesnt have access to the folder) double clicks on
the share, the "Access is Denied" message box is displayed. But I have no
'failure' entry in the Security Event Log on the server.

What am I doing wrong? Am I missing something?
What do I need to do to get the failed attempt captured in the
security event log?

Any help would be appreciated.

Thanks
K C
Security Analyst III
Self Regional Healthcare
Greenwood, SC USA

Posted by Roger Abell [MVP] on March 5, 2007, 10:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
NTFS auditing is controlled by enabling audit of Object Access
in the security policy, which you did not list as enabled.


>I have Success/Failure turned on in the following Local Security Settings:
> Audit Acct logon events
> Audit Acct Management
> Audit Directory Service Access
> Audit Logon Events
> Audit Policy Change
>
> I have a shared folder on the server that has the following permissions
> set
> on it:
> Security (local NTFS): Everyone Full Control
> Sharing permissons: TestUser1 - Read Only
>
> I have auditing set for "Everyone" of Type: Failure on the folder.
>
> When TestUser2 (who doesnt have access to the folder) double clicks on
> the share, the "Access is Denied" message box is displayed. But I have no
> 'failure' entry in the Security Event Log on the server.
>
> What am I doing wrong? Am I missing something?
> What do I need to do to get the failed attempt captured in the
> security event log?
>
> Any help would be appreciated.
>
> Thanks
> K C
> Security Analyst III
> Self Regional Healthcare
> Greenwood, SC USA



Posted by =?Utf-8?B?a2VpdGggYw==?= on March 5, 2007, 11:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the reply Roger.
Audit Object Access auditing is enabled (success&failure); I neglected
to list it in my email (good catch!)

"Roger Abell [MVP]" wrote:

> NTFS auditing is controlled by enabling audit of Object Access
> in the security policy, which you did not list as enabled.
>
>
> >I have Success/Failure turned on in the following Local Security Settings:
> > Audit Acct logon events
> > Audit Acct Management
> > Audit Directory Service Access
> > Audit Logon Events
> > Audit Policy Change
> >
> > I have a shared folder on the server that has the following permissions
> > set
> > on it:
> > Security (local NTFS): Everyone Full Control
> > Sharing permissons: TestUser1 - Read Only
> >
> > I have auditing set for "Everyone" of Type: Failure on the folder.
> >
> > When TestUser2 (who doesnt have access to the folder) double clicks on
> > the share, the "Access is Denied" message box is displayed. But I have no
> > 'failure' entry in the Security Event Log on the server.
> >
> > What am I doing wrong? Am I missing something?
> > What do I need to do to get the failed attempt captured in the
> > security event log?
> >
> > Any help would be appreciated.
> >
> > Thanks
> > K C
> > Security Analyst III
> > Self Regional Healthcare
> > Greenwood, SC USA
>
>
>

Posted by on March 5, 2007, 12:38 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If I recall correctly, you can audit a folder but not the share. Now,
your permissions are blocking the request from getting to the folder.
Try changing the ACL (access control list) to:

CIFS: Authenticated Users: Read, Change
NTFS: TestUser1: Read

This should give you the same result (only TestUser1 can read from the
shared folder) and the desired result (failed access being logged.)

> I have a shared folder on the server that has the following permissions set
> on it:
> Security (local NTFS): Everyone Full Control
> Sharing permissons: TestUser1 - Read Only



Posted by on March 5, 2007, 3:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I just tried these permissions on my test server. While I still
suggest using these ACLs for manageability purposes, they do not fix
the auditing issue. I am looking into it and will post back.

> If I recall correctly, you can audit a folder but not the share. Now,
> your permissions are blocking the request from getting to the folder.
> Try changing the ACL (access control list) to:
>
> CIFS: Authenticated Users: Read, Change
> NTFS: TestUser1: Read
>
> This should give you the same result (only TestUser1 can read from the
> shared folder) and the desired result (failed access being logged.)
>
>
>> I have a shared folder on the server that has the following permissions set
>> on it:
>> Security (local NTFS): Everyone Full Control
>> Sharing permissons: TestUser1 - Read Only


Similar ThreadsPosted
Auditing shared folder April 7, 2008, 1:02 pm
Auditing access to shared folders? December 1, 2005, 10:32 pm
Unable to access officews shared folder with remote access VPN July 5, 2005, 4:39 am
Logging attempted access over a networked connection February 15, 2006, 12:35 pm
Shared Folder Forensics November 14, 2005, 8:39 am
Shared Folder Permission April 21, 2007, 6:36 am
Problem with Shared folder December 29, 2007, 3:41 pm
Shared folder security settings June 24, 2005, 9:08 am
Auditing Whom delete an file or folder. June 15, 2005, 3:06 am
Grant permission to a shared folder in XP or W2000 February 16, 2006, 6:21 am

The site map in XML format XML site map

Contact Us | Privacy Policy