Bypass Traverse Checking not working

Bypass Traverse Checking not working

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Bypass Traverse Checking not working Roden 09-19-2005
Posted by =?Utf-8?B?Um9kZW4=?= on September 19, 2005, 12:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am having trouble getting Bypass Traverse checking working on my Windows
2003 EE server in a Windows 2003 domain.

I have set Bypass Traverse Checking to Authenticated Users via Group Policy.
However I have a service account that can not delete a file in the C:\Temp
folder. The service account has Modify permissions to the C:\Temp folder and
no permissions to C:\

Theoretically it should traverse C:\ and be able to find C:\Temp

If I give the Service account the NTFS permission of "Travers Folder \
Execute File" the service account can then delete the file in the C:\Temp
folder.

I do not understand this as Bypass Travers Checking should give the same
results.

The following TechNet article states "Traverse folder takes effect only when
the group or user is not granted the Bypass traverse checking user right in
the Group Policy snap-in".
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/e4be109f-5547-4df8-90f0-4d885dc302e7.mspx

Any idea on why Bypass Travers Checking does to appear to be applied?


Posted by =?Utf-8?B?SVdTRUM=?= on September 20, 2005, 2:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
Have you tried checkoing your Local and Domain security policies as well
to see if there are any other settings conflicting with the group policy -
we've had loads of problems in getting all the various policies to work as we
expect them to.


Cheers
IWSEC
www.iwsec.co.uk
"Roden" wrote:

> I am having trouble getting Bypass Traverse checking working on my Windows
> 2003 EE server in a Windows 2003 domain.
>
> I have set Bypass Traverse Checking to Authenticated Users via Group Policy.
> However I have a service account that can not delete a file in the C:\Temp
> folder. The service account has Modify permissions to the C:\Temp folder and
> no permissions to C:\
>
> Theoretically it should traverse C:\ and be able to find C:\Temp
>
> If I give the Service account the NTFS permission of "Travers Folder \
> Execute File" the service account can then delete the file in the C:\Temp
> folder.
>
> I do not understand this as Bypass Travers Checking should give the same
> results.
>
> The following TechNet article states "Traverse folder takes effect only when
> the group or user is not granted the Bypass traverse checking user right in
> the Group Policy snap-in".
>
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/e4be109f-5547-4df8-90f0-4d885dc302e7.mspx
>
> Any idea on why Bypass Travers Checking does to appear to be applied?
>

Similar ThreadsPosted
Help me Please!!!!!!! Bypass traverse checking May 12, 2006, 10:32 am
website password bypass June 5, 2007, 9:28 am
Bypass W2K3 SP2 WMF Security June 6, 2007, 4:43 pm
traverse folder permission August 9, 2006, 9:44 am
Traverse Folder Permissions January 7, 2007, 11:55 am
CRL Checking.... February 13, 2007, 12:25 pm
MSBA - Password Complexity Checking July 7, 2005, 11:15 am
Checking Folder Ownership and Permissions in VBScript November 11, 2005, 2:50 pm
Checking ACL's on 60000 Folders - Advice needed February 14, 2006, 4:48 pm
OS Batch/CL Checking a Volume for Suspicious email addresses January 11, 2007, 11:52 am

The site map in XML format XML site map

Contact Us | Privacy Policy