09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8 Security Utilities 277<br />

You can hide one or more entries by right-clicking an entry and choosing Exclude. The<br />

selected entry and any others that begin with the same text will be hidden from the display.<br />

For example, if you exclude C:\Folder, then C:\Folder\Subfolder will also be hidden.<br />

Click the Save button to save the list contents to a tab-delimited Unicode text file. Choose<br />

Compare To Saved from the File menu to display the differences in permissions between the<br />

current list against a previously saved file. You can use this feature to verify the configuration<br />

of one system against that of a baseline system.<br />

ShareEnum<br />

An aspect of <strong>Windows</strong> network security that is often overlooked is file shares. Lax security<br />

settings are an ongoing source of security issues because too many users are granted<br />

unnecessary access to files on other computers. If you didn’t specify permissions when<br />

creating a file share in <strong>Windows</strong>, the default used to be to grant Everyone Full Control. That<br />

was later changed to grant Everyone just Read access, but even that might expose sensitive<br />

information to more people than those who should be authorized.<br />

<strong>Windows</strong> provides no utilities to list all the shares on a network and their security settings.<br />

ShareEnum fills that void, giving you the ability to enumerate all the file and printer shares in<br />

a domain, an IP address range, or your entire network to quickly view the share permissions<br />

in a table view, and to change the permissions on those shares.<br />

Because only a domain administrator has the ability to view all network resources,<br />

ShareEnum is most effective when you run it from a domain administrator account.<br />

ShareEnum is a GUI utility and doesn’t accept any command line parameters (other than<br />

/ accepteula). From the drop-down list, select , which scans your entire<br />

network, , which lets you select a range of addresses to scan, or the name<br />

of a domain. Click Refresh to scan the selected portion of your network. If you selected<br />

, you will be prompted to enter a range of IP addresses to scan.<br />

ShareEnum displays share information in a list view, as shown in Figure 8-3.<br />

FIGURE 8-3 ShareEnum.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!