Security Basics mailing list archives

Re: enumerating folder permissions


From: Ned Fleming <ned () kaw us>
Date: Fri, 07 Jul 2006 16:06:23 -0500

On Thu, 06 Jul 2006 12:25:43 -0400, Raoul Armfield <armfield () amnh org>
wrote:

Jamie Wareham wrote:
I'm not sure if I'm following you correctly, but it seems like you could
simply select "view permissions" (under advanced permissions options)
for the folder permissions.  They can see, but not change.


True but the problem there is that you only see the groups that have 
access to the folder.  They will have no easy way of knowing who the 
members of the groups are.

Has one on this list ever had a request to make something like this 
available to users?

For SarbOx we're having to report this type of information. Thus far,
one of my minions has hand-cranked some reports.

The AccessEnum proggie sure looks interesting. We're going to give it
a whirl.

twapi.sourceforge.net might be of help. E.g., list group members is as
simple as this:

  http://twapi.sourceforge.net/listusersingroup.example

twapi has scores of useful code examples:

  http://twapi.sourceforge.net/examples.html



---------------------------------------------------------------------------
This list is sponsored by: SensePost

Hacking, like any art, will take years of dedicated study and
practice to master. We can't teach you to hack. But we can teach you
what we've learned so far. Our courses are honest, real, technical
and practical. SensePost willl be at Black Hat Vegas in July. To see
what we're about, visit us at:

http://www.sensepost.com/training.html
---------------------------------------------------------------------------


Current thread: