»

Saturday, November 13, 2010

AD Group: Domain Users

The permissions on the files and folders on Win 2003 Server were all farked up. Normal Domain Users group (on AD) were able to access everything on the shared resources !

WTH! What was wrong?!

So starts the end-of-the-day investigation based solely on adrenaline after long long day at work:

1. Permissions on users and default accounts (ie. Administrator, SYSTEM, Domain User) were checked folder-by-folder and nothing looks amiss.

2. Advanced permissions were tweaked assuming that too much rights have been given. Still no change. Everything are still accessible!

3. Time checked: 9pm Day: Friday. Reality sets in ... WTF am I still doing here so late! Heck, Cinta Fitri have to be skipped :)

4. AD check: Started with the most common user/group ie. Domain User group. BINGO ! Domain Users were member of Administrators group !! WTH !!!

Case in question closed ... time check 9.30pm :)