Share access security "hole"?


luca2

Recommended Posts

Hi,

in a VM (windows10) that I only granted read/write privileges to access only one share I accidentally find out this.

The share created acts as a data hdd for this VM only.

It works as it should, but if for example I do a screenshot and then try to save it, at the beginning the share is not shown, but I can do a "create an access to a network share". At this moment I can access any share!!!!

 

What should I check to avoid this?

 

Rgds

Link to comment

Hi, sorry for late replay, but I wanted to confirm Unraid works as it should.

 

I recreated the scenario and could not log in. I guess I have added the share while installing the vm, and at this moment I must have used my admin password. Accidentally I let windows save it. Although I desconnected the share later, when the other user tried to connect the share later I guess my password was still there.

 

I forgot to ask if there is a way to hide the complete published shares that are visible when you try to add a network share? Although you cannot access them you can see them.

 

Rgds

Link to comment
3 minutes ago, luca2 said:

Hi, sorry for late replay, but I wanted to confirm Unraid works as it should.

 

I recreated the scenario and could not log in. I guess I have added the share while installing the vm, and at this moment I must have used my admin password. Accidentally I let windows save it. Although I desconnected the share later, when the other user tried to connect the share later I guess my password was still there.

 

I forgot to ask if there is a way to hide the complete published shares that are visible when you try to add a network share? Although you cannot access them you can see them.

 

Rgds

If you do not want shares be visible then set the Export setting to ‘Yes (hidden)’ which means you can still access it if you know the name, but it is not listed.

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.