Profile permissions ...

Esh, Andrew AEsh at tricord.com
Wed Oct 30 15:13:04 GMT 2002


Yes, this is right. I see 0x000f003f all the time when processing ACL lists.
It's the "all" mask.

-----Original Message-----
From: Simo Sorce [mailto:simo.sorce at xsec.it]
Sent: Wednesday, October 30, 2002 2:41 AM
To: Samba Technical
Subject: Re: Profile permissions ...


On Wed, 2002-10-30 at 07:45, Richard Sharpe wrote:
> Hi,
> 
> In looking at NTUSER.DAT, it seems that the permissions associated with 
> some of the SIDs are:
> 
>   0x000f003f
> 
> Hmmm, here is one of the entries:
> 
>    0x0014 003f 000f 0101 0000 0000 0005 0012 0000
> 
> Which seems to be:
> 
>   ACCESS Denied, No Propogate Inherit, All Access, S-1-5-4608
> 
> Does this seem reasonable?

not at all

from include/rpc_secdesc.h that I lately updated:

#define SEC_RIGHTS_FULL_CONTROL         0x000f003f

so it is full control!

Richard, remember special rights means different things depending on
which object they are applyed on, see rpc_secdesc.h for more information
on this bits for various object types.

Simo.

-- 
Simo Sorce - simo.sorce at xsec.it
Xsec s.r.l.
via Durando 10 Ed. G - 20158 - Milano
tel. +39 02 2399 7130 - fax: +39 02 700 442 399
-------------- next part --------------
HTML attachment scrubbed and removed


More information about the samba-technical mailing list