Possible file security issues of IBM/Lenovo Windows XP

Operating System, Common Application & ThinkPad Utilities Questions...
Post Reply
Message
Author
Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2264
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

Possible file security issues of IBM/Lenovo Windows XP

#1 Post by Puppy » Mon Jun 16, 2008 5:31 am

It seems as all of IBM/Lenovo Windows XP preloads are extracted to FAT32 partition and converted to NTFS later. I noticed there is a difference in NTFS permissions for "All Users" folder. While on clean Windows XP installation the folder is read-only for members of Users group, ThinkPads have always set full permissions for Everyone. A malicious software running under limited account (Users) can easily modify some system-wide settings like startup programs for all users, including Administrators ! There is Microsoft KB article about it:

File security issues after converting FAT32 partitions to the NTFS file system
http://support.microsoft.com/kb/810142

Unfortunately there is not any solution you can easily apply. I'd expect a BAT file or any kind of script which would automatically correct this issue. I also tried to search IBM support with no luck. Has anyone tried to correct the permissions yourself ?

I'd consider it as serious security issue today.
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8

RealBlackStuff
Admin
Admin
Posts: 17510
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

#2 Post by RealBlackStuff » Mon Jun 16, 2008 7:37 am

Have you tried Start/Run/secpol.msc to modify those settings?
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2264
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

#3 Post by Puppy » Mon Jun 16, 2008 7:51 am

Local Security Policy is something different. This is purely incorrect file system permissions (files and folders) issue. I'm currently playing with a batch file using cacls.exe to correct it.
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8

ARD
Freshman Member
Posts: 121
Joined: Mon Jan 30, 2006 4:50 am
Location: Miami, FL, USA!

#4 Post by ARD » Tue Jun 17, 2008 6:22 pm

My All Users folder has the Read & Execute, List Folder Contents, and Read allowed permissions for the Everyone Group.
This OS install was directly from the Restore CD for my T43.
Maybe this has changed for newer models?
This space for rent!
Send PM.

IBM (No Lenovo logo on LCD bezel) ThinkPad T60 2623-D6U, Core Duo 1.83 Ghz, 14.1" SXGA+, 4GB RAM, Hitachi 7k320, Windows XP Pro SP3
Lenovo ThinkPad T500 2055-2CU, Core 2 Duo 2.53 Ghz, 15.4" WSXGA+, 8GB RAM, Hitachi 7k750, Windows 7 Ultimate 64 Bit

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Windows OS (Versions prior to Windows 7)”

Who is online

Users browsing this forum: No registered users and 3 guests