Inappropriate user with Backup Files and Directories privilege |
---|
Risk Level: | High | Check or Attack Name: Backup Privilege |
---|---|---|
Platforms: | Windows NT | |
Description: | A user has been detected with the Back up Files and Directories privilege. This right is normally only granted to Administrators and Backup Operators, and can be used to read any file or registry key, regardless of permissions. If the user also has Restore Files and Directories privileges, the ownership of files and other objects can be changed. |
|
Remedy: | Check user rights for Back up files and Directories. Remove any names disallowed by your security policy. To audit and revoke this privilege, follow these steps:
|
|
References: | Microsoft Knowledge Base Article Q104221, Windows NT Backup and Security, http://support.microsoft.com/support/kb/articles/q104/2/21.asp |
Know Your Risks |