Project 7-4

Top: Shows that the administrator have activate DAC for common users.

Discretionary Access Control to share file can be dangerous. Discretionary Access Control model is also known as the least restrictive way of implementing. user has total control over any object that he or she owns, along with the other program that are associated with those files.

Discretionary Access Control is often targeted by attackers, due to high-level privileges for end-user. In this practical i am going to use my Window 2008 to give permission to an end-user.

Discretionary Access Control has two significant weakness:
  1. It gives freedom to the user and may poses security risks as it relies on the end-user subject to set the proper level of security.
  2. User permission will be "inherited" by any program that the user executes.

How to create Discretionary Access Control in Window Vista/2003/2008:
  1. Create a new file
  2. Go to the file properties, then security tab
  3. Deny "read" for the administrator
  4. Go to file sharing, and choose the user who is allowed to enter it
  5. DAC permission have been granted to another user

P1062344 posted during Saturday, July 17, 2010 at 10:20 PM

About Me

Name: Maverick Yong Kim Wee
Chinese Name: 杨 金 辉
Admin No: P1062344
Class: DISM 1A/01

No.of readers

Comments