General discussion
May 10, 2001 at 09:46 AM
dgemcse

Ghost users and SAM/ACL corruption…

by dgemcse . Updated 25 years, 1 month ago

Here’s a juicy one…
IIS4 on NT4 SP6a..
After deleting users, AND restarting IIS, FTP, and security services, I can still log in as the missing users.
Anyone ever hear of this one?
Possibly a similar or congruent issue….
Am setting up a directory for FTP that enables users to log in directly to their dir’s, (neat idea, if you need it) you can check out MS’s own instructions at
http://support.microsoft.com/support/kb/articles/Q201/7/71.ASP
Followed by the letter, however some users can still VIEW the directory AFTER they have successfully logged in. The dir’s are still secure, however some users can see them and some can’t. Either way, they can only WRITE to their own dir’s.
Could the SAM or ACL’s be corrupted in some way? How would you “fix” them? And before you say just recreate the users, I pulled my hair out doing it several times, all with the same results…..always viewable.
Today I created over 100 seperate dir’s and users to match, all the SAME way, and some have this problem, and some don’t. All permissions are correct and same for given scenario/dir. About the only thing I think I can say, is that SOME of these users MAY have been on the SAM/ACL before.

How can you check to see if SAM/ACL is corrupt, orflush it of any old data?

This discussion is locked

All Comments