WQuinn QuotaAdvisor Can be Bypassed Using NTFS Streams
QuotaAdvisor 4.1 can be bypassed easily by using NTFS streams as the software does not check NTFS streams when enforcing quota settings.
September 27, 2000
Reported September 28, 2000 by Delphis Consulting VERSIONS AFFECTED DESCRIPTIONIt is possible for a local user to bypass disk quota controls put in place by WQuinn QuotaAdvisor 4.1. DEMONSTRATION By utilizing NTFS streams, a local user can easily bypass quota controls put in place by QuotaAdvisor 4.1. The software, QuotaAdvisor, does not check NTFS streams when enforcing quota rules. VENDOR RESPONSE The vendor is aware of this issue but does not have any immediate plans to address it. A suggested work around for this issue is to frequently check data shares for the existence of NTFS streams or switch to another disk quota software package that takes NTFS streams into account. CREDITDiscovered by Delphis Consulting |
About the Author
You May Also Like