»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 09-18-2003, 03:23 AM   #1 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
Program to monitor accessed files/paths

I need to troubleshoot a security problem. There's a program (nokia pc suite if you need to know ), that works fine when the user has administrative rights, but with normal user rights a portition of the program (namely datalayer.exe) crashes. I need a program that monitors what resources datalayer.exe tries to access to set up proper permissions.

It needs to be freeware, as it's for this onetime use only.
-M

muno is offline   Reply With Quote
Old 09-19-2003, 06:58 AM   #2 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
How come I always need to bumb my posts to get even one reply???
muno is offline   Reply With Quote
Old 09-20-2003, 04:16 AM   #4 (permalink)
Registered User
 
cadetstimp's Avatar
 
Join Date: Oct 2001
Location: Oceanside CA
Posts: 1,591
cadetstimp is on a distinguished road
If it is Win2k/XP pro..... right click the group of folder(s) and file(s) you wish to monitor and then select properties.

Go into the security tab and then click the Advanced button.

Click on the auditing tab and then click add

select everyone and then click ok

When prompted check the boxes for the successfull and failed actions you want to monitor and then click ok

Click ok...Click ok.


Now that you've turned on auditing for those folders and files that you've selected... any actions that you selected to audit will appear in the security log in the event viewer. To look at the log right click My Computer and then select Manage. Expand the Event Viewer and then look at the security log.

Running the program should produce the failure entries you're looking for....then you'll know which files need full access.


NOTE: Remeber which folders and files you're auditing! When you're done go back in and remove everyone from the auditing list. Too much auditing left on can slow down a system...

FUNNY TRICK: Just for fun I used to place a shared file on my system and then go to our companies workgroup space. Under the temp section that everyone uses, I would create a folder called EpisodeITrailer or something else non work related and then I would place a shortcut in the folder to the shared file on my pc. Then all I had to do was watch my security log to see who was going into the folder on a regular basis (just listing the shortcut created an entry telling me what host name and user logon just opened the folder). Interseting way to see who's browsing around and slacking off and how often! (made for some funny copnversations!..."hey, how did you know I was browsing in there!")

Last edited by cadetstimp; 09-20-2003 at 04:24 AM.
cadetstimp is offline   Reply With Quote
Old 09-20-2003, 07:23 AM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
I'll second the tools pgriffet mentions. I use them frequently.
DVNT1 is offline   Reply With Quote
Old 09-22-2003, 02:21 AM   #6 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
Thank you all.
With w2ks native auditing I was able to see what files were accessed without rights, and ntregmon showed me what registry key it was failing to write to.
(HKLM\Software\Nokia\Datalayer)

Boy, the ntregmon util listed like 100 events every millisecond Had some job to find the correct failure. (there were like cazillion of notfounds and bufferoverflows)

It works flawlessly now.
-M
muno is offline   Reply With Quote
Old 09-22-2003, 02:50 AM   #7 (permalink)
Registered User
 
Dj-Icer's Avatar
 
Join Date: May 2003
Location: Neo Japan
Posts: 1,175
Dj-Icer is on a distinguished road
Needed that weblink! Thanks too!
__________________
|c3R
Dj-Icer is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 12:57 AM.