Share via

C$, IPC$, and ADMIN$ Network Share Access (Windows Server 2008 R2 Standard)

Anonymous
2022-10-31T13:26:56+00:00

I'm trying to impliment some registry changes to allow elevated access to the $C, IPC$, and ADMIN$ shares for Nessus scanning purposes. I've implimented the following changes:

-HKLM\software\Microsoft\Windows\CurrentVersion\Policies\System\

  • EnableAccountTokenFilterPolicy 1
  • LocalAccountTokenFilterPolicy 1

-Winreg permissions

  • HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg
  • Create a allow read all permission set for the winreg folder

-HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters

  • AutoShareServer 1
  • AutoShareWks 1

I tested the changes in a lab environement and was able to good credentialed scan with the desired administrative privilieges. However, I do have some concerns before making the changes in the live environment, as the lab environment does not have end users attached to test if the changes will affect their access/normal use.

  1. Do I need to disconnect the old drives that are inaccessible to the admin credentials or should I run the NetShareDel funtion on those shares?
  2. Will disconnecting/deleting those shares have an impact to authenticated users active on the net?
  3. Do I have to log out/restart the domain controller for those changes to take effect, or is there any other (less disruptive) method to have those shares regenerated with the desired access?
  4. When the shares are regenerated after deletion/disconnection, will they still contain the same contents of the drive previously, just with adjusted permissions?

Any information would be greatly appreciated!

-Jon

Windows for home | Previous Windows versions | Files, folders, and storage

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Anonymous
    2022-10-31T19:37:19+00:00

    Your question is beyond the scope of these Forums

    This Community is mainly for home users and their computer problems, not business systems.

    The following forum(s) have migrated to Microsoft Q&A: All English Windows Server forums!
    Visit Microsoft Q&A to post new questions.

    https://docs.microsoft.com/en-us/answers/products/windows

    Windows Server General

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2022-10-31T19:36:56+00:00

    Your question is beyond the scope of these Forums

    This Community is mainly for home users and their computer problems, not business systems.

    The following forum(s) have migrated to Microsoft Q&A: All English Windows Server forums!
    Visit Microsoft Q&A to post new questions.

    https://docs.microsoft.com/en-us/answers/products/windows

    Windows Server General

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2022-10-31T14:05:39+00:00

    Good day JCompton12! I am glad to be able to provide assistance to you today. I would suggest to post this query to our neighbor forum from the link below. They are more oriented on with regards to this type queries/issues and there will be IT Pros/System Admins/Server Admins/AD Admins who are available that will be able to fulfill your query as we are more of home/personal consumer based forum.

    https://learn.microsoft.com/en-us/answers/produ...

    Regards,

    Paul R.

    Was this answer helpful?

    0 comments No comments