ãµãŒããŒäžã®ãããã¯ãŒã¯ããã³ããŒã«ã«ãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ã«ã€ããŠèª¬æããŸãã
ãµãŒããŒäžã®å ±æãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã¯ã誰ããç¥ã£ãŠããããã«ããã§ã«3.0ã®SMBãããã³ã«ã«ãã£ãŠå®è¡ãããŸãã ãã©ã«ããžã®ãããã¯ãŒã¯ã¢ã¯ã»ã¹ã¯ãSMBããã³NTFSã¢ã¯ã»ã¹èš±å¯ã«ãã£ãŠå¶éã§ããŸãã SMBã¢ã¯ã»ã¹èš±å¯ã¯ããããã¯ãŒã¯çµç±ã§å ±æãã©ã«ããŒã«ã¢ã¯ã»ã¹ããå Žåã«ã®ã¿æ©èœããç¹å®ã®ãã©ã«ããŒã®å¯çšæ§ã«ããŒã«ã«ã§ã¯åœ±é¿ããŸããã NTFSã¢ã¯ã»ã¹èš±å¯ã¯ããããã¯ãŒã¯äžãšããŒã«ã«ã®äž¡æ¹ã§æ©èœããã¢ã¯ã»ã¹èš±å¯ãäœæããéã®æè»æ§ãå€§å¹ ã«åäžããŸãã SMBãšNTFSã®ã¢ã¯ã»ã¹èš±å¯ã¯åå¥ã«æ©èœããã®ã§ã¯ãªããæ倧ã®æš©å©å¶éã®ååã«åŸã£ãŠäºãã«è£å®ããŸãã
SMBå ±æã³ãã³ãã¬ããã°ã«ãŒãã§Server 2012ã®ãã©ã«ããŒãå ±æããããã«ãNew-SMBShareã³ãã³ãã¬ããã衚瀺ãããŸããã ãã®ã³ãã³ãã¬ãããäŸãšããŠäœ¿çšãããšãã¯ã©ã¹ã¿ãŒæ§æãé€ããå ±æãã©ã«ããŒã®äœææã«äœ¿çšå¯èœãªãã¹ãŠã®æ©èœã衚瀺ãããŸãïŒããã¯å¥ã®å€§ããªãããã¯ã§ãïŒã
æ°ããå ±æãã©ã«ããŒã®äœæã¯éåžžã«ç°¡åã§ãã
net share homefolder=s:\ivanivanov /grant:"admin",full /grant:"folderowner",change /grant:"manager",read /cache:programs /remark:"Ivanov"
ãŸãã¯
new-smbshare homefolder s:\ivanivanov âcachingmode programs âfullaccess admin âchangeaccess folderowner âreadaccess manager ânoaccess all âfolderenumerationmode accessbased -description "Ivanov"
ç§ãã¡ã¯ç解ããŠããŸãïŒ
ãããã¯ãŒã¯äžã®å ±æãã©ã«ããŒã®ååã¯ãããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒäžã®ãã©ã«ããŒã®ååãšç°ãªãå ŽåããããŸãã 80æåã®å¶éããããååã®ãã€ããšã¡ãŒã«ã¹ãããã¯äœ¿çšã§ããŸããã-name
å ±æããããŒã«ã«ãã©ã«ããŒãžã®ãã¹ã ãã¹ã¯ããã£ã¹ã¯ã®ã«ãŒãããå®å šã§ãªããã°ãªããŸããã-path
å ±æãã©ã«ããŒå ã®ãã¡ã€ã«ã®èªåŸæ§ãèšå®ããŸãã-cachingmode
ã¹ã¿ã³ãã¢ãã³ãã¡ã€ã«ãšã¯äœã§ããïŒ
ãªãã©ã€ã³ãã¡ã€ã«ã¯ããµãŒããŒäžã«ãããã¡ã€ã«ã®ã³ããŒã§ãã ãã®ã³ããŒã¯ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒã«ããããµãŒããŒã«æ¥ç¶ããã«ãã¡ã€ã«ãæäœã§ããŸãã æ¥ç¶ãããšãå€æŽãåæãããŸãã ãããã¯åæ¹åã«åæãããŸãããªãã©ã€ã³ãã¡ã€ã«ã«å€æŽãå ããå Žåã次åæ¥ç¶ãããšããµãŒããŒäžã®ãã¡ã€ã«ãå€æŽãããŸãã ãµãŒããŒã§èª°ããå€æŽãå ããå ŽåãããŒã«ã«ã³ããŒãå€æŽãããŸãã äž¡æ¹ã®ãã¡ã€ã«ã§äžåºŠã«å€æŽãè¡ãããå Žåãåæãšã©ãŒãçºçãããããä¿åããããŒãžã§ã³ãéžæããå¿
èŠããããŸãã ã³ã©ãã¬ãŒã·ã§ã³ã®ããã«ãç§ã¯ãã®æ©äŒãå©çšããŸããããåãŠãŒã¶ãŒã«å¯ŸããŠããŒã«ãäœæããæžã蟌ã¿ã®å¯èœæ§ãªãã«ä»ã®ãŠãŒã¶ãŒãèªãããã®ã¢ã¯ã»ã¹ãå¶éããå Žåã次ã®ãã³ãååŸããŸãïŒ
- äœæ¥ã¯ãããã¯ãŒã¯ã«äŸåããŸãã-ã¹ã€ãããçŒæãããããµãŒããŒãåèµ·åããããã¯ã€ã€ãç Žæããããã¢ã¯ã»ã¹ãã€ã³ãããªãã«ãªã£ããããå¯èœæ§ããããŸã-ãŠãŒã¶ãŒã¯èªåã®ã³ããŒãæäœããŸã
- ãŠãŒã¶ãŒã¯ã©ãã§ãä»äºãããããšãã§ããŸãïŒåœããã¹ãé£è¡æ©-äœããã®çç±ã§VPNãžã®æ¥ç¶ãå©çšã§ããªãå Žæã
- ãŠãŒã¶ãŒãVPNãä»ããŠäœæ¥ããŠããã«ãããããããæ¥ç¶ãéåžžã«é ããã絶ããåæãããŠããå ŽåããµãŒããŒäžã§äœããããããšããããããªãã©ã€ã³ã³ããŒã䜿çšããŠå€æŽãåæããæ¹ãç°¡åã§ãã
- ãŠãŒã¶ãŒã«ãã®ãããªæ©äŒãäžããã°ããŠãŒã¶ãŒèªèº«ãäœããã€åæããããéžæã§ããŸãã
以äžã®å€ãåããŸãã
- none-ãã¡ã€ã«ã¯ãªãã©ã€ã³ã§ã¯äœ¿çšã§ããŸãã;ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ã«ã¯ãµãŒããŒãžã®ã¢ã¯ã»ã¹ãå¿ èŠã§ã
- ããã¥ã¢ã«-ãŠãŒã¶ãŒèªèº«ããªãã©ã€ã³ã§å©çšã§ãããã¡ã€ã«ãéžæããŸã
- ããã°ã©ã -ãã©ã«ããŒå ã®ãã¹ãŠããªãã©ã€ã³ã§äœ¿çšå¯èœïŒããã¥ã¡ã³ãããã³ããã°ã©ã ïŒæ¡åŒµåã* .exeã* .dllã®ãã¡ã€ã«ïŒïŒ
- ããã¥ã¡ã³ã-ããã¥ã¡ã³ãã¯å©çšå¯èœãããã°ã©ã ã¯ãããŸãã
- branchcache-ãŠãŒã¶ãŒã®ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒã®ä»£ããã«BranchCacheãµãŒããŒã§ãã£ãã·ã¥ãçºçããŸãããŠãŒã¶ãŒã¯èªåã§ãªãã©ã€ã³ãã¡ã€ã«ãéžæããŸã
å ±æèš±å¯-noaccess, -readaccess, -changeaccess, -fullaccess
ãããã®èš±å¯ã«ã¯1ã€ã®å€§ããªå©ç¹ããããŸã-éåžžã«åçŽã§ãã
-noaccessç§æžãã¹ãã¥ã¯ãŒã-ç§æžãšé ä¿¡ãããŒãžã£ãŒã¯ããããªãã¯ã¢ã«ãŠã³ãã£ã³ã°ãã©ã«ããŒã§ã¯äœã®é¢ä¿ããããŸãã
-readaccess audit-ã¢ã«ãŠã³ãã£ã³ã°ã®äœæ¥ããã§ãã¯ããç£æ»è ã¯ãå ±æãã©ã«ããŒå ã®ãã¡ã€ã«ãšãµããã©ã«ããŒã®ååã確èªããããèªã¿åãçšã«ãã¡ã€ã«ãéããããããã°ã©ã ãå®è¡ãããã§ããŸãã
-changeaccess accountant-å ±æãã©ã«ããŒã®äŒèšå£«ã¯ããã¡ã€ã«ãšãµããã©ã«ããŒã®äœæãæ¢åã®ãã¡ã€ã«ã®å€æŽããã¡ã€ã«ãšãµããã©ã«ããŒã®åé€ãã§ããŸã
-fullaccess admin-fullaccessã¯ãreadaccess + changeaccessãšããŒããã·ã§ã³ãå€æŽããæ©èœã§ãã
å ±æãã©ã«ããŒãäœæãããšãæãå¶éã®å³ããã«ãŒã«ãèªåçã«é©çšãããŸã-Everyoneã°ã«ãŒãã«ã¯èªã¿åãæš©éãäžããããŸãã
ãããã®ã¢ã¯ã»ã¹èš±å¯ã¯ããããã¯ãŒã¯çµç±ã§å ±æãã©ã«ããŒã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã«ã®ã¿é©çšãããŸãã ããšãã°ãã¿ãŒããã«ãµãŒããŒã®å ŽåãããŒã«ã«ã«ãã°ã€ã³ãããšãç§æžãšãããŒãžã£ãŒã®äž¡æ¹ãçµçéšéã§å¿ èŠãªãã¹ãŠãèŠãããšãã§ããŸãã ããã¯NTFSã¢ã¯ã»ã¹èš±å¯ã«ãã£ãŠä¿®æ£ãããŸãã SMBã¢ã¯ã»ã¹èš±å¯ã¯ãå ±æãªãœãŒã¹äžã®ãã¹ãŠã®ãã¡ã€ã«ãšãã©ã«ããŒã«é©çšãããŸãã ã¢ã¯ã»ã¹æš©ã®ãã詳现ãªèª¿æŽã¯ãNTFSã¢ã¯ã»ã¹èš±å¯ã«ãã£ãŠãå®è¡ãããŸãã
ãã®ãã©ã¡ãŒã¿ãŒã䜿çšãããšãå ±æãã©ã«ããŒãžã®æ¥ç¶ã®æ倧æ°ãå¶éã§ããŸãã ååãšããŠããã©ã«ããžã®ã¢ã¯ã»ã¹ãå¶éããNTFSã¢ã¯ã»ã¹èš±å¯ãè£å®ããããã«äœ¿çšããããšãã§ããŸããå¿ èŠãªæ¥ç¶æ°ã確èªããå¿ èŠãããã ãã§ãã-concurrentuserlimit
ãããã¯ãŒã¯ç°å¢ã§è¡šç€ºãããå ±æãªãœãŒã¹ã®èª¬æã 説æã¯å€ãã®äººãç¡èŠããéåžžã«è¯ãããšã§ãã-description
æå·å-encryptdata
ããŒãžã§ã³3.0ããåã®SMBã§ã¯ããã¡ã€ã«ãµãŒããŒããã¯ã©ã€ã¢ã³ããžã®ãã©ãã£ãã¯ãä¿è·ããå¯äžã®æ¹æ³ã¯VPNã§ããã å®è£ æ¹æ³ã¯ãã·ã¹ãã 管çè ã®èšå®ïŒSSLãPPTPãIPSECãã³ãã«ãªã©ïŒã«å®å šã«äŸåããŠããŸããã Server 2012ã§ã¯ãæå·åã¯ç¹å¥ãªã€ã³ãã©ã¹ãã©ã¯ãã£ãœãªã¥ãŒã·ã§ã³ãå¿ èŠãšããã«ãéåžžã®ããŒã«ã«ãããã¯ãŒã¯ãŸãã¯ä¿¡é Œã§ããªããããã¯ãŒã¯ãä»ããŠãç®±ããåºããŠæ©èœããŸãã ãµãŒããŒå šäœãšåã ã®ãããªãã¯ãã©ã«ãã®äž¡æ¹ã§æå¹ã«ã§ããŸãã SMB 3.0ã®æå·åã¢ã«ãŽãªãºã ã¯AES-CCMã§ãHMAC-SHA256ã®ä»£ããã®ããã·ã¥ã¢ã«ãŽãªãºã ã¯AES-CMACã§ãã è¯ããã¥ãŒã¹ã¯ãSMB 3.0ãããŒããŠã§ã¢AESïŒ AES-NI ïŒããµããŒãããŠããããšã§ããæªããã¥ãŒã¹ã¯ããã·ã¢ãAES-NIããµããŒãããŠããªãããšã§ãã
æå·åã®å°å ¥ãè ãããã®ã¯äœã§ããïŒ SMB 3.0ãã€ãŸãWindows 8ããµããŒãããã¯ã©ã€ã¢ã³ãã®ã¿ãæå·åãããå ±æãã©ã«ããŒãæäœã§ãããšããäºå®ã«ããããã®çç±ã¯ããŠãŒã¶ãŒæš©å©ã®æ倧蚱容å¶éã§ãã 管çè ã¯ãèªåãäœãããŠããããç¥ã£ãŠãããå¿ èŠã«å¿ããŠãç°ãªãããŒãžã§ã³ã®SMBãæã€ã¯ã©ã€ã¢ã³ãã«ã¢ã¯ã»ã¹ã§ãããšæ³å®ãããŠããŸãã ãã ããSMB 3.0ã§ã¯æ°ããæå·åããã³ããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšããããããSMBã®ç°ãªãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã¯æå·åãããªããããVPNãå¿ èŠã§ãã ãã®ã³ãã³ãã¯ããã¹ãŠã®ã¯ã©ã€ã¢ã³ããæå·åãæå¹ã«ããŠãã¡ã€ã«ãµãŒããŒã«å ¥ãã®ã«åœ¹ç«ã¡ãŸãã
set-smbserverconfiguration ârejectunencryptedaccess $false
æ¢å®ã®æ§æïŒæå·åããããããªãã¯ãã©ã«ããŒãžã®æå·åãããŠããªããã©ãã£ãã¯ã¯çŠæ¢ãããŠããŸãïŒã§ã¯ãã¯ã©ã€ã¢ã³ãã§3.0ããäžã®SMBããŒãžã§ã³ã§ã¯ã©ã€ã¢ã³ããã©ã«ããŒã«ã¢ã¯ã»ã¹ããããšãããšããã¢ã¯ã»ã¹ãšã©ãŒããçºçããŸãã ã€ãã³ã1003ã¯ããµãŒããŒäžã®Microsoft-Windows-SmbServer /æäœãã°ã«è¿œå ãããã¢ã¯ã»ã¹ããããšããŠããã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ãèŠã€ããããšãã§ããŸãã
SMBãšEFSã®æå·åã¯ãäºãã«é¢ä¿ã®ãªã2ã€ã®ç°ãªããã®ã§ããã€ãŸããFATããã³ReFSããªã¥ãŒã ã§äœ¿çšã§ããŸãã
ããã¯ã¢ã¯ã»ã¹ããŒã¹ã®åæã§ãã ã¢ã¯ã»ã¹ããŒã¹ã®åæãæå¹ã«ãããšãå ±æãã©ã«ããŒã«ã¢ã¯ã»ã¹ã§ããªããŠãŒã¶ãŒã¯ãã¡ã€ã«ãµãŒããŒã«è¡šç€ºãããªãããããã®ãã©ã«ããŒãŸãã¯ãã®ãã©ã«ããŒã«ã¢ã¯ã»ã¹ã§ããªãçç±ãå°ãªããªããŸãã ãŠãŒã¶ãŒã¯èªåã®ã¢ã¯ã»ã¹å¯èœãªãã©ã«ããŒãèŠãŠãä»ã®äººã®äºæã«å ¥ãããšã¯ããŸããã ããã©ã«ãã¯ãªãã§ãã-folderenumerationmode
- ã¢ã¯ã»ã¹ããŒã¹-æå¹
- ç¡å¶é-ãªãã«ãã
ãã®ããŒã¯ããµãŒããŒã®åèµ·ååŸã«ã¢ã¯ã»ã¹ãçµäºããäžæå ±æãã©ã«ããŒãäœæããŸãã æ°žç¶çãªå ±æãã©ã«ããŒã¯ããã©ã«ãã§äœæãããŸãã-temporary
NTFSã¢ã¯ã»ã¹èš±å¯
NTFSã¢ã¯ã»ã¹èš±å¯ã䜿çšãããšããã©ã«ãå ã®æš©éããã詳现ã«åºå¥ã§ããŸãã ç¹å®ã®ã°ã«ãŒããç¹å®ã®ãã¡ã€ã«ãå€æŽããã®ãé²ããåºæ¬çãªãã¹ãŠãç·šéã§ããããã«ããŸãã åããã©ã«ãå ã§ã1ã€ã®ãŠãŒã¶ãŒã°ã«ãŒãã1ã€ã®ãã¡ã€ã«ãå€æŽããæš©å©ãæã¡ãå¥ã®ãŠãŒã¶ãŒã°ã«ãŒããç·šéããä»ã®ãã¡ã€ã«ã衚瀺ããããšã¯ã§ããŸããã ã€ãŸããNTFSã¢ã¯ã»ã¹èš±å¯ã䜿çšãããšãéåžžã«æè»ãªã¢ã¯ã»ã¹ã·ã¹ãã ãäœæã§ããŸããäž»ãªããšã¯ãåŸã§æ··ä¹±ããªãããšã§ãã ããã«ãNTFSã¢ã¯ã»ã¹èš±å¯ã¯ããããã¯ãŒã¯çµç±ã§ãã©ã«ããŒã«ã¢ã¯ã»ã¹ãããšããå ±æã¢ã¯ã»ã¹èš±å¯ãè£è¶³ãããšããããã³ãã¡ã€ã«ãšãã©ã«ããŒã«ããŒã«ã«ã«ã¢ã¯ã»ã¹ãããšãã®äž¡æ¹ã§æ©èœããŸãã
6ã€ã®åºæ¬çãªæš©éãããã14ã®é«åºŠãªæš©éã®çµã¿åããã§ãã
åºæ¬çãªèš±å¯
ãã«ã¢ã¯ã»ã¹ïŒãã«ã³ã³ãããŒã«ïŒ -ãã©ã«ããŒãŸãã¯ãã¡ã€ã«ãžã®ãã«ã¢ã¯ã»ã¹ããã©ã«ããŒãšãã¡ã€ã«ã®ã¢ã¯ã»ã¹æš©ãšç£æ»ã«ãŒã«ãå€æŽã§ããŸãã
å€æŽ -ãã©ã«ããŒã®å 容ã®èªã¿åããå€æŽã衚瀺ããã©ã«ããŒ/ãã¡ã€ã«ã®åé€ãããã³å®è¡å¯èœãã¡ã€ã«ã®å®è¡ãè¡ãæš©å©ã èªã¿åããšå®è¡ïŒèªã¿åããšå®è¡ïŒãæžã蟌ã¿ïŒæžã蟌ã¿ïŒãåé€ïŒåé€ïŒãå«ãŸããŸãã
èªã¿åããšå®è¡ïŒreadandexecuteïŒ -æžã蟌ã¿ã®å¯èœæ§ãªãã«ãèªã¿åãã®ããã«ãã©ã«ããŒãšãã¡ã€ã«ãéãæš©å©ã å®è¡å¯èœãã¡ã€ã«ãå®è¡ããããšãã§ããŸãã
ãã©ã«ããŒã®å 容ã®äžèŠ§è¡šç€ºïŒãã£ã¬ã¯ããªã®äžèŠ§è¡šç€ºïŒ -ãã©ã«ããŒã®å 容ã衚瀺ããæš©å©
èªã¿åã -æžã蟌ã¿ã®å¯èœæ§ãªãã«ãèªã¿åãã®ããã«ãã©ã«ããŒãšãã¡ã€ã«ãéãæš©å©ã ãã©ã«ããŒã®å 容/ããŒã¿ã®èªã¿åãïŒreaddataïŒãå±æ§ã®èªã¿åãïŒreadattributesïŒãè¿œå ã®å±æ§ã®èªã¿åãïŒreadextendedattributesïŒãèªã¿åãèš±å¯ïŒreadpermissionsïŒãå«ãŸããŸã
æžã蟌ã¿ïŒæžã蟌ã¿ïŒ -ãã©ã«ããŒãšãã¡ã€ã«ãäœæãããã¡ã€ã«ãå€æŽããæš©å©ã ãã¡ã€ã«äœæ/ããŒã¿æžã蟌ã¿ïŒwritedataïŒããã©ã«ããŒäœæ/ããŒã¿èšé²ïŒappenddataïŒãå±æ§ã®æžã蟌ã¿ïŒwriteattributesïŒãè¿œå å±æ§ã®æžã蟌ã¿ïŒwriteextendedattributesïŒãå«ãŸããŸãã
è¿œå ã®èš±å¯
ãã©ã«ããŒã«14ã®ã¢ã¯ã»ã¹èš±å¯ã®ãã¡1ã€ã ããèšå®ããäœãèµ·ãããã調ã¹ãŸããã çŸå®ã®äžçã§ã¯ãã»ãšãã©ã®å Žåãåºæ¬çãªã¢ã¯ã»ã¹èš±å¯ã§ååã§ãããæãå¶éãããæš©éãæã€ãã©ã«ããŒãšãã¡ã€ã«ã®åäœã«èå³ããããŸããã
ãã©ã«ããŒãã©ããŒã¹/ãã¡ã€ã«å®è¡ïŒãã©ããŒã¹ïŒ -ãã©ã«ããŒã®ã¢ã¯ã»ã¹èš±å¯ã«é¢ä¿ãªãããã¡ã€ã«ãå®è¡ããã³èªã¿åãæš©å©ã ãŠãŒã¶ãŒã¯ãã©ã«ããŒã«ã¢ã¯ã»ã¹ã§ããŸããïŒãã©ã«ããŒå ã®å 容ã¯è¬ã®ãŸãŸã§ãïŒãããã©ã«ããŒå ã®ãã¡ã€ã«ã«ã¯çŽæ¥ãªã³ã¯ïŒå®å šãçžå¯ŸããŸãã¯UNCãã¹ïŒãä»ããŠã¢ã¯ã»ã¹ã§ããŸãã Traverseãã©ã«ããŒã«ãã©ã«ããŒãé 眮ãããŠãŒã¶ãŒãäœæ¥ããããã«å¿ èŠãªãã®ä»ã®ã¢ã¯ã»ã¹èš±å¯ããã¡ã€ã«ã«é 眮ã§ããŸãã ãŠãŒã¶ãŒã¯ããã©ã«ããŒå ã®ãã¡ã€ã«ãäœæããã³åé€ã§ããŸããã
ãã©ã«ããŒã®å 容/ããŒã¿ã®èªã¿åãïŒreaddataïŒ -å€æŽã®å¯èœæ§ãªãã«ãã©ã«ããŒã®å 容ã衚瀺ããæš©å©ã 衚瀺ããŠãããã©ã«ãå ã®ãã¡ã€ã«ãå®è¡ããŠéãããšã¯ã§ããŸãã
èªã¿åãå±æ§ïŒreadattributesïŒ -ãã©ã«ããŒãŸãã¯ãã¡ã€ã«ã®å±æ§ïŒ FileAttributes ïŒã衚瀺ããæš©å©ã
ãã©ã«ããŒãŸãã¯ãã¡ã€ã«ã®å 容ã衚瀺ããããå±æ§ãå€æŽãããããããšã¯ã§ããŸããã
è¿œå å±æ§ã®èªã¿åãïŒreadextendedattributesïŒ -ãã©ã«ããŒãŸãã¯ãã¡ã€ã«ã®è¿œå å±æ§ã衚瀺ããæš©å©ã
è¿œå ã®å±æ§ã§èŠã€ããããšãã§ããã®ã¯ãOS / 2ã¢ããªã±ãŒã·ã§ã³ãšã®äžäœäºææ§ãæäŸããããã«äœ¿çšãããããšã ãã§ããã ïŒ Windows InternalsãPart 2ïŒCovering Windows Server 2008 R2 and Windows 7 ïŒã ç§ã¯ãããã«ã€ããŠäœãç¥ããŸããã
ãã¡ã€ã«ã®äœæ/ããŒã¿ã®æžã蟌ã¿ïŒwritedataïŒ -ãŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ããªããã©ã«ããŒã«ãã¡ã€ã«ãäœæã§ããããã«ããŸãã ãã¡ã€ã«ããã©ã«ããŒã«ã³ããŒãããã©ã«ããŒã«æ°ãããã¡ã€ã«ãäœæã§ããŸãã ãã©ã«ããŒã®å 容ã®è¡šç€ºãæ°ãããã©ã«ããŒã®äœæããŸãã¯æ¢åã®ãã¡ã€ã«ã®å€æŽã¯ã§ããŸããã ãã®ãã¡ã€ã«ã®ææè ã§ãã£ãŠãããŠãŒã¶ãŒã¯ãã¡ã€ã«ãå€æŽã§ããŸãã-äœæã®ã¿ã
Create folder / appenddata-ãŠãŒã¶ãŒã¯ãæ¢åã®ã³ã³ãã³ããå€æŽããã«ããã©ã«ããŒã«ãµããã©ã«ããŒãäœæãããã¡ã€ã«ã®æåŸã«ããŒã¿ãè¿œå ã§ããŸãã
確èªãã
ãµããã©ã«ããŒãäœæãããšããã¹ãŠãæ確ã«ãªããŸãã
ããŒã...ããã¯CMDã§ã¯åäœããŸããã ãããããªãã
ã³ã³ãã¢äžã§ïŒ
ãããŠãããã¯ãã®ããã«æ©èœããŸããã
ãã©ãã¯ããžãã¯ã®ã»ãã·ã§ã³ãéå§ããŸããFileã¯ã©ã¹ã®AppendTextã¡ãœããã䜿çšããŸãã ãã°ãªããžã§ã¯ããååŸããŸãã
AppendAllTextã¯è©ŠããŠã¿ã䟡å€ããªããªã£ããšæã
ååãšããŠãåé¡ã¯æ確ã§ãã ãã¡ã€ã«ã«ããŒã¿ãè¿œå ããæš©éã ãã§ã¯äžèšã®æ¹æ³ã«ã¯äžååã§ããããã¡ã€ã«ã«æžã蟌ãå¿ èŠããããŸãã ãããããããšãšãã«ããšã³ããªãè¿œå ããã ãã§ãªãããã¡ã€ã«ãå€æŽããæ©äŒãäžããŸããã€ãŸãããã¡ã€ã«ã®å å®¹å šäœãç Žå£ããå¯èœæ§ãéããŸãã
æŠå¿µãä¿®æ£ããå¿ èŠããããŸãããã°ãªããžã§ã¯ããååŸããã®ã§ã¯ãªããé¢å¿ã®ãããã¹ãŠã®ãã©ã¡ãŒã¿ãŒãèšå®ããæ°ãããªããžã§ã¯ããäœæããŸãããã ã¢ã¯ã»ã¹æš©ãæ瀺çã«æå®ã§ããå Žæãå¿ èŠã§ãã FileStreamãå¿ èŠã§ããå ·äœçã«ã¯ã FileStreamã³ã³ã¹ãã©ã¯ã¿ãŒïŒStringãFileModeãFileSystemRightsãFileShareãInt32ãFileOptionsïŒã圹ç«ã¡ãŸãã 以äžã®ãã©ã¡ãŒã¿ãŒãå¿ èŠã§ãã
次ã®ããã«ãªããŸãã
ããŸãããïŒ ãã°ãªããžã§ã¯ããäœæãã ããã«äœããæžã蟌ãããšããŸãã ã FileStream.Writeã¡ãœããã¯ãå ¥åå€ããã€ãåäœã§åãå ¥ããŸãã ãã€ãã«æžã蟌ãã€ãã³ã-Encoding ã¯ã©ã¹ ã GetEncodingã¡ãœããïŒåºåã«krakozyabraã¯å¿ èŠãããŸããïŒã GetBytes ïŒå®éã«ã¯å€æïŒãè¿œãè¶ããŸã
ãã©ã¡ãŒã¿ãŒFileStream.WriteïŒ
äœãæžãã; æžã蟌ã¿ãéå§ããå Žæã æžã蟌ãŸãããã€ãæ°
ç§ãã¡ã¯æžããŸãïŒ
確èªããŸãã
ãã¹ãŠãæ£åžžã§ããããŠãŒã¶ãŒã«ã¯æžãããå 容ã衚瀺ããæš©éããããŸããã 管çè ã®äžã§ãã°ã€ã³ããŠããŸãã
ãã¹ãŠãæ©èœããŸãã
ãã¡ã€ã«ã®ãããã©ã«ããŒã«ã¯ããã©ã«ããŒã®äœæ/ããŒã¿ã®ããã¯ã¢ããã®èš±å¯ã«å ããŠããã©ã«ããŒã®å 容/ããŒã¿ã®èªã¿åãã®èš±å¯ãå¿ èŠã§ãã ãã¡ã€ã«ã«ã¯ããã©ã«ãã®äœæ/ç¶æ¿ãç¡å¹ã«ããããŒã¿ã®ããã¯ã¢ããã®ã¿ã§ååã§ãã ãŠãŒã¶ãŒãäœããæžã蟌ãå¿ èŠã®ãããã¡ã€ã«ãããŠãŒã¶ãŒãå®å šã«ä¿è·ããããšã¯ã§ããŸããïŒãŠãŒã¶ãŒã¯æ»æè ã§ããå¯èœæ§ããããŸãïŒããäžæ¹ã§ããã©ã«ããŒå ã®ãã¡ã€ã«ã®ãªã¹ããé€ãããŠãŒã¶ãŒã¯äœã衚瀺ããããå®è¡ã§ããŸããã
ãã®çµè«ã¯ç°¡åã§ããããããã¡ã€ã«ã§ã¯ãã»ãã¥ãªãã£ã§ä¿è·ããããã°ãå®è£ ããããšã¯ã§ããŸããããPowerShellã¯.NETãªããžã§ã¯ããæäœããæ©èœãç¯çŽããŸãã
æåŸ ã©ããã«åäœããŸã-ãŠãŒã¶ãŒãã©ã«ããŒtestpermsã衚瀺ããããã«ã¢ã¯ã»ã¹äžèœãªå Žæã«testappendãµããã©ã«ããŒãäœæããŸãã ãã¡ã€ã«ã®æåŸã«è¡ãè¿œå ããŠã¿ãŸããã-ããçš®ã®ãã°ã®ã¡ã³ããã³ã¹ããšãã¥ã¬ãŒãããŸããni c:\testperms\testappend âitemtype directory
newevent >> c:\testperms\user.log .
ããŒã...ããã¯CMDã§ã¯åäœããŸããã ãããããªãã
ac c:\testperms\user.log newevent ac : "C:\testperms\user.log".
ã³ã³ãã¢äžã§ïŒ
"newevent" | out-file c:\testperms\user.log -append out-file : "C:\testperms\user.log".
ãããŠãããã¯ãã®ããã«æ©èœããŸããã
ãã©ãã¯ããžãã¯ã®ã»ãã·ã§ã³ãéå§ããŸããFileã¯ã©ã¹ã®AppendTextã¡ãœããã䜿çšããŸãã ãã°ãªããžã§ã¯ããååŸããŸãã
$log = [io.file]::appendtext("c:\testperms\user.log") "AppendText" "1" : " "c:\testperms\user.log"."
AppendAllTextã¯è©ŠããŠã¿ã䟡å€ããªããªã£ããšæã
$log = [io.file]::appendalltext("c:\testperms\user.log","newevent") "AppendAllText" "2" : " "c:\testperms\user.log"."
ååãšããŠãåé¡ã¯æ確ã§ãã ãã¡ã€ã«ã«ããŒã¿ãè¿œå ããæš©éã ãã§ã¯äžèšã®æ¹æ³ã«ã¯äžååã§ããããã¡ã€ã«ã«æžã蟌ãå¿ èŠããããŸãã ãããããããšãšãã«ããšã³ããªãè¿œå ããã ãã§ãªãããã¡ã€ã«ãå€æŽããæ©äŒãäžããŸããã€ãŸãããã¡ã€ã«ã®å å®¹å šäœãç Žå£ããå¯èœæ§ãéããŸãã
æŠå¿µãä¿®æ£ããå¿ èŠããããŸãããã°ãªããžã§ã¯ããååŸããã®ã§ã¯ãªããé¢å¿ã®ãããã¹ãŠã®ãã©ã¡ãŒã¿ãŒãèšå®ããæ°ãããªããžã§ã¯ããäœæããŸãããã ã¢ã¯ã»ã¹æš©ãæ瀺çã«æå®ã§ããå Žæãå¿ èŠã§ãã FileStreamãå¿ èŠã§ããå ·äœçã«ã¯ã FileStreamã³ã³ã¹ãã©ã¯ã¿ãŒïŒStringãFileModeãFileSystemRightsãFileShareãInt32ãFileOptionsïŒã圹ç«ã¡ãŸãã 以äžã®ãã©ã¡ãŒã¿ãŒãå¿ èŠã§ãã
- ãã¡ã€ã«ãžã®ãã¹ã¯ç解ã§ãã
- ãã¡ã€ã«ãéãæ¹æ³-ãã¡ã€ã«ãéãããã¡ã€ã«ã®çµãããèŠã€ãã
- ãã¡ã€ã«èš±å¯-ããŒã¿ã®è¿œå
- ä»ã®FileStreamãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹-äžèŠ
- ãããã¡ãµã€ãº-ããã©ã«ãã®8ãã€ã
- è¿œå ãªãã·ã§ã³-ããã
次ã®ããã«ãªããŸãã
$log = new-object io.filestream("c:\testperms\user.log",[io.filemode]::append,[security.accesscontrol.filesystemrights]::appenddata,[io.fileshare]::none,8,[io.fileoptions]::none)
ããŸãããïŒ ãã°ãªããžã§ã¯ããäœæãã ããã«äœããæžã蟌ãããšããŸãã ã FileStream.Writeã¡ãœããã¯ãå ¥åå€ããã€ãåäœã§åãå ¥ããŸãã ãã€ãã«æžã蟌ãã€ãã³ã-Encoding ã¯ã©ã¹ ã GetEncodingã¡ãœããïŒåºåã«krakozyabraã¯å¿ èŠãããŸããïŒã GetBytes ïŒå®éã«ã¯å€æïŒãè¿œãè¶ããŸã
$event = " ." $eventbytes = [text.encoding]::getencoding("windows-1251").getbytes($event)
ãã©ã¡ãŒã¿ãŒFileStream.WriteïŒ
äœãæžãã; æžã蟌ã¿ãéå§ããå Žæã æžã蟌ãŸãããã€ãæ°
ç§ãã¡ã¯æžããŸãïŒ
$log.write($eventbytes,0,$eventbytes.count)
確èªããŸãã
gc c:\testperms\user.log gc : "C:\testperms\user.log ".
ãã¹ãŠãæ£åžžã§ããããŠãŒã¶ãŒã«ã¯æžãããå 容ã衚瀺ããæš©éããããŸããã 管çè ã®äžã§ãã°ã€ã³ããŠããŸãã
gc c:\testperms\user.log .
ãã¹ãŠãæ©èœããŸãã
ãã¡ã€ã«ã®ãããã©ã«ããŒã«ã¯ããã©ã«ããŒã®äœæ/ããŒã¿ã®ããã¯ã¢ããã®èš±å¯ã«å ããŠããã©ã«ããŒã®å 容/ããŒã¿ã®èªã¿åãã®èš±å¯ãå¿ èŠã§ãã ãã¡ã€ã«ã«ã¯ããã©ã«ãã®äœæ/ç¶æ¿ãç¡å¹ã«ããããŒã¿ã®ããã¯ã¢ããã®ã¿ã§ååã§ãã ãŠãŒã¶ãŒãäœããæžã蟌ãå¿ èŠã®ãããã¡ã€ã«ãããŠãŒã¶ãŒãå®å šã«ä¿è·ããããšã¯ã§ããŸããïŒãŠãŒã¶ãŒã¯æ»æè ã§ããå¯èœæ§ããããŸãïŒããäžæ¹ã§ããã©ã«ããŒå ã®ãã¡ã€ã«ã®ãªã¹ããé€ãããŠãŒã¶ãŒã¯äœã衚瀺ããããå®è¡ã§ããŸããã
ãã®çµè«ã¯ç°¡åã§ããããããã¡ã€ã«ã§ã¯ãã»ãã¥ãªãã£ã§ä¿è·ããããã°ãå®è£ ããããšã¯ã§ããŸããããPowerShellã¯.NETãªããžã§ã¯ããæäœããæ©èœãç¯çŽããŸãã
å±æ§ïŒwriteattributesïŒã®æžã蟌㿠-ãŠãŒã¶ãŒããã¡ã€ã«ãŸãã¯ãã©ã«ããŒã®å±æ§ãå€æŽã§ããããã«ããŸãã ãã¹ãŠãåçŽãªããã§ãã ãããã次ã®è³ªåã«çããã ãã§ãããç§ã®ç«ã®åçã¯ç§ã®ãããã£ãŒã«ã®ã»ãŒå šäœãå ããŠããã®ã§ãããžãã¹äžã®ãããšãã¯ã§ããŸããã ç«ã§ãã©ã«ããå§çž®ãããã®ã§ããã管çè æš©éãå¿ èŠã§ãã ããªãã¯ç§ããã©ã«ãã®å±æ§ãå€æŽããæš©å©ãæã£ãŠãããšèšã£ãã ããã¯å±æ§ã§ããïŒ ãªãå€æŽã§ããªãã®ã§ããïŒã
ã¯ããå±æ§ãæžã蟌ãæš©å©ãæã€ãŠãŒã¶ãŒã¯ãå§çž®ããã³æå·åå±æ§ãé€ãããã¡ã€ã«ããã³ãã©ã«ããŒã®ã»ãšãã©ãã¹ãŠã®è¡šç€ºå±æ§ãå€æŽã§ããŸãã æè¡çã«ã¯ããŠãŒã¶ãŒã«ã¯SetFileAttributesé¢æ°ãå®è¡ããæš©å©ãäžããããŸãã ãŸãããã¡ã€ã«å§çž®ã¯ãFSCTL_SET_COMPRESSIONãã©ã¡ãŒã¿ãŒãæž¡ãå¿ èŠãããDeviceIOControlé¢æ°ã«ãã£ãŠå®è¡ãããŸãããã¡ã€ã«å§çž®ã¯ããã®å¯äžã®ä»äºããã¯ã»ã©é ããã®ã§ãã ãã®æ©èœã䜿çšããŠãã·ã¹ãã å ã®ãã¹ãŠã®ããã€ã¹ãšãã®ãªãœãŒã¹ã管çã§ããŸããããããããŠãŒã¶ãŒã«ãã®æ©èœãå®è¡ããæš©å©ãäžããããšã¯ã管çè ã«ãªãããšãæå³ããŸãã
æå·åã®å Žåãåæ§ã§ããæå·åãæ åœããEncryptFileé¢æ°ã§ã¯ããŠãŒã¶ãŒã«ãã©ã«ãã³ã³ãã³ã/ããŒã¿ã®èªã¿åãããã¡ã€ã«ã®äœæ/ããŒã¿ã®æžã蟌ã¿ãå±æ§ã®èªã¿åããå±æ§ã®æžã蟌ã¿ããªããžã§ã¯ããžã®åæã®æš©éãå¿ èŠã§ãã ããããªãã§ã¯äœãæ©èœããŸããã
æ¡åŒµå±æ§ïŒwritextendedattributesïŒã®æžã蟌㿠ã ããããããã¯OS / 2ã¢ããªã±ãŒã·ã§ã³ãšã®äžäœäºææ§ã®ããã«äœ¿çšããããã®ã§ãã ãŸããCïŒ\ Windows \ system32 \ services.exeãã¡ã€ã«ã®é«åºŠãªå±æ§ã§ããæè¿ããã€ã®æšéŠ¬ïŒ ZeroAccess.C ïŒãæžãå§ããŸããã ãã¶ããæé«ã¬ãã«ã§ãããããªãã«ããå¿ èŠããããŸããïŒ çè«çã«ã¯ããã®è³ªåã«çããããšã¯ã§ããŸãã-å®éã«çç£ãã䟡å€ããããããããŸãã-è©Šããããšã¯ãããŸããã
ãµããã©ã«ããŒãšãã¡ã€ã«ãåé€ããŸãã ïŒdeletesubdirectoriesandfilesïŒãã©ã«ãã«ã®ã¿é©çšãããèå³æ·±ãèš±å¯ã äžçªäžã®è¡ã¯ããŠãŒã¶ãŒãåé€æš©éãäžããã«èŠªãã©ã«ããŒå ã®ãµããã©ã«ããŒãšãã¡ã€ã«ãåé€ã§ããããã«ããããšã§ãã
ãŠãŒã¶ãŒãããŒã¿ãå ¥åãã補åã«ã¿ãã°ããããšããŸãã ãµããã©ã«ããŒå ã«ã¢ã«ãã¡ãããé ã«AããZãŸã§ã®èŠªãã©ã«ããŒCatalogãããããã®äžã«ã¯ããã€ãã®ååããããŸãã ååã¯æ¯æ¥å€ãããäœããè¿œå ãããäœããå€æŽãããäœããå€ããªããå€ããªã£ãæ å ±ãåé€ããå¿ èŠããããŸãã ãã ããå ¬åãŸãã¯æªæãããããã«ã誰ããKãã£ã¬ã¯ããªå šäœãå©ãã®ã¯ããŸãè¯ããããŸãããããã¯ããŠãŒã¶ãŒãåé€æš©ãæã£ãŠããå Žåã«éåžžã«å¯èœã§ãã ãŠãŒã¶ãŒããåé€ããæš©å©ãåé€ããå Žåã管çè ã¯ç¹å®ã®ã¢ã€ãã ã®åé€èŠæ±ãçµæ¥å®è¡ãããããäœæ¥ãå®å šã«å€æŽã§ããŸãã
ããã«ã¯ããµããã©ã«ããŒãšãã¡ã€ã«ã®åé€ãå«ãŸããŸãã ã¢ã«ãã¡ãããã®ãã¹ãŠã®æåã§ãç¶æ¿ãç¡å¹ã«ãªãããŠãŒã¶ãŒã¯ãµããã©ã«ããŒãšãã¡ã€ã«ãåé€ããæš©éãè¿œå ãããŸãã ãã®çµæããŠãŒã¶ãŒã¯ã«ã¿ãã°ãã©ã«ããŒå ã®åäžã®ã¬ã¿ãŒãåé€ã§ããŸããããã¬ã¿ãŒå ã®ãã¹ãŠãåé€ã§ããŸãã
åé€ïŒåé€ïŒã ããã§ã¯ãã¹ãŠãç°¡åã§ãã åé€ã¯åé€ã§ãã èªã¿åãèš±å¯ããªããšæ©èœããŸããã
èªã¿åãã¢ã¯ã»ã¹èš±å¯ïŒreadpermissionsïŒã¯ããŠãŒã¶ãŒã«ãã©ã«ããŒãŸãã¯ãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ã衚瀺ããæš©å©ãäžããŸãã æš©éãªã-ãŠãŒã¶ãŒã«ã¯[ã»ãã¥ãªãã£]ã¿ãã§æš©éã衚瀺ãããŸãã
æš©éã®å€æŽ -ãŠãŒã¶ãŒã¯æš©éãå€æŽã§ããåºæ¬çã«ãŠãŒã¶ãŒããã©ã«ããŒã®ç®¡çè ã«ããŸãã ããšãã°ããã¯ãã«ã«ãµããŒãã«æš©éãå§ä»»ããããã«äœ¿çšã§ããŸãã èªã¿åãæš©éããªããšãæå³ããããŸããã ã¢ã¯ã»ã¹èš±å¯ãå€æŽããŠãããã©ã«ããŒã®ææè ãå€æŽãããããã§ã¯ãããŸããã
æææš©ã®å€æŽïŒæææš©ïŒ - ããããææè ã§ãã ææè ã¯ããã¡ã€ã«ãŸãã¯ãã©ã«ããŒãäœæãããŠãŒã¶ãŒã§ãã
ææè ã®ç¹æ§ã¯ãäœæãããã©ã«ããŒãžã®ãã«ã¢ã¯ã»ã¹ããããäœæãããã©ã«ããŒãžã®ã¢ã¯ã»ã¹èš±å¯ãä»äžã§ããããšã§ãããããã«éèŠãªããšã¯ãææè ãããã©ã«ããŒãŸãã¯ãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ãå€æŽããæš©å©ã奪ãããšã¯ã§ããŸããã Vasyaããã©ã«ããŒãäœæããPeteã«ãã«ã¢ã¯ã»ã¹æš©ãäžããPetyaãå ¥ã£ãŠäžè¬çãªãã©ã«ããŒãç¹ã«Vasyaãžã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãéé£ããå ŽåãVasyaã¯ãã©ã«ããŒã®ææè ã§ãããããçŸç¶ãç°¡åã«åŸ©å ã§ããŸãã Petyaã¯ãæææš©ã®å€æŽã®èš±å¯ãæã£ãŠããå Žåã§ãããã©ã«ããŒã®ææè ãå€æŽã§ããŸããã ããã«ãVasyaã§ããããã©ã«ããäœæããã«ãããããããææè ãå€æŽããããšã¯ã§ããŸããã æææš©ã®å€æŽã¯ãAdministratorsã°ã«ãŒããŸãã¯Domain Adminsã°ã«ãŒãã«ã®ã¿é©çšãããŸãã
ããããPetyaãVasinaã®ãã©ã«ããŒå ã«ãã¡ã€ã«ãäœæããVasyaããã®ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹æš©ãä»äžããªãã£ãå ŽåãVasyaã¯ãã®ãã¡ã€ã«å ã®ç§å¯ãèããŠæšæž¬ããããšããã§ããŸããã ãã¡ã€ã«ã®ææè ã¯Petyaã§ãããããVasyaã¯ãã¡ã€ã«ã®æš©éãå€æŽã§ããŸããã ãŸããVasyaã¯ãã¡ã€ã«ã®ææè ãå€æŽã§ããŸããããµãã³ã³ãããšãªããžã§ã¯ãã®ææè ãå€æŽããããšã¯ãVasyaãå±ããŠããªã管çè ã°ã«ãŒãã®ç¹æš©ã§ããããŸãã Vasyaã«æ®ãããå¯äžã®ãªãã·ã§ã³ã¯ããã©ã«ããŒå ã®Petinã®ãã¡ã€ã«ã確èªããããšã§ãã
管çããŸã
CMDã¯ãæ¢ç¥ã®icaclã䜿çšããŠèš±å¯ã管çããŸããPowerShellã§ã¯ãNTFSã¢ã¯ã»ã¹èš±å¯ã®ç®¡çã¯æ¬¡ã®ãã
ã«ãªããŸããã¢ã¯ã»ã¹èš±å¯ãèšå®ãããªããžã§ã¯ããååŸããŸã
$acl = get-acl c:\testperms
System.Security.AccessControl.FileSystemAccessRuleã¯ã©ã¹ã䜿çšããŠæš©å©æååãäœæããŸãã以äžã®ãã©ã¡ãŒã¿ãŒãèšå®ã§ããŸãã
- ã°ã«ãŒã/ãŠãŒã¶ãŒå-ACLã®å¯Ÿè±¡è
- èš±å¯-ACEïŒæçš¿ã§æå®ãããå€ãååŸããŸãïŒ
- é©çšå¯Ÿè±¡-GUIã§ã¯ãããã¯è¿œå ã®ã»ãã¥ãªãã£èšå®ã®ããããããŠã³ãªã¹ãã§ããå®éã«ã¯ã3ã€ã®å€ã®ã¿ãåããŸãïŒnoneïŒãã®ãã©ã«ããŒã®ã¿ïŒãcontainerinheritïŒãã¹ãŠã®ãµããã©ã«ããŒã«é©çšïŒãobjectinheritïŒãã¹ãŠã®ãã¡ã€ã«ã«é©çšïŒãå€ãçµã¿åãããããšãã§ããŸãã
- ãããã®ã¢ã¯ã»ã¹èš±å¯ããã®ã³ã³ãããŒå ã®ãªããžã§ã¯ããšã³ã³ãããŒã®ã¿ã«é©çšããŸãïŒGUIã®ãã§ãã¯ããã¯ã¹ïŒ-ãŸãã3ã€ã®å€ïŒnoneïŒãã§ãã¯ãªãïŒãinheritonlyïŒACEã¯éžæããã¿ã€ãã®ãªããžã§ã¯ãã«ã®ã¿é©çšãããŸãïŒãnopropagateinheritïŒãã®ã³ã³ãããŒå ã®ã¿ã«ã¢ã¯ã»ã¹èš±å¯ãé©çšããŸãïŒã
- ã«ãŒã«ã¯èš±å¯ãŸãã¯æåŠã§ã
ããã©ã«ãã®ç¹æš©è¡ã¯æ¬¡ã®ããã«ãªããŸãã
$permission = âcontoso.com\adminâ,âfullcontrolâ,âcontainerinherit,objectinheritâ,ânoneâ,âallowâ
äžèšã§å®çŸ©ããæš©éã§æ°ããACEãäœæããŸã
$ace = new-object security.accesscontrol.filesystemaccessrule $permission
ãããŠãæ°ããäœæããACEããªããžã§ã¯ãã«é©çšããŸã
$acl.setaccessrule($ace) $acl | set-acl c:\testperms
å®è·µãã
SMBããã³NTFSã®ã¢ã¯ã»ã¹èš±å¯ã«é¢ããç¥èãåããŠãããããããçµã¿åãããããšã§ããŸã£ããè€éãªã¢ã¯ã»ã¹ã«ãŒã«ãäœæã§ããŸãã ããã€ãã®äŸïŒ
çš®é¡ | SMBæš©é | NTFSã¢ã¯ã»ã¹èš±å¯ |
å šå¡ã®ãã©ã«ããŒïŒãããªãã¯ïŒ | ãŠãŒã¶ãŒ-èªã¿åã/æžã蟌㿠| ãŠãŒã¶ãŒ-å€æŽ |
ãã©ãã¯ããã¯ã¹ããŠãŒã¶ãŒã¯æ©å¯å ±åæžãææ¡ãã¹ããŒã¬ã³ãæšãŠãŸã-ããã¥ã¢ã«ã¯èªã¿ãŸãã | ãŠãŒã¶ãŒ-èªã¿åã/æžã蟌ã¿
ããã¥ã¢ã«-èªã¿åã/æžã蟌㿠| ãŠãŒã¶ãŒ-èšé²ããã®ãã©ã«ããŒã«ã®ã¿é©çšãããŸãããã®ãã©ã«ããŒã«ãã¡ã€ã«ãæžã蟌ãããšã¯çéãã±ããã§ãããšæ³å®ãããŸããããã¯ããã®ãã©ã«ããŒã«æ ŒçŽãããŠãããã¡ã€ã«ã®ãã©ã«ããŒã®å
容ã衚瀺ããæš©å©ãªãã«ç·šéãã䟿å©ãªæ¹æ³ããªãããã§ãïŒãŠãŒã¶ãŒããã®ãããªãã©ã«ããŒã«æžã蟌ã䟿å©ãªæ¹æ³ãååšããŸããïŒããŸãã衚瀺ã¯ãã©ã€ãã·ãŒã䟵害ããŸãã
ãªãŒããŒã·ãã-å€æŽã |
çšé | â | â , , .
, . , , ( SysInternals Suite) . |
â / | â . |
Windowsã§ã®æš©éã¯è°è«ã®äœå°ã®ããããšã§ããäžæ¹ã§ã¯ãåºæ¬çãªèš±å¯ã¯éåžžã«åçŽã§ãããã±ãŒã¹ã®90ïŒ ãã«ããŒããŠããŸãããããããã现ãã調æŽãå¿ èŠã«ãªãå§ãããšãç°ãªããŠãŒã¶ãŒã°ã«ãŒãã1ã€ã®ãã©ã«ããŒãå ±æãã©ã«ããŒã®ã»ãã¥ãªãã£èŠä»¶ãè¿œå ã®ã¢ã¯ã»ã¹èš±å¯ãç¶æ¿ãããã³ææè ã®åŠçã¯éåžžã«å°é£ã«ãªããŸãã
ä»ã®äººãæ··ä¹±ãããªãããšãæã¿ãŸãã
䜿çšææïŒ
MSDN
Technet