It is possible for a local user to bypass disk quota controls put in place by WQuinn QuotaAdvisor 4.1. DEMONSTRATION By utilizing NTFS streams, a local user can easily bypass quota controls put in place by QuotaAdvisor 4.1. The software, QuotaAdvisor, does not check NTFS streams when enforcing quota rules. VENDOR RESPONSE The vendor is aware of this issue but does not have any immediate plans to address it. A suggested work around for this issue is to frequently check data shares for the existence of NTFS streams or switch to another disk quota software package that takes NTFS streams into account. CREDIT |
0 comments
Hide comments