IP-TEC - Infopeople Technical Service Archive: Re: Strange security question.

Re: Strange security question.

Cary Gordon (cgordon@CERF.NET)
Sat, 18 May 1996 05:22:31 -0700

Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Thu, 16 May 1996 20:42:34 -0700
To: ip-tec@library.berkeley.edu
From: Cary Gordon <cgordon@cerf.net>
Subject: Re: Strange security question.

JoAnn;

Perhaps I am missing the point, but what do you really gain by making these
files hidden. I just make all of the key files read-only. I also either
take attrib off of the system or I rename it to something obscure. Some
files will generate errors if made read only and these files (mainly .ini
files) I automatically regenerate from backups using batch files.

The problem, as you have experienced, with hidden is that, often, these
files are hidden from programs as well.

Cary

>I'm going to have to preface this question with a long story.
>
>I was trying to make all my files hidden, like we learned in the security
>workshop. I run windows 3.1 with Direct Access as the shell to keep people
>out.
>
>Suddenly, there was some kind of error, the computer froze, and when I
>rebooted Direct Access would start up and then freeze with no menu choices
>or buttons available. I booted up from my backup floppy, and of course all
>the dos files were hidden as well. I used the attrib command to make them
>visible, found that nothing would work, and had to dump the whole windows
>directory and reload windows. Then Ifound out that I had to reload netscape
>and direct access as well, since some of their files were in the windows
>directory. This was about three hours of trial and error, since I (used to)
>know nothing about DOS.
>
>So last night I tried the hidden thing again. The same thing happened-but
>this time as I was tearing my hair out, I noticed that when I went into DOS
>and used the attrib -h /s command to make the files unhidden, I got a
>message saying that there were threefiles that the -h did not work with-
>they were IO.SYS, MSDOS.SYS, and 386SPART.PAR. After a little trial and
>error, I found that if I used the attrib command for each to take off the
>system, hidden and read only attributes, then put the system attribute back
>on, the computer worked fine. And only 15 minutes instead of 3 hours!
>
>My question is: why does making these hidden conflict with Direct Access?
>And what can I do about it? If everything on this computer is hidden except
>for these three system files, it'll be like a big flag to hackers saying
>PLEASE MODIFY THIS.
>
>JoAnn Rees

-------------------------------------------------------
Cary Gordon cgordon@cerf.net
Community Partner 72477.62@compuserve.com
Sherman Oaks Branch
Los Angeles Public Library