When you enable developer mode in Windows 10 you also disable security. When everybody can make symlinks it becomes possible to make symlink on alternative data stream on c:\programdata This will redirect the path used for Windows Defender files that gets executed as system
-
Show this thread
-
bonus gotcha- junction folders cannot be created over smb.... you could think that of course the same restrictrion applies to symlinks- but no. When you enable passwordless sharing users\public gets writeable by everyone and Guest account enables.
1 reply 1 retweet 10 likesShow this thread -
Replying to @jonasLyk
Well, you can create mount points over SMB you just need to be an administrator. They get resolved on the server so if a user could do it you could access any directory you like. https://www.tiraniddo.dev/2018/12/abusing-mount-points-over-smb-protocol.html …
1 reply 0 retweets 3 likes -
Replying to @tiraniddo
allright- i may have jumped to conclusion regarding that. But yarh- I assume that is why users\all users is a ntfs symbolic directory :)
1 reply 0 retweets 0 likes -
Replying to @jonasLyk
It's very possible that is the reason. Of course aren't remote -> local SMB symbolic links disabled by default? Not that it matters to your original point that developer mode enables symbolic link creation even over SMB :-)
1 reply 0 retweets 0 likes
they are- but you can set on public folder remote, then you can redirect where next operations on user account pictures by priv service will end up
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.