3 ms·
In Windows, if a process has Backup privilege it can bypass any permissions, and it is not audited by default due to it would create too much audit volume by ac
by Hilift 1y ago
In Windows, if a process has Backup privilege it can bypass any permissions, and it is not audited by default due to it would create too much audit volume by actual backup applications. Any process that has this privilege can use it, but the privilege is disabled by default, so it would require deliberate enablement. It is fairly easy to enable in managed code like C#. Same goes for Restore privilege.
- 9dev 1y agoNo need to go that far if any random app can read your entire user directory and everyone just accepts elevation prompts without reading them.
- fc417fc802 1y ago... and? In an audited environment you'd carefully vet how the backups work. That functionality is inside the security boundary so to speak. I don't believe it's integrated with (any bypass of) auditing but the same "ignore permissions" capability exists on Linux as CAP_DAC_READ_SEARCH and is primarily useful for the same sort of tasks.