ARGH!

Nov. 1st, 2004 11:57 am
sobrique: (Default)
[personal profile] sobrique
So today, I have a helpdesk call. Logged by a helpdesk person who I shall refer to as CB, on behalf of a user who I shall refer to as CW.

The [department] directories have all been taken over by "20004" owner, they should all be owned by [userid] including legacy data as I am the only user of this data. Please change all ownership to me.

This user couldn't login to the Unix systems this morning. Neither could anyone else in his (small) department. As you may imagine, this was a cause for some concern.

The problem was found, and quickly sorted - ownership of all their department has mysteriously changed to UID "20004". Being unable to access their own home directories, login scripts etc. the system basically just dumped them back out again. Technically it didn't entirely, but it was stuffed enough that the windows enviroment they used didn't work.

And so I have been through the entire departmental share 'fixing' permissions. root where it should be, specific user where it should be, etc.

And then I got as far as looking up who UID 20004 actually was. It was CB. The guy who logged the call. It was the Unix to NT mapping for his 'NT domain admin' account.

In a brief surge of fury, I cast my eyes around for a suitable LART. Thankfully for his life expectancy, and my career, I didn't find one. But I did just pop up to the helpdesk to 'query' it.

I was greeted with "Oh, I didn't think I could change ownerships.".

Clearly what has happened, is that this directory, which is also shared as a CIFS share for convenience, has had the 'Take Ownership' button clicked on it. Why, I don't know - I can't think of a good reason for it, although I can think of a few less good reasons.

The issue gets a little uglier though - this department is technically a 'restricted' area. In the security clearance sense. Protectively marked stuff is on a stand alone fileserver, but indications of nosiness on the part of admin staff with no Need to Know is really not a good thing.

Now I'm a firm believer that people behaving like fuckwits with admin rights, really shouldn't have them any more. This, I think I shall be raising with various boss level type people.

Oh, and if anyone feels like giving their credit card a work out, please buy me this. I promise I'll use it for it's intended purpose. The best LART Evaaah

Date: 2004-11-01 05:15 am (UTC)
From: [identity profile] jambon-gris.livejournal.com
I take it you informed your boss about the specifics, as this looks like a moment for arse covering in a big way.

Date: 2004-11-03 12:34 am (UTC)
From: [identity profile] crashbarrier.livejournal.com
Damn you.. now i want a plane tooo.....:((((

Profile

sobrique: (Default)
sobrique

December 2015

S M T W T F S
  12345
6789101112
13141516171819
20212223242526
2728 293031  

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Feb. 19th, 2026 07:06 pm
Powered by Dreamwidth Studios