mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
165 lines
8.4 KiB
165 lines
8.4 KiB
<#
|
|
Tests the SecurityDescriptor parameter sets that no other test file covers, with the module built in
|
|
NTFSSecurity\bin\Release on files in a sandbox folder. The cmdlets change a descriptor of Get-NTFSSecurityDescriptor
|
|
in memory only, and the item changes when Set-NTFSSecurityDescriptor writes the descriptor; the cmdlets that read
|
|
return what their Path parameter set returns. Tests of audit entries need the Security privilege and skip without
|
|
it.
|
|
#>
|
|
[Diagnostics.CodeAnalysis.SuppressMessageAttribute(
|
|
'PSUseDeclaredVarsMoreThanAssignments', '', Justification = 'Pester shares variables between blocks.'
|
|
)]
|
|
param ()
|
|
|
|
BeforeDiscovery {
|
|
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
|
|
$holdsSecurityPrivilege = Test-PrivilegeHeld -Name 'SeSecurityPrivilege'
|
|
}
|
|
|
|
BeforeAll {
|
|
Import-Module -Name (Join-Path -Path $PSScriptRoot -ChildPath 'TestHelpers.psm1') -Force
|
|
$modulePath = Join-Path -Path $PSScriptRoot -ChildPath '..\NTFSSecurity\bin\Release\NTFSSecurity.psd1'
|
|
Import-Module -Name $modulePath -Force -ErrorAction Stop
|
|
$sandbox = New-TestSandbox -Name 'SecurityDescriptorSets'
|
|
Push-Location -LiteralPath $sandbox
|
|
$sidType = [System.Security.Principal.SecurityIdentifier]
|
|
|
|
function Get-ExplicitAccessCount {
|
|
param ([System.Security.AccessControl.FileSystemSecurity] $Acl)
|
|
|
|
@($Acl.GetAccessRules($true, $false, $sidType)).Count
|
|
}
|
|
}
|
|
|
|
AfterAll {
|
|
Pop-Location
|
|
Remove-TestSandbox -Sandbox $sandbox
|
|
Remove-Module -Name NTFSSecurity -Force -ErrorAction SilentlyContinue
|
|
}
|
|
|
|
Describe 'Cmdlets that change a security descriptor in memory' {
|
|
It 'Clear-NTFSAccess should remove the explicit access entries of the descriptor' {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'ClearAccess'
|
|
Add-NTFSAccess -Path $file -Account 'S-1-1-0' -AccessRights ReadData
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
|
|
Clear-NTFSAccess -SecurityDescriptor $sd -ErrorAction Stop
|
|
|
|
Get-ExplicitAccessCount -Acl $sd.SecurityDescriptor | Should -Be 0
|
|
Get-ExplicitAccessCount -Acl (Get-Acl -LiteralPath $file) | Should -Be 1
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
Get-ExplicitAccessCount -Acl (Get-Acl -LiteralPath $file) | Should -Be 0
|
|
}
|
|
|
|
# Like the Path parameter set, the cmdlet doesn't copy the inherited entries, so the DACL ends up empty.
|
|
It 'Clear-NTFSAccess -DisableInheritance should leave the descriptor with an empty, protected DACL' {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'ClearAccessProtected'
|
|
Add-NTFSAccess -Path $file -Account 'S-1-1-0' -AccessRights ReadData
|
|
$daclBefore = (Get-Acl -LiteralPath $file).GetSecurityDescriptorSddlForm('Access')
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
|
|
Clear-NTFSAccess -SecurityDescriptor $sd -DisableInheritance -ErrorAction Stop
|
|
|
|
$sd.SecurityDescriptor.AreAccessRulesProtected | Should -BeTrue
|
|
@($sd.SecurityDescriptor.GetAccessRules($true, $true, $sidType)) | Should -BeNullOrEmpty
|
|
(Get-Acl -LiteralPath $file).GetSecurityDescriptorSddlForm('Access') | Should -Be $daclBefore
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
$acl = Get-Acl -LiteralPath $file
|
|
$acl.AreAccessRulesProtected | Should -BeTrue
|
|
@($acl.GetAccessRules($true, $true, $sidType)) | Should -BeNullOrEmpty
|
|
}
|
|
|
|
It 'Disable-NTFSAccessInheritance should protect the DACL of the descriptor and keep the inherited entries' {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'DisableAccess'
|
|
$inheritedCount = @((Get-Acl -LiteralPath $file).GetAccessRules($false, $true, $sidType)).Count
|
|
$inheritedCount | Should -BeGreaterThan 0
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
|
|
Disable-NTFSAccessInheritance -SecurityDescriptor $sd -ErrorAction Stop
|
|
|
|
$sd.SecurityDescriptor.AreAccessRulesProtected | Should -BeTrue
|
|
(Get-Acl -LiteralPath $file).AreAccessRulesProtected | Should -BeFalse
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
$acl = Get-Acl -LiteralPath $file
|
|
$acl.AreAccessRulesProtected | Should -BeTrue
|
|
Get-ExplicitAccessCount -Acl $acl | Should -Be $inheritedCount
|
|
}
|
|
|
|
It 'Enable-NTFSAccessInheritance should let the DACL of the descriptor inherit' {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'EnableAccess'
|
|
Disable-NTFSAccessInheritance -Path $file -RemoveInheritedAccessRules
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
|
|
Enable-NTFSAccessInheritance -SecurityDescriptor $sd -ErrorAction Stop
|
|
|
|
$sd.SecurityDescriptor.AreAccessRulesProtected | Should -BeFalse
|
|
(Get-Acl -LiteralPath $file).AreAccessRulesProtected | Should -BeTrue
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
$acl = Get-Acl -LiteralPath $file
|
|
$acl.AreAccessRulesProtected | Should -BeFalse
|
|
@($acl.GetAccessRules($false, $true, $sidType)) | Should -Not -BeNullOrEmpty
|
|
}
|
|
|
|
It 'Clear-NTFSAudit should remove the explicit audit entries of the descriptor' -Skip:(-not $holdsSecurityPrivilege) {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'ClearAudit'
|
|
Add-NTFSAudit -Path $file -Account 'S-1-1-0' -AccessRights ReadData -InheritanceFlags None -PropagationFlags None
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
|
|
Clear-NTFSAudit -SecurityDescriptor $sd -ErrorAction Stop
|
|
|
|
@($sd.SecurityDescriptor.GetAuditRules($true, $false, $sidType)) | Should -BeNullOrEmpty
|
|
@(Get-NTFSAudit -Path $file -ExcludeInherited) | Should -HaveCount 1
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
@(Get-NTFSAudit -Path $file -ExcludeInherited) | Should -BeNullOrEmpty
|
|
}
|
|
|
|
It 'Enable-NTFSAuditInheritance should let the SACL of the descriptor inherit' -Skip:(-not $holdsSecurityPrivilege) {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'EnableAudit'
|
|
Disable-NTFSAuditInheritance -Path $file
|
|
$sd = Get-NTFSSecurityDescriptor -Path $file
|
|
$sd.SecurityDescriptor.AreAuditRulesProtected | Should -BeTrue
|
|
|
|
Enable-NTFSAuditInheritance -SecurityDescriptor $sd -ErrorAction Stop
|
|
|
|
$sd.SecurityDescriptor.AreAuditRulesProtected | Should -BeFalse
|
|
(Get-NTFSInheritance -Path $file).AuditInheritanceEnabled | Should -BeFalse
|
|
Set-NTFSSecurityDescriptor -SecurityDescriptor $sd -ErrorAction Stop
|
|
(Get-NTFSInheritance -Path $file).AuditInheritanceEnabled | Should -BeTrue
|
|
}
|
|
}
|
|
|
|
Describe 'Cmdlets that read a security descriptor in memory' {
|
|
BeforeAll {
|
|
$file = New-TestSandboxItem -Sandbox $sandbox -Name 'Read'
|
|
Add-NTFSAccess -Path $file -Account 'S-1-1-0' -AccessRights ReadData
|
|
}
|
|
|
|
It 'Get-NTFSAccess should return the entries that it returns for the path' {
|
|
$expected = @(Get-NTFSAccess -Path $file | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.IsInherited })
|
|
|
|
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSAccess -ErrorAction Stop)
|
|
|
|
$result | Should -Not -BeNullOrEmpty
|
|
($result | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.IsInherited }) -join ';' | Should -Be ($expected -join ';')
|
|
$result | ForEach-Object -Process { $_.FullName | Should -Be $file }
|
|
}
|
|
|
|
It 'Get-NTFSOwner should return the owner that it returns for the path' {
|
|
$expected = (Get-NTFSOwner -Path $file).Owner.Sid
|
|
|
|
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSOwner -ErrorAction Stop)
|
|
|
|
$result | Should -HaveCount 1
|
|
$result[0].Owner.Sid | Should -Be $expected
|
|
$result[0].FullName | Should -Be $file
|
|
}
|
|
|
|
It 'Get-NTFSAudit should return the audit entries that it returns for the path' -Skip:(-not $holdsSecurityPrivilege) {
|
|
Add-NTFSAudit -Path $file -Account 'S-1-1-0' -AccessRights ReadData -InheritanceFlags None -PropagationFlags None
|
|
$expected = @(Get-NTFSAudit -Path $file | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.AuditFlags })
|
|
|
|
$result = @(Get-NTFSSecurityDescriptor -Path $file | Get-NTFSAudit -ErrorAction Stop)
|
|
|
|
$result | Should -HaveCount 1
|
|
($result | ForEach-Object -Process { '{0}|{1}|{2}' -f $_.Account.Sid, $_.AccessRights, $_.AuditFlags }) -join ';' | Should -Be ($expected -join ';')
|
|
}
|
|
}
|
|
|