Reported September 28, 2000 by Delphis Consulting

VERSIONS AFFECTED
  • WQuinn QuotaAdvisor 4.1

DESCRIPTION

It is possible for a local user to bypass disk quota controls put in place by WQuinn QuotaAdvisor 4.1.

DEMONSTRATION

By utilizing NTFS streams, a local user can easily bypass quota controls put in place by QuotaAdvisor 4.1.  The software, QuotaAdvisor, does not check NTFS streams when enforcing quota rules. 

VENDOR RESPONSE

The vendor is aware of this issue but does not have any immediate plans to address it.  A suggested work around for this issue is to frequently check data shares for the existence of NTFS streams or switch to another disk quota software package that takes NTFS streams into account.

CREDIT
Discovered by Delphis Consulting