Why does Vista,7,8 require ownership of external drive, but not bartPE


Recommended Posts

I brought this question up in a previous support thread that was just locked by request of the OP.

So I guess i'll move the question to a new thread.

When transferring data from a previous machine to a new machine, you open the old drive on the new machine and attempt to navigate to the previous user account in the documents and settings folder or users folder and the new Vista, 7 or 8 machine says that before you can access this folder it the OS must take ownership.

But if you boot into a bartpe environment and try to load that exact same folder, it will open up first try and the files are visible and copyable clear as day without taking any sort of ownership.

Charisma said

This happened with me when I recently set up a new build--set up the OS on a SSD and used the old drive with all my files on it as a secondary/storage drive. I'm just going through doing that as needed, but it's quite normal, since the files were created/owned by a different SID on a different system.

Because BartPE doesn't have to take ownership we know it's not a security measure of the file system on the previous drive. So we know it is possible to read files without taking ownership, is it the case that Vista, 7 and 8 cares to much? Or does it have something to do with UAC?

It is a security system of NTFS.

Unfortunately, the kernel implements (or in this case doesn't) the security based on the folder settings. Windows 7 and 8 are correctly implementing security. Bartpe isn't >.>

SOOOOOO.. Physical access to the disk beats all else.

  • Like 2

It is a security system of NTFS.

Unfortunately, the kernel implements (or in this case doesn't) the security based on the folder settings. Windows 7 and 8 are correctly implementing security. Bartpe isn't >.>

SOOOOOO.. Physical access to the disk beats all else.

Exactly Windows Vista 7, 8 is correctly implementing security. But what good is that, if you can just boot bartpe which isn't correctly implementing it and get access.

I haven't used BartPE, but my assumption would be the following...

BartPE runs in the context of Administrator which already has access to all the folders. When you run Windows Vista or later you're running under the context of a less privileged user and you need to be given access to that folder, as a less privileged user, before you can access it. If you fired up Explorer as Admin (you can do this) then I suspect you wouldn't encounter the take ownership prompts on Windows Vista or later just as you don't in BartPE.

The ACL rules are still the same in all cases.

Physical access > All.

Lets say your server dies? How do you recover the file system?

The reason this is important is because you can transfer the FS to a new server, and all of the permissions will persist.

If you can take the disk out of the server and plug it into something stupid (bartpe/XP for instance :p) you can bypass the security settings.

Hell, Vista, 7 and 8 can all bypass it if you have physical access and Admin permission on the kernel.

The point is that people ought not be able to take drives off your servers without your permission :p But you want your permissions (when moved with your.. permission.. >.>) to persist :)

EDIT::

I figured Bartpe wasn't implementing NTFS permissions correctly, might well be that you're always running as Admin on the system thus you're taking advantage of established permissions. No idea >.<

Exactly Windows Vista 7, 8 is correctly implementing security. But what good is that, if you can just boot bartpe which isn't correctly implementing it and get access.

It's why bootable images (either DVD-based or USB-based) of WinPE (which bartPE is based on) are useful in forensic analysis of Windows PCs (such as that of the unlamented Adam Larranza) - it's also part of how drive-migration tools (such as Drive Magician and TrueImage, and Partition Magic before that) have ALWAYS worked.

The $0.64USD question is did bartPE need updating to work with Windows 8's NTFS.

With everything including PE you can read the contents of an external drive. It's just that Vista, 7 and 8 make it more of a pain in the ass to accomplish the same thing.

Nope, NTFS is entirely backwards compatible. If it encounters a flag it doesn't understand, it steps over it. There's a KB on ReFS that explains NTFS implementation of this area >.<

Bartpe is running XP's kernel, thus XP's NTFS implementation without proper security permissions.

@ Warwagon - Physical access yes?

Even thought NTFS details the permissions, the Kernel implements them. Thus you can do whatever you want if you have control of the Kernel.

EDIT::

For your edit >.>

If you consider moving your file permissions with the file system a pain in the arse, sure. I think most admins prefer it this way, makes life a ****ton easier.

BartPE is just a homegrown version of WinPE

http://msdn.microsof...dded.51%29.aspx

When you boot your device by using Windows PE, you have complete access to the NTFS file system on the target device, regardless of administrator privileges, access control lists, or NTFS permissions placed on the file system.

http://download.micr...dowsPE_tech.doc

Windows PE allows you to access the NTFS file system without regard to the access control lists placed on the file system.

This is no different than booting say as mentioned already a linux CD, as also stated if you have physical access does not matter what sort of ACLs you have set on the filesystem, be windows NTFS, or other OS file systems EXT3, ReiserFS, HFS+, etc.

Unless the filesystem/file is encrypted - if you have physical access then you can gain access. Is what your asking why does a full blown OS like XP, Vista, 7 or 8 adhere to NTFS permissions when an OS like winPE does not?

I would of like for that other thread to remain open for a place of discussion as well. Would of been a good place to go over NTFS basics - and the details of why users run into problems when they move disks or try and share externals between systems. If your going to use an OS, its a good idea to understand the basics of how its filesystems permissions system works ;)

I agree we see quite a few threads with the same flavor - why can I not access my files when I reinstall my OS, or when I put the disk in different machine, etc. If you have physical access, and not encrypted and you are admin on the OS your using to access - then does not matter what permissions were set on the other OS, you can always take ownership and set the permissions to your liking.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The fact that memory in general is so high I have to take a loan out to build a computer now is just beyond stupid. Who's really to blame here? Low supply or high demand?
    • Display Driver Uninstaller (DDU) 18.1.5.5 by Razvan Serea Display Driver Uninstaller (DDU) is a utility for completely removing AMD/NVIDIA/INTEL graphics drivers and related packages from your system, attempting to eliminate all leftovers (including registry entries, folders and files, driver store). Though AMD/NVIDIA/INTEL drivers can usually be removed via the Windows Control Panel, this uninstaller tool was created for situations where standard uninstall fails, or when you need to fully remove NVIDIA or ATI graphics card drivers. After using this driver cleaner, your system will behave as though it’s the first time you’re installing a new driver—similar to a fresh Windows installation. As with all such tools, we recommend creating a restore point beforehand, allowing you to undo changes if issues arise. If you're having trouble installing an older or newer driver, try it—there are reports that it resolves such problems. Recommended usage: The tool can be used in Normal mode but for absolute stability when using DDU, Safemode is always the best. Make a backup or a system restore (but it should normally be pretty safe). It is best to exclude the DDU folder completely from any security software to avoid issues. You do NOT need to uninstall the driver prior using DDU. Requirements: .NET Framework 4.8 Compatible with Windows 7, 8, 8.1, 10, and 11 (32-bit or 64-bit) Note: Using on Insider Preview builds is at your own risk. Display Driver Uninstaller (DDU) 18.1.5.5 changelog: Added 'Reset to recommended' button for the Options. General fixes and improvements. Download: Display Driver Uninstaller (DDU) 18.1.5.5 | 1.7 MB (Freeware) Download: DDU Portable | 1.2 MB Links: Display Driver Uninstaller Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • WACUP 1.99.51.24568 Preview by Razvan Serea WACUP (WinAmp Community Update Project) is a modern, enhanced version of the classic Winamp music player, designed for better stability, performance, and compatibility. Built for Windows, WACUP retains the familiar Winamp interface while adding 64-bit support, bug fixes, and new features like improved audio format support, customizable skins, and optimized playlist management. Unlike bloated alternatives, WACUP focuses on lightweight performance and regular updates, making it the best choice for fans of the classic Winamp experience. Basically, if you miss the good old days of Winamp and want a modern upgrade that doesn’t mess things up, WACUP is for you! WACUP key features: Classic Winamp Feel – Keeps the familiar interface and functionality. Bug Fixes & Stability – Fixes old Winamp issues and improves performance. 64-Bit Support – Works better on modern systems. More Formats & Plugins – Supports additional audio formats and third-party plugins. Customizable UI – Skins and tweaks for a personalized look. Better Library Management – Improved playlists, media organization, and search. No Bloat – Focuses on performance without unnecessary extras. Regular Updates – Community-driven development with new features and fixes. WACUP 1.99.51.24568 Preview changelog: Fixed a deadlock seen from the recent crash reports when doing some of the drag + drop actions within the media library window Fixed a loading crash seen related to a problem with some of the artwork cache image files being restored which should now be better handled allowing for the bad image to be removed without it failing Fixed a deadlock seen from the recent crash reports when the internal metadata cache clearing is triggered which could block the main ui thread for too long with this now being moved to a background thread Fixed some performance issues with some of the methods related to determining artwork support which mainly affected the local library import / refresh (this is still slower for some compared to other players because there's more data & artwork aspects being checked for which means doing more processing on a single file despite the best of attempts to reduce duplicate / heavy processing where possible) Fixed a crash with the JTFE based missing files hotkey which no one seems to have used for an age for this to appear (maybe it's time to seriously consider stripping out features that aren't being used) Fixed how some of the file types which use extra information to reference their sub-songs is handled which was preventing some from being correctly resolved back to their base file (noticed fixing above) Fixed an issue with the handling of files with underscores in their filepath which wasn't being correctly handled causing some of the filename to be lost when shown as the title if title reading is delayed Fixed a few things that might be behind NotSoDirect not being stable for some setups though am still not certain that the changes done for this are going to fully resolve the problem from the crash reports Fixed the OS toast handling when there's no prior shortcut in the OS start menu to now create the shortcut (needed to allow the yes/no buttons for the new build / post-release toast) to be done as a hidden one so it's less likely to cause annoyance for those not wanting to see it whilst still allowing this less than ideal OS api implementation requirement to be met to avoid toasts without the needed buttons Fixed a regression when moving from taglib1 to taglib2 which broke some of the handling in place to allow for external programs to still access files when wacup has a held open cached instance of the file Everything else Updated cppwinrt (gen_win10shell.dll) to 3.0.260520.1 (26 May 2026) Updated libcurl (libcurl.dll) to 8.2.1 (24 Jun 2026) Updated Monkey's Audio (in_ape.dll) to 13.15 (28 Jun 2026) Updated mpg123 (mpg123.dll) to 1.33.6 (6 Jun 2026) Updated OpenSSL (libcurl.dll) to 3.5.7 (9 Jun 2026) Updated pugixml to 1.16 (16 Jun 2026) Updated taglib (tag2.dll) to 2.3.0 (11 May 2026) Updated vgmstream (in_vgmstream.dll) to the latest Git commit from 28 Jun 2026 Download: WACUP 64-bit | 9.6 MB (Freeware) Download: WACUP 32-bit View: WACUP Website | Screenshots Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • "over a thousand engineering hours" and started selling it but could not take a couple of minuets to send an AI email to ask permission. What an expensive lesson.
    • just tested it yesterday, a simple page with autoloading ADS takes 60mb....just 1 page for 60 megabytes.   poor people with a limited internet never will visit neolose
  • Recent Achievements

    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      526
    2. 2
      +Edouard
      265
    3. 3
      PsYcHoKiLLa
      146
    4. 4
      Steven P.
      99
    5. 5
      macoman
      55
  • Tell a friend

    Love Neowin? Tell a friend!