Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

EduSweep Powerful script analysis and detection for your network. Keep the nasties at bay for the low, low cost of nothing!

Go Back   EduGeek.net Forums > EduGeek Projects > Projects: > EduSweep
Reply
 
LinkBack Thread Tools Search Thread Language
Sponsored Links
Old 10-04-2008, 12:13 PM   #1
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Talking EduSweep in use

I just gave a few profiles a quick sweep with beta 5 and look what came up! Names have been changed to protect the guilty.

#### Scan Summary ####

Scan Date: 10/04/2008 12:02:07
Files Scanned: 518
Errors: 0
Detected Items: 4

#### Detected Items ####
\\nbl-sr-02\student$\My Settings\Favorites\proxy\Freedom Proxy.url
\\nbl-sr-02\student$\My Settings\Favorites\proxy\The OpenDoorNetwork - Unlock The Internet With Us! Proxy Sites For Work and School - Visit MySpace, Bebo, Facebook and MORE!! F.url
\\nbl-sr-02\student$\My Settings\Recent\HACKER.lnk
\\nbl-sr-02\student$\My Settings\Recent\pc virus.lnk


Scan completed in 2 seconds.

That's the keyword detection in action there, picking up on "proxy", "hack" and "virus". Two clicks and they were all nicely sitting in quarantine.
  Reply With Quote
The Following 15 Users Say Thank You to bizzel For This Useful Post:
browolf (06-05-2008), Extro (06-05-2008), Gatt (10-04-2008), Geoff (10-04-2008), Gibbo (16-09-2008), GlennT (10-04-2008), IanM4657 (11-04-2008), ICTNUT (10-04-2008), ICT_GUY (10-04-2008), katem (16-04-2008), pallen (10-04-2008), PEO (11-04-2008), plexer (10-04-2008), rush_tech (10-04-2008), Trojan (10-04-2008)
Old 10-04-2008, 12:53 PM   #2
 
Gatt's Avatar
 
Join Date: Jan 2006
Location: Swinton
Posts: 2,284
uk uk scotland
Thanks: 90
Thanked 46 Times in 34 Posts
Rep Power: 22 Gatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the rough
Send a message via MSN to Gatt
Default

Ooh.. this looks good... (runs to download site..)
  Reply With Quote
Old 10-04-2008, 01:07 PM   #3
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,931
uk uk lancashire
Thanks: 42
Thanked 230 Times in 209 Posts
Blog Entries: 1
Rep Power: 67 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default

Just tried this. I found a problem. I get a 'Proxy authentication required' error when I try and update the definitions.
  Reply With Quote
Old 10-04-2008, 01:31 PM   #4
 
WithoutMotive's Avatar
 
Join Date: Feb 2006
Location: Wigan, UK
Posts: 258
uk uk lancashire
Thanks: 14
Thanked 13 Times in 10 Posts
Rep Power: 8 WithoutMotive will become famous soon enough
Send a message via MSN to WithoutMotive
Default

Quote:
Originally Posted by Geoff View Post
Just tried this. I found a problem. I get a 'Proxy authentication required' error when I try and update the definitions.
I get the same thing
  Reply With Quote
Old 10-04-2008, 01:33 PM   #5
 
Gatt's Avatar
 
Join Date: Jan 2006
Location: Swinton
Posts: 2,284
uk uk scotland
Thanks: 90
Thanked 46 Times in 34 Posts
Rep Power: 22 Gatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the rough
Send a message via MSN to Gatt
Default

Oh this is good... just found a kid who seems to habe the entire clip art sounds in his folder (605 WAV Files :O )
  Reply With Quote
Old 10-04-2008, 01:49 PM   #6
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,931
uk uk lancashire
Thanks: 42
Thanked 230 Times in 209 Posts
Blog Entries: 1
Rep Power: 67 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default

mines still scanning. Up to sixth formers though
  Reply With Quote
Old 10-04-2008, 01:55 PM   #7
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Default

Fantastic to hear it's working well for most of you! For people with proxy errors, don't worry for the moment, you do have the latest definitions and I'll look into it. Do you run a proxy server locally and if so, what kind?
  Reply With Quote
Old 10-04-2008, 02:01 PM   #8
 
rush_tech's Avatar
 
Join Date: Jul 2006
Location: Nottingham
Posts: 498
uk uk england
Thanks: 24
Thanked 45 Times in 25 Posts
Rep Power: 13 rush_tech has a spectacular aura aboutrush_tech has a spectacular aura aboutrush_tech has a spectacular aura about
Default

Yer its working fine here. Check defintions seems to work "no update is necessary"
  Reply With Quote
Old 10-04-2008, 02:02 PM   #9
 
Gatt's Avatar
 
Join Date: Jan 2006
Location: Swinton
Posts: 2,284
uk uk scotland
Thanks: 90
Thanked 46 Times in 34 Posts
Rep Power: 22 Gatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the roughGatt is a jewel in the rough
Send a message via MSN to Gatt
Default

Rescanned after deletion and there all gone All the games, WAVS, Vids.. the lot
  Reply With Quote
Old 10-04-2008, 02:02 PM   #10
 
Geoff's Avatar
 
Join Date: Jun 2005
Location: Fylde, Lancs, UK.
Posts: 9,931
uk uk lancashire
Thanks: 42
Thanked 230 Times in 209 Posts
Blog Entries: 1
Rep Power: 67 Geoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud ofGeoff has much to be proud of
Send a message via ICQ to Geoff Send a message via AIM to Geoff Send a message via MSN to Geoff Send a message via Yahoo to Geoff Send a message via Skype™ to Geoff
Default

Proxy server is Squid running with NTLM transparent authentication. There's also dansguardian running with passthru NTLM authentication support.

Squid supports basic authentication if NTLM fails for some reason though.
  Reply With Quote
Old 10-04-2008, 02:08 PM   #11
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Default

Quote:
Originally Posted by Geoff View Post
Proxy server is Squid running with NTLM transparent authentication. There's also dansguardian running with passthru NTLM authentication support.

Squid supports basic authentication if NTLM fails for some reason though.
Okay, I'll see if there's an option in the .net framework that controls the authentication type. We use an RM Smartcache here which is loosely Squid-based, I think.
  Reply With Quote
Old 10-04-2008, 03:11 PM   #12
 
GlennT's Avatar
 
Join Date: Sep 2006
Location: Zummmerzet!
Posts: 240
uk uk wessex
Thanks: 12
Thanked 15 Times in 14 Posts
Rep Power: 8 GlennT will become famous soon enough
Default

Yikes!
"16072 files were detected"
  Reply With Quote
Old 10-04-2008, 03:18 PM   #13
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Default

Quote:
Originally Posted by GlennT View Post
Yikes!
"16072 files were detected"


Sounds like it's working alright but what did you point it at and which definitions were turned on?
  Reply With Quote
Old 10-04-2008, 03:26 PM   #14
 
GlennT's Avatar
 
Join Date: Sep 2006
Location: Zummmerzet!
Posts: 240
uk uk wessex
Thanks: 12
Thanked 15 Times in 14 Posts
Rep Power: 8 GlennT will become famous soon enough
Default

Quote:
Originally Posted by bizzel View Post


Sounds like it's working alright but what did you point it at and which definitions were turned on?
All definitions and aimed at all user areas.....seems mostly Staff mp3's....they have some weird tastes in music that's for sure!
Found a few alarming videos in the student area though....
  Reply With Quote
Old 10-04-2008, 07:00 PM   #15
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Default

If you're seeing the "proxy authentication required" error, could you post the following here:

* The version of System.deployment.dll that you have installed. If it's below 2.0.50727.103, it may be the cause of the problems.
* Whether you're running the program locally or from a network share
* When the error occurs. I believe I'm right in thinking that it's when you press the "Check updates" button.

I think it's a fairly simple problem but I need to know a little more about what exactly triggers it. I'll roll the fix into beta 6.

Thanks!

Last edited by bizzel; 10-04-2008 at 07:07 PM..
  Reply With Quote
Reply

Register now for FREE and post messages!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Image Verification
  I agree to forum rules 


Tags
edusweep


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 02:11 AM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright EduGeek.net