![]() | Register | FAQ | Members | Social Groups | User Map | Calendar | Search | Today's Posts | Mark Forums Read |
General Chat General Chat forum sponsored by
From what you think about Billy G to what you think about your favourite beer. |
| | | LinkBack | Thread Tools | Search Thread | Language |
| Sponsored Links |
| | #1 |
![]() Join Date: Jan 2006
Posts: 3,451
Thanks: 49
Thanked 151 Times in 124 Posts
Rep Power: 39 | OMFG ! This is truely the most batty thing I've heared of. |
| |
| | #2 |
![]() | You can say that again. But can't help feelin sorry for the guy if it is true what he is sayin? Seemas like one big mess. I do know of schools where they have little if no security whatsoever. This is one for the local authority to work out good luck to them. |
| |
| | #3 |
![]() Join Date: Nov 2005 Location: Middlesbrough
Posts: 407
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 | Interesting, I believe the school are also breaking the Data Protection Act by placing those files online for anyone to download. |
| |
| | #4 |
![]() | Just looked at the website's front page - is it me or does this site seem to function as both its INTRAnet and its INTERnet site? Having a menu labelled "Student Data" where u can choose to look at info such as their behaviour availble on the Internet is shocking - that should not be there - for any reasons! |
| |
| | #5 |
![]() Join Date: Nov 2005 Location: Middlesbrough
Posts: 407
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 | Exactly, I'm on the verge or ringing the school to tell them they're breaking the DP act, I've already spoken to someone at the information Commissioners office about it. |
| |
| | #6 |
![]() Join Date: Nov 2005 Location: Middlesbrough
Posts: 407
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 | Heh, looks like the site is now offline :P |
| |
| | #7 |
![]() Join Date: Jun 2005
Posts: 255
Thanks: 1
Thanked 9 Times in 7 Posts
Rep Power: 9 | The server is a Frogteacher box this supplies web services with access to the school network mapping the users home folder in Active directory so that it can be accessed from any Internet connected PC via Internet Explorer (Home School links). One issue that I am aware of is that Google indexes pages that you may not wish the public to view. This post on Google outlines a "Google hack” the search string used is in the first post. If one of the pages indexed has search facilities for the MySQL database the users can be listed, as with any other data stored there. I suspect this is where the person has fallen foul; they have found one of these links in google and exploited it. |
| |
| | #8 |
![]() | Wow this is the school I went to when I was a lad! I can't beleive they've been so stupid? Does anyone know who their Network manager/It technician is? It would be interesting to hear their take on this. |
| |
| | #9 |
![]() | @woody: Normally i'd say "Check their website".. but in this instance that may not be the best thing to do - lol! |
| |
| | #10 | |
![]() | Quote:
| |
| |
| | #11 |
![]() Join Date: Jul 2005 Location: Kettering, Northants
Posts: 5,118
Thanks: 54
Thanked 206 Times in 110 Posts
Blog Entries: 1 Rep Power: 55 | The problem seems to be that the authentication for the session is based in the id string for the page ... if the account that that session had been used had had it's account locked then you would not be able to access it. It is a common problem with systems that keep authentication shells of any sort for more that a few hours without being cookie based, or similar (integrated windows authentication as an example of not needing to authenticate repeatedly). The actions of the school were over the top ... the attitude of the student was over the top ... a friendly word from the student to the NM would have sorted this out long since. |
| |
| | #12 |
![]() Join Date: Sep 2005 Location: Rochdale
Posts: 290
Thanks: 5
Thanked 2 Times in 2 Posts
Rep Power: 7 | Why blame the NM? I'm sure at Hathershaw they have some bigwig in charge of this thing, not your put upon NM. |
| |
| | #14 | |
![]() | Quote:
| |
| |
| | #15 |
![]() Join Date: Jul 2005 Location: Kettering, Northants
Posts: 5,118
Thanks: 54
Thanked 206 Times in 110 Posts
Blog Entries: 1 Rep Power: 55 | I have to admit to having lost any sympathy with the student now ... he has registered a similar domain (top search in google) and posted a site outlining it all ... does he not know how stupid and damaging to his case this might be? He hasn't responded on the thread at all on the newsgroup but I have tried contacting the school (the site is now down so they may be aware) but without success. |
| |
| |
| | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Another how to map a windows share thread ! | richardp | Mac | 10 | 15-10-2007 01:22 PM |
| The Post Your Desktop Thread | mrforgetful | General Chat | 59 | 02-07-2007 10:25 AM |
| BSF/PFI thread on ICTTechnician.com | GrumbleDook | General Chat | 12 | 26-04-2006 01:45 PM |
| Screencasts Request Thread | russdev | General EduGeek News/Announcements | 4 | 23-04-2006 10:59 PM |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search Thread |
|
|








