<?xml version="1.0"?>
<rss version="2.0"><channel><title/><link>https://www.edugeek.net/blogs/blog/116-psydiis-blog/</link><description/><language>en</language><item><title>Clever little printer trick. (a note to self)</title><link>https://www.edugeek.net/blogs/entry/1195-clever-little-printer-trick-a-note-to-self/</link><description><![CDATA[<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-username="mavhc" data-cite="mavhc" data-ipsquote-contentapp="blog" data-ipsquote-contenttype="blogs" data-ipsquote-contentid="1195" data-ipsquote-contentclass="blog_Entry"><div>2 steps to have printers just print to the IP of the printer:<p>
run on startup: pnputil /a 'driver.inf'</p><p>
Preferably a v4 printer</p><p> </p><p>
then on login:</p><p>
</p><pre class="ipsCode">
$CurrentUser = [system.Security.Principal.WindowsIdentity]::GetCurrent()
$WindowsPrincipal = New-Object System.Security.Principal.WindowsPrincipal($CurrentUser)

Add-printerport -Name "TCPPort:printerdns/ip" -PrinterHostAddress "printerdns/ip" -ErrorAction SilentlyContinue

Add-PrinterDriver -name "Kyocera TASKalfa 4053ci v4 KX (XPS)" -ErrorAction SilentlyContinue
Add-PrinterDriver -name "Kyocera TASKalfa 4053ci KX" -ErrorAction SilentlyContinue
Add-PrinterDriver -name "Kyocera TASKalfa 4052ci KX" -ErrorAction SilentlyContinue

if ([system.DirectoryServices.ActiveDirectory.ActiveDirectorySite]::GetComputerSite().Name -eq "site1") {
 Add-Printer -Name "Name to appear to users" -PortName "TCPPort:thatDNSorIPfromEarlier" -driver "Kyocera TASKalfa 4053ci v4 KX (XPS)" -ErrorAction SilentlyContinue
 set-printconfiguration -color $false -printername "Name to appear to users"  -ErrorAction SilentlyContinue
 $printer = Get-CimInstance -Class Win32_Printer -Filter "Name='Name to appear to users'"
 Invoke-CimMethod -InputObject $printer -MethodName SetDefaultPrinter
 if (-not $WindowsPrincipal.IsInRole("PupilsGroup")) {
   Add-Printer -Name "Office printer" -PortName "TCPPort:..."   -driver "Kyocera TASKalfa 4053ci v4 KX (XPS)" -ErrorAction SilentlyContinue
   Add-Printer -Name "Office printer v3" -PortName "TCPPort:...."   -driver "Kyocera TASKalfa 4052ci KX" -ErrorAction SilentlyContinue
   set-printconfiguration -color $false -printername "Office printer" -ErrorAction SilentlyContinue
   if ($WindowsPrincipal.IsInRole("OfficeGroup")) {
     $printer = Get-CimInstance -Class Win32_Printer -Filter "Name='Office printer'"
     Invoke-CimMethod -InputObject $printer -MethodName SetDefaultPrinter
   }
 }
}
if ([system.DirectoryServices.ActiveDirectory.ActiveDirectorySite]::GetComputerSite().Name -eq "site2") {
   ....
}
</pre><div></div><p></p></div></blockquote>]]></description><guid isPermaLink="false">1195</guid><pubDate>Fri, 28 Apr 2023 15:08:26 +0000</pubDate></item><item><title>Do you ever run a computer without an antivirus and/or firewall?</title><link>https://www.edugeek.net/blogs/entry/384-do-you-ever-run-a-computer-without-an-antivirus-andor-firewall/</link><description><![CDATA[<p>Real-Time scanning is essential</p><p>
-------------------------------------</p><p>
There is a good analogy with  vaccination programmes and also condom use vs abstinence around this topic.</p><p> </p><p>
Decent AV blocks generic attacks. I've seen a piece of malware slip though LGfL mail filter, past Symantec MSMSE into my mail store and onto my unpatched (we always run a few days behind the releases) clients, where it was identified by Sophos EndPoint Security  as suspicious and blocked. A few hours later both Symantec and Sophos had specific detection for it and the mailstores cleaned themselves up.</p><p> </p><p>
Nothing to see here move along. </p><p> </p><p>
It would have been a major issue without the client protection.</p><p> </p><p>
You cannot trust everyone to be  as careful as you, thus by allowing your computer to interact with others (websites, friends, email, even yourself when you are in a hurry) you are exposing it to risk. c.f issues with abstinence programmes in fight against STDs.</p><p> </p><p>
Running machines without AV also allows for pools of undetected infection, which makes it harder to prevent and deal with outbreaks. Your internet connected PC (even if it is behind a firewall) makes you a global citizen, and you have a shared responsibility to the health of your neighbours computer (metaphorically). Yes sometimes AV product cause collateral damage, however globally this is has less of an impact than running no AV at all.</p><p> </p><p>
For those who don't run AV on their CCTV, IPTV, Cashless Catering, Printers, Mobiles, switches(!) etc.:I suggest you consider the trend recently - infrastructure is the next target, and while it may be that national institutions will bear the brunt of the directed attacks, once released, self-replicating code could go anywhere. </p><p> </p><p> </p><p>
The myth of Mac and Linux</p><p>
--------------------------------------</p><p>
Historically MS-DOS and later, Windows, would execute any code for anyone with full privileges, often simply inserting a disk would be enough. This is why UNIX/MACOS and RISCOS users used to be smug. MAC and RISCOS users were really only protected by their platform's minority status. This all changed about ten years ago with OS X, GNOME/KDE, JavaScript and Flash. However the unix based platforms still do not generally give Joe User permission to edit system files, and thus persistent malware infections are rare. However both UNIX-like systems and WinNT based systems have flaws that allow malicious code to break into the kernel and once there your machine is compromised completely, and only a full offline scan can give you any chance to clean up your system.</p><p> </p><p>
There is a reason that really nasty infections are called root-kits not SYSTEM-kits.</p><p> </p><p>
P.</p>]]></description><guid isPermaLink="false">384</guid><pubDate>Wed, 03 Nov 2010 13:39:21 +0000</pubDate></item></channel></rss>
