Jump to content

Recommended Posts

Posted

Hi All,

 

We are being plagued at the moment with students playing Minecraft in lessons. We have blocked the .exe from running and have denied any student saving a .exe on their home folders. The little darlings are now embedding the .exe into a Powerpoint presentation then running it from there and it is working. Does anyone know how to block .exes running from within Powerpoint? I've done a Google around and have searched forums but have found nothing that would suit.

 

We are running Windows 7 32-bit on clients, Office 2010 and our domain is Server 2008 R2.

 

Any help or ideas would be greatly appreciated.

 

Thank you.

Al

Posted
The exe surely runs from some temporary location - could you track this (experiment yourself and use taskmgr command line to see where exe is running from) and block the temp location running?
Posted
When we look into the Powerpoint file, the exe file location point to the temporary AppData on the local profile of one of our student users. The location just says C:\Users\09Username\AppData\Local\Temp\Filename.exe but the file does not exist on the PC I am testing on so it must be getting the source from the local profile of another PC somewhere on the network. The thing I do not understand is all our Student accounts have mandatory profiles.
Posted

When you are testing and run the file, does it run? If so, check the temp folder in appdata on the user you're testing with. If this is the case, I'd put a software restriction in place for c:\users\*\appdata\local\temp\*.exe (which I think is one we have in place here)

 

Cheers

 

Will

  • Thanks 2
Posted
However annoying it is, you have to give them some credit for finding a way around the restrictions! Now you just got to find a way of nailing the little b%^&....
Posted

Thanks for all the responses guys. We found that the exe was a repackaged exe with a different hash so our GPO blocking the file didn't pick it up. We have added the new exe hash now. Yes you have to give them credit. Some of them are very enterprising little gifts from God! We'll just have to keep our eyes on what they are bringing in....

 

Cheers chaps!

 

Al

Posted
One of the reasons we use software restriction policies and whitelists - bit of pain to initially set up but once done work very well at stopping random rubbish being run.
Posted
One of the reasons we use software restriction policies and whitelists - bit of pain to initially set up but once done work very well at stopping random rubbish being run.

 

Just enforce applocker

Posted (edited)

Hi

 

I dont think you can stop them embedding the exe but what you can do is.

 

Stop them seeing the c drive.

Stop them downloading exe with your proxy

Stop them running exe files from there area and usb storage devices.

Stop them running exe file in any shared area for students

 

Its not perfect but they will find it hard.

 

Using Group Policy Objects to hide specified drives

 

How Software Restriction Policies Work: Group Policy we use path rules

 

dansguardian default list: mimetype and extention this is how danguardian does it but might give you some ideas.

 

Richard

Edited by ricki
Posted
I think you guys are going about this the wrong way. You're looking for technical solutions to something that is ultimately a disciplinary issue. You can eventually reach a point where you can box them in to where they can't do these sorts of things, but management becomes a pain and the functionality of the machines is hampered. Start out with handing lunch detentions out like candy and move on from there if the problem persists.
Posted
I think you guys are going about this the wrong way. You're looking for technical solutions to something that is ultimately a disciplinary issue. You can eventually reach a point where you can box them in to where they can't do these sorts of things, but management becomes a pain and the functionality of the machines is hampered. Start out with handing lunch detentions out like candy and move on from there if the problem persists.

 

This is true enough - however it needs major buy in from the SLT and proper policies in place.

 

I know many schools have a hard time achieving this, so being able to lock things down whilst trying to change attitudes to a sensible way of thinking is a good middle ground. Also stops screaming staff members ;)

Posted
This is true enough - however it needs major buy in from the SLT and proper policies in place.

 

I know many schools have a hard time achieving this, so being able to lock things down whilst trying to change attitudes to a sensible way of thinking is a good middle ground. Also stops screaming staff members ;)

 

Agreed. Here it would be - why does the computer allow them to do this. Please fix.

 

Meldrew

Posted
This is true enough - however it needs major buy in from the SLT and proper policies in place.

 

I know many schools have a hard time achieving this, so being able to lock things down whilst trying to change attitudes to a sensible way of thinking is a good middle ground. Also stops screaming staff members ;)

 

Yeah, I'll most certainly agree with this. Sometimes the overly complicated technical solution is in fact the easier approach than having to deal with humans. :rolleyes:

Posted

The little rascals!

 

You could always look in to using AppLocker in a Group Policy (in a GPO it's listed as Application Control Policies). There's a bit of work to do but that will most probably solve the issue for you.

Posted

You have to give them some credit I guess. The kids pulling this of will the best next generation of techies. They should certainly be stopped though!

 

I remember using VB Macros in Excel 97 to get a common dialogue box open that would allow me access to the hard disc and allow me to install various games. The NM never did figure it out :)

Posted

One thing I learnt when I worked in the IT Services department at a college was that the more you locked the computers down, the more ways they found to either bugger them up or get around the lock down.

 

In the end we stopped locking them down and implemented HD Guard so they could do whatever they liked to the machines and one reboot later the machines were back to normal with any changes they've made gone.

 

Support calls went down dramatically and up-time of the PCs improved exponentially!

 

At the School I work at we've recently reminded the staff about Impero and now if a user is not doing what they are supposed to the teacher just blocks their internet connection or blanks all their screens so they have to pay attention to what they are saying.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...