bigb3n Posted September 4, 2007 Posted September 4, 2007 Hi all. We have just migrated away from RM CC3 to a Windows 2003 network. Does anybody know of a easy way of blocking .BAT, COM, EXE and SWF being run by a student user? I know of software restrictions policies in group policy but I have never used them myself. We use Impero to block and watch what students do so I can block things they do in that but I feel that it's only a matter of time before somebody tries to run regedit.exe from a memory stick.... Thanks in advance, Ben
mrforgetful Posted September 5, 2007 Posted September 5, 2007 If you want to stop them running anything you'll have to use a Software Restriction Policy, or I think there is a Group Policy where you can enter a list of allowed programs and no others will run. If you wish to stop them saving files of certain types in their User Areas you can use a File Resource Manager File Screen to do that.
SpuffMonkey Posted September 5, 2007 Posted September 5, 2007 We've just started to use Disknet Pro to stop all this malarky - stops the U3 memory sticks too.
ICTNUT Posted September 5, 2007 Posted September 5, 2007 This depends on if you want to do it the hard way (FREE) or the easy way (£££) If you want to do it for free the you will have to use Software Restirction Policies based on HASH rules and do regular sweeps of user directories to ensure viloations are removed (see link in my signature below). As far a BAT, CMD, and COM are concerned there are GPO setting which can be set to prevent these being run (a search of the forums should bring up alot as this has been covered many times), also if the users are just domain users then they should not be able to install much anyhow. There is a domain GPO policy that will stop windows installer from running so this would stop a large number of installers running and a GPO to stop access to tools like regedit and such If you are willing to spend money the I would recommend Space Guard from Tools4Ever -> http://www.tools4ever.com/products/spaceguard/ I have been using this for at least 2 years now and has proven to be very good. It will sort out your quota sizes for you but the main thing is it will stop files based on file extension and it works. The cost is around £300 ish (don't quote me) for a file server with unlimited quotas and rule sets.
bigb3n Posted September 12, 2007 Author Posted September 12, 2007 Hi again, many thanks for your replies, SpaceGuard looks like just the product for me. I really have had enough of hash rules and software policies etc etc Thanks again for your help. Ben
altecsole Posted September 13, 2007 Posted September 13, 2007 We use a software restriction policy based on a path - executables etc are blocked for all paths other than the C: drive. If you have 2003 R2 you can also use disk management to stop users saving certain files to their user area.
Geoff Posted September 13, 2007 Posted September 13, 2007 You can also do something similar if you have *nix Samba based file servers too.
rrichmond Posted October 12, 2007 Posted October 12, 2007 I think you may find my post useful. Stopping .EXE, .CMD and .BAT files Plus its free and works well. We use it at our school.
webman Posted October 12, 2007 Posted October 12, 2007 Would have been easier if you hadn't migrated from CC3 *runs*
bigb3n Posted October 13, 2007 Author Posted October 13, 2007 Would have been easier if you hadn't migrated from CC3 *runs* The network model we had was 6 years old and the cost to stay with RM was way to expensive compared to putting in a normal Windows 2003 network. Also, CC4 looked like it addressed a lot of issues we had with CC3 but trying to get a release date for it from RM was impossible. We had terrible issues with profiles, slow log on's, software installation problems, full domain controllers ( user areas ) troubleshooting pc's when they went wrong ( no local log on ) which we don't have now. At the moment, we have the kids on our side and we have a few of the really good hackers finding holes in my system and letting us know what they are but it's only a matter of time before one of them actually does something using the .COM . EXE exploit. When I first started the current job at LES I really didn't like RM, but over the 2 years I have used it it has really grown on me and I now see why schools have it as it does most things for you. As a Microsoft professional I believe you can do everything ( well most ) better without RM. Cheers, Ben
cixxtynine Posted February 22, 2013 Posted February 22, 2013 The best way to block any file in a domain environement is to create a rule in your current default domain group policy : 1. Edit yours. 2. Go in User configuration -> Policies -> Windows Settings -> Security Settings -> Software Restriction Policies -> Additional Rules 3. Create a new Hash Rule. Reference from : Deny Specific Application in Active Directory GPO - TechSultan
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now