tomscaper Posted October 8, 2007 Posted October 8, 2007 I dont know if this has been covered before, but we are currently having some problems with the kids being able to install firefox, this is allowing them to them bypass our proxy and surf anywhere on the internet. i have had some other trouble with them installing firefox on there usb sticks and installing this program http://portableapps.com/ And using firefox from there. Is anyone having problem with this aswell or does anyone know of a solution. I have blocked the exe's to run firefox and the portable app program but some kids are still getting on somehow.
Geoff Posted October 8, 2007 Posted October 8, 2007 block port 80 traffic on your border firewall, or redirect it to a transparent proxy (if you want to maintain access for software updates, etc).
FN-GM Posted October 8, 2007 Posted October 8, 2007 they could be getting past while logging on and by-passing the group policies and then running firefox.
tomscaper Posted October 8, 2007 Author Posted October 8, 2007 I was speaking to someone and they were saying that the firefox installer does not need admin priverlages to install, which is why the kids can install it. I dont know fully how it all works but its always seemed that any outgoing traffic points to the gateway first and we have to force the internet settings towards our proxy.
mrforgetful Posted October 8, 2007 Posted October 8, 2007 Our internet doesn't work if you don't enter the ISA server in the proxy settings.
FN-GM Posted October 8, 2007 Posted October 8, 2007 Can you add the installer file to the restricted applications & block firefox website?
mrforgetful Posted October 8, 2007 Posted October 8, 2007 That would work but you'd need to redo a new policy everytime the installer was updated, which with Firefox seems to be every day!
tomscaper Posted October 8, 2007 Author Posted October 8, 2007 i have done that and blocked the application exe, the installer exe but they download it from home and bring it in. I have just noticed taht there was a new version of firefox, mabye they have just downloaded the new version but still this is going to be a problem. if a proxy is not set in the internet settings then internet access comes though with out authentication
mrcrazy04 Posted October 8, 2007 Posted October 8, 2007 In that case blocking port 80 on your firewall (the gateway) for everything but the proxy, as Geoff suggested should do the trick. What proxy server do you have?
mrcrazy04 Posted October 8, 2007 Posted October 8, 2007 Also, using GP to prevent unknown files from being executed from anything other than C: should help, as they can't run anything from their usb sticks then.
Guest Guest Posted October 8, 2007 Posted October 8, 2007 Just take the Default Gateway out of the info DHCP sends out.
PEO Posted October 8, 2007 Posted October 8, 2007 Take away USB drive access. Tell them they have to use the school email. exe files will be blocked if they email them selfs. If they change the file extension to a .jpq etc the the anti virus will pick up on it.
CyberNerd Posted October 8, 2007 Posted October 8, 2007 why not just let them have firefox and fix the gaping security hole with the proxy
PEO Posted October 8, 2007 Posted October 8, 2007 why not just let them have firefox and fix the gaping security hole with the proxy how? :oops:
CyberNerd Posted October 8, 2007 Posted October 8, 2007 why not just let them have firefox and fix the gaping security hole with the proxy how? :oops: as per Geoffs post, the firewall should only allow access to the internet from the proxy server - this forces users to go through the proxy no matter what browser they use.
ZeroHour Posted October 8, 2007 Posted October 8, 2007 Why not just use software restriction policy to block execution of files from external sticks and there my docs etc. Have a search on the forum, pretty sure there is lots of info on the subject. As for the firewall/proxy what one do you have there?
FN-GM Posted October 8, 2007 Posted October 8, 2007 Here is a link to what ZeroHour was referring to http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=11762&highlight=shop+exe+files+from+being+run
Oops_my_bad Posted October 8, 2007 Posted October 8, 2007 Yeah, you need to close the big hole in your firewall/proxy as a priority really :?
FN-GM Posted October 8, 2007 Posted October 8, 2007 Another forum post that might help http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=11128
tomscaper Posted October 9, 2007 Author Posted October 9, 2007 I have set the exe in the software restriction policy and i think it is sorting the problem out, but when never versions come out they can get around it again. regarding (j17sparky) how would i take the gateway out of the dhcp info that gets sent out, and would this affect anything else. Also i dont have access to the firewall, i wouldnt really know how to block access or set up so it only goes though the proxy
ZeroHour Posted October 9, 2007 Posted October 9, 2007 Use software restriction policy to block executables running from other then the areas you want. Then they cant run it regardless.
zag Posted October 9, 2007 Posted October 9, 2007 As others have mentioned you should look at your proxy to find out why it lets people browse the internet without enabling it. This is a huge security hole.
Guest Guest Posted October 9, 2007 Posted October 9, 2007 If you go into DHCP it should be quite obvious how to get rid of the default gateway. What affect it will have depends on how your software is setup but we've had no problems at all. Only one is sybalius which needs to be activated but that just means manually adding the gateway while it does so.
richardp Posted October 9, 2007 Posted October 9, 2007 Don't forget about Torpark, they don't even have to install it !!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now