ZeroHour Posted December 3, 2007 Posted December 3, 2007 I agree with a lot of the points but if I were you I would block vbs files as well as bat files. They are much more powerful.
maxymaxy Posted December 4, 2007 Author Posted December 4, 2007 Hi all, Yes, I am a class room teacher TRYING to teach four senior IT subjects with at least one student who is way better than me. I get a small time allowance to help other teachers put teaching material onto our intranet. My title makes it sound like I have more say in how the network runs than I actually do. Our NW manager is not the easiest person to converse with but the light at the end of the tunnel is he is leaving at the end of the year. Yes I am asking a lot of the ABT client but it is able to deliver with the powerful registry editing function. I will stand my ground though and still think the client should be password protected to uninstall it and it should protect it's own install directory.
mrforgetful Posted December 4, 2007 Posted December 4, 2007 Fancy that, I've just replied to your post on AB Forums and find you here hah. I haven't read the thread but am going to guess people have already said what I said before. The problem's not AB's fault, it's the entire network setup you have.
localzuk Posted December 4, 2007 Posted December 4, 2007 maxymaxy, have you thought about going to your head and discussing this issue? ie. going above the NM's head?
MkII Posted December 4, 2007 Posted December 4, 2007 maxymaxy, have you thought about going to your head and discussing this issue? ie. going above the NM's head? The world has gone mad I tell ya! A teacher complaining that the network SHOULDN'T be wide open to attack! - maxy - can you head over to the TES forums and argue for us?? Is the NM an x teacher by any chance? Our other member with Novell + open access + deep freeze thought it highly educationally valuable and indeed challenged his brighter students to break into the servers. 1
mrforgetful Posted December 4, 2007 Posted December 4, 2007 Not sure about challenging them but with Deep Freeze on the clients there's not a lot that a reboot won't fix. We used it when we had Windows 98.
K.C.Leblanc Posted December 4, 2007 Posted December 4, 2007 maxymaxy, have you thought about going to your head and discussing this issue? ie. going above the NM's head? Agreed, try to get some other teachers to speak to the head aswell.
maxymaxy Posted December 8, 2007 Author Posted December 8, 2007 Hi all, I've got an interview with the principal on Monday. I have done a bit of canvassing and have support from library staff, a few teachers and my deputy head. So let's see what happens 8O I will post back and let you know what happened.
maxymaxy Posted December 8, 2007 Author Posted December 8, 2007 I know this is a bit off topic, but has anyone used "Hidefolders XP"? I thought that I might give that a go to hide ABT install files until I can get proper group policies setup on the server...just trying to protect the client.
MkII Posted December 8, 2007 Posted December 8, 2007 I use hidecalc to hide drives, which is free rather than a trial - you can set it using various methods locally, or via a domain in one fell swoop - when the time comes. Dunno why you're messing tho'. If you're doing so much you're already substantially changing the PC images. And if you're going to do that, it would be far less destructive and far simpler to disable the admin logins and/ or change the pupil logins to user or guest status, then they'll be unable to install or remove programs altogether. If you want more control you could delve into gpedit. All a bit painful though on a network, which is why domain administration was invented - then you only have to do the task once.
ctbjs Posted December 8, 2007 Posted December 8, 2007 You don't even need to install an application to hide drives you can do this yourself via group policy. There is some policy editing required to hide the drives you want to but it is all very simple to do. This forum is a great place to throw in ideas of how our networks are set up and it is very very apparent that our schools all use varying methods and software solutions to both protect them and to provide a service to our customers, the teachers, pupils and admin staff. It would be interesting to see a thread started on everyone's network setup, how they do things whether they utilize third party management products or whether they use vanilla windows networks and basically how they control certain aspects of their network in terms of filtering and classroom management. I realise there are probably different areas on the forum for all of these individually but in terms of an overall network setup it would be interesting to see what we all were using. I am bamboozled by the fact that a network should be so open as maxymaxy's appears to be certainly in respect of students, frankly ours have a redirected start menu, the applications they have in that start menu are the only ones they can use, no downloading, no installing or uninstalling or access to drives. They are at school to follow a national curriculum which includes ICT and therefore do not need full access to their systems. Teachers logging on for students should have their hands cut off as they are indeed potentially flouting Data Protection Act policies and putting personal and confidential data at risk. An ICT Co-ordinator is more likely to be a teacher and not a techie in my experience but tend to have a say in how the ICT functions within the school in terms of delivery to students for the curriculum, they should not be involved with the security of the network as I am sure this will not be part of their job description. However, if the concern from the ICT Co-ordinator is that the security is insufficient or non-existent then I feel he/she should take this up with the NM directly in the first instance as they should be working together for the good of the students anyway. However if the NM is reluctant or worse unwilling to change then the NM needs to be advised that the ICT Co-ordinator will be approaching the head rather than going behind his back as this helps no-one. I've gone on way too long and I have a 1 year olds birthday party to go to, its raining and my daughter is asleep in bed, maxymaxy, speak to the NM if he/she won't budge then tell them if they do not take the appropriate steps to secure the network that you will have no choice than to seek advice from the head/principal.
maxymaxy Posted December 10, 2007 Author Posted December 10, 2007 Thank you for the time you have taken to reply. I had an interview with the principal today and he was unaware of the what was happening behind the scenes. It was a worthwhile talk and he is now more aware of the different problems. The NW manager leaves in a few days time and a new one won't be appointed until next year. He has given me the go ahead with a trial of ABT with a view to rolling it out to the rest of the school in the short term. So the situation with the 'open policy' is on hold until the new NW arrives. I will certainly be up front there about my concerns when he/she arrives. The technician is now in charge and I don't think he will be making any changes to workstation images....steady as she goes. In the meantime I will set as many policies as I can with ABT to restrict the student's activities. I am looking forward to taking back a bit of control. From teacher's perspective this is about all I can do.
Markpg Posted November 1, 2011 Posted November 1, 2011 It ridiculous to even allow kids to have local admin rights. Trust me i would know and honestly change your security before some smart arse gets an idea.
SYNACK Posted November 1, 2011 Posted November 1, 2011 It ridiculous to even allow kids to have local admin rights. Trust me i would know and honestly change your security before some smart arse gets an idea. Looks like he was on the way to fixing it, back in 2007 Zombie Thread Alert [ATTACH=CONFIG]11855[/ATTACH] Welcome To EG anyhow.
zag Posted February 13, 2014 Posted February 13, 2014 Massive thread bump here as I was good searching for a solution to this for our BYOD users. Abtutor now has these functions installed but you need to enable them in the control app Tools >> Connection Security >> Additional Security It wont stop the original problems but it does add another layer of protection.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now