genesis Posted March 23, 2015 Posted March 23, 2015 Hi I have come across a student , who is trying to run a password revealing software. He has extracted the exe on a USB and have tried to install from the USB drive. Our GPO has stopped him from running this program and Trojan alert was triggered form our AV and I was able to find the user .Now I would like to inform the teacher in charge about his activity. Mail PassView: Password recovery for Outlook, Outlook Express, Thunderbird, Windows Mail, and more... PasswordFox - Reveal the user names/passwords stored in Firefox Have you come across such activities by students. Can you please let me know if you have any policy in place , that students not allowed to install a software of this king on the school network. Any suggestion much appreciated Thanks
elsiegee40 Posted March 23, 2015 Posted March 23, 2015 Most schools make their students sign an acceptable use policy of some sort. This should cover the issue that you talk about. To be honest, this should be going straight to SLT as a serious security issue that they will deal with under the school's discipline procedures. There is both a Safeguarding risk and a DPA risk from attempting to get other passwords. It is not fyour job to discipline the student under such circumstances. Document. Pass to SLT. ASAP
dry Posted March 23, 2015 Posted March 23, 2015 Had a student try and pull a similar trick on our network. Instead of giving him a bog-standard detention or whatever, he was made to help out our department for half an hour a day for two weeks (or something like that). He helped us go round the school checking for faults and cable-tieing kb/mouse cables to PCs- which was really useful as it was peak vandalism season! I'm glad we gave him a bit of a nicer punishment than detention, as he went on to write a useful app for students to use at school for his computing coursework (obviously we thoroughly checked his source code before installing it on the network ). It is written into school policy that students will not attempt to install software of any type on the computers.
Grey-gear Posted March 23, 2015 Posted March 23, 2015 Policy is same as @dry on this matter, though not seen any students try this were I work (yet)
salc Posted March 23, 2015 Posted March 23, 2015 We recently had a similar incident. The student's Head of House took it very seriously. The student lost his network access for a few days until he and his mother had a meeting with the HoH and re-signed the AUP. The student still has certain sanctions and is watched fairly carefully.
Grey-gear Posted March 23, 2015 Posted March 23, 2015 We recently had a similar incident. The student's Head of House took it very seriously. The student lost his network access for a few days until he and his mother had a meeting with the HoH and re-signed the AUP. The student still has certain sanctions and is watched fairly carefully. That sound fair. As @elsiegee40 said @genesis Document. Pass to SLT. ASAP The soon the better.
JJonas Posted March 23, 2015 Posted March 23, 2015 As elsiegee40 says document and straight to SLT. We would also get our PCSO to have a few words with him.
Popular Post TechMonkey Posted March 23, 2015 Popular Post Posted March 23, 2015 Ohhh that takes me back. Let me tell you a story, back in a simpler time.. The Boss had written a little script that sat in the background that monitored all applications running. If it detected an exe that wasn't from an known area it would kill it and log, in a text file, username, PC Name, exe name, time date etc. He even had a front end that sat on his PC that would let us know if anything was in the text file. It was one of those hobby applications that it got tweaked when a great plan came together or we heard of an exploit at a different school. This was on Win98, RM Connect 2.4, fairly heavily modified to be well locked down The greatest feature added was the flashing popup that appeared when an entry in the text file was discovered along with a sound file played at full volume. Ever hopeful that some little toe rag would try something for all the prep to pay off. & then, one day, it happened. We both froze, not believing it was happening. It must be a false alarm. But no, neither of us was testing software, testing the application or doing anything that would set it off. We took a look at the display. It was showing a pupil. A known meddler. Trying to run something off a USB stick. We silenced the alarm, only for it to go off again. Was the program not working properly? No, the little tyke had tried again. Suddenly The Boss set off like a whippet after the hare. Another alarm, the pupil was trying a different program. I don't remember the exact names, but they were along the lines of scanner.exe and hackthesystem.exe. You know the ones. A few more alarms went off that I confirmed and then silence..... What happened? Were we safe? Had the network sucumbed? The Boss finally arrived back at the office with a look of sheer joy. He had walked in on the pupil as he tried again, for the last time it turned out. After an ear bending he was taken to his teacher for a longer ear bending and then to year head for more of the same. What really caused the joy was that it was all caught on camera. How I wish we had the HD cameras of today, but alas it was a black and white grainy, VHS tape system. But still you could easily see the door open, The Boss enter and the little lamb turning with a look of terror as he realised there could be only one reason why this apparition appeared before him. It was a fine moment, one of triumph and a fantastic pay off for perseverance. But alas those sweet dulcet tones were never heard again and a not long after we went to CC3 so application control was built in. The application vindicated, a triumphant hero and prized, was retired. Sorry, slightly off track but jogged a memory. On topic, sounds like your setup did what it should, stopped the application and informed you of the offender. This now goes to SLT/Head of Year/Form Tutor for them to deal with under the usual disciplinary procedures. 5
kennysarmy Posted April 30, 2015 Posted April 30, 2015 Many years ago a sixth form student here wrote a virus and brought it in to school and left it on one of the PC's. It was found quite by chance and was probably harmless but I reported the issue to the Headteacher at the time who called him in to his office, the student sat down and I explained what had happened and eventually he confessed. The Head then said.."you better get your bag then...." to which the student looked quizzically at us both, then the Head said "I'm throwing you out the school....."
clockend25 Posted April 30, 2015 Posted April 30, 2015 We had a set of students earlier in the year who'd managed to use a boot disk of some kind to create admin users on PCs. Securus and FEP flagged up that they were then running all sorts of software once on with these accounts, including LOIC and some exes to kill Impero etc. We put the evidence together and went to the principal with it, and they were collared.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now