Jump to content

Recommended Posts

Posted

OK - currently we have a group called Webdeny - if you're in that security group IE won't run for you and the proxy server is changed to a bogus one. This has worked fine for ages but students seem to have found a way round it (not sure what yet).

 

So 2 questions:

1. How are they getting round it

2. What ways do you use to block specific students when they've been bad boys (or girls)

 

Cheers

Posted

Loads of different ways, so we're gonna need abit more information.

 

Can pupils run .exes from their home drive of removable media? If so they could be using another browser from there...

 

Does your proxy do transparent proxying? It's possible that without any proxy information they may be able to browse the web using another browser?

 

I'm sure other people have points to add...

Posted
Loads of different ways, so we're gonna need abit more information.

 

Can pupils run .exes from their home drive of removable media? If so they could be using another browser from there...

 

Does your proxy do transparent proxying? It's possible that without any proxy information they may be able to browse the web using another browser?

 

I'm sure other people have points to add...

 

No it was IE and they can't run stuff from home drives or flash drives.

No it has to have the proxy info in there.

Posted
Interesting... I presume since he's been added to your blocking OU the pupil has logged off and logged back on?

Yes - he's been blocked for ages. Very irritating though.

Posted

I would deny access by changing the proxy settings to point somewhere that does not exist. Then block access to the settings In IE. All done by AD.

 

You might be able to bypass this with a .reg file, but this depends on your setup.

Posted

Depending on you set up, it might be possible for users who have a localy cached profile to log on with the network cable unpluged. Doing this stops GPOs being applied. If there is a proxy specified in the default user profile he'd be able to use the net.

 

Another possibility is he's using someone elses account.

 

Spuid & DansGuardian or an older version of censornet (when it was still free) are two free Linux based solutions for net filtering.

Posted
you haven't upgraded from IE6 to IE7 have you? Aren't the Adm templates different for those versions? Could it be that you have setup the Webdeny for IE6 and it's not working on IE7?
Posted
I would deny access by changing the proxy settings to point somewhere that does not exist. Then block access to the settings In IE. All done by AD.

 

You might be able to bypass this with a .reg file, but this depends on your setup.

 

That's exactly how it is configured.

Posted
How about setting up a logon script that alerts you when he logs on then using a remote viewer to see what he's doing?

 

Thanks guys - I've got a few things to try from this. In terms of a script to let me know when someone logs on - does anyone have one please?

Posted
OK - currently we have a group called Webdeny - if you're in that security group IE won't run for you and the proxy server is changed to a bogus one. This has worked fine for ages but students seem to have found a way round it (not sure what yet).

 

So 2 questions:

1. How are they getting round it

2. What ways do you use to block specific students when they've been bad boys (or girls)

 

Cheers

 

I create a sub OU (not internet access) with a new GPO and enter false proxy server settings. then under User Config/Admin Template/System/Don't Run Specified Windows Applications (add iexplore.exe, firefox.exe and firefoxportable.exe) to the list.

 

Also make sure that the user cannot logon if their profile fails to load (ie student may remove network cable during logon so that GP settngs are not applied) Comp Settings/Admin Templates/System/User Profiles/ Log User off when roaming profile fails

Posted

Get a proxy that allows you to block usernames.

Use a software restriction on an OU to deny Internet Explorer (This will only work well with IE7 as there are ways around it with IE 6) then pop the users in there.

Set up the logon scripts so you know when a particular user has logged on so you can observe them remotely to see what they are upto.

Posted
2. What ways do you use to block specific students when they've been bad boys (or girls)

 

Like you, we have a domain group called "Webdeny" and proxy settings set at the machine and user level.

 

However we have an ISA2004 server sat up on the edge of the network and seperating us from our RBC (the RBC hates it being there, as it stops them coming in when they want, but after they transmitted the Blaster worm or whatever it was to us in the summer of 2003 they just can't be trusted!)

 

Members of the group webdeny are banned from going out onto the web by a rule on the ISA server unless it is for specific sites - we operate a whitelist of sites always used for educational purposes (such as mymaths.co.uk) so the naughty students are restricted from general internet use but can still do their work. ;)

 

Works well enough for us - they hate the fact that they can't get around it: they can run what they like on the PC, be it Firefox from a USB stick or IE, but the proxy just won't let them through if they've been bad boys or girls. :lol:

Posted

I'd be inclined to agree with gwendes, we've had this before when we were asked to block someone from the internet only to find that they already were.

 

We do our banning with Policy Central which can be told completely block IE, both the executabe and then all websites even if you did somehow get past not having a browser.

 

On connecting to the room with netsupport we found the same user logged onto 3 machines :D

Posted

We have an OU that denies internet access - the whole school is going into it Friday morning because I'm pissed off with staff allowing the kids to do nothing but surf the net and look at rubbish all week.....

 

:-)

Posted
Same here, OU with no IP in the proxy settings for the naughty blighters. I am also fed up of staff letting kids play games, etc, and may also drop the enitre school into the OU, we've already had one TFT smashed as someone got frustrated at losing his game.......... Dread to think how many mice have been trashed by bored kids :twisted:
Posted
I reckon he's just logged on as someone else...

 

No he wasn't - that was the first thing I checked.

 

Finally figured it (I think) - something to do with CLEO set up we'd just implemented whereby an auto config their end simply checks for our proxy and if it doesn't find it drops them out to their proxy - so we'd put bogus details in using script etc and the CLEO bit says "oh that isn't the right setting - have ours" thus giving them a route out. Sorted it now.

 

On another note if I specify a GP to stop IE running why is it that Microsoft seem to think that only means by clicking the icon so they can still call it via Excel macro for example!??!

Posted

On another note if I specify a GP to stop IE running why is it that Microsoft seem to think that only means by clicking the icon so they can still call it via Excel macro for example!??!

 

Hmm, that made me wonder if the kiddiewinks can avoid blocks on iexplore.exe by doing:

 

Data > Import External Data > New Web Query

 

and browsing in that window instead. It seems to render using IE and will display Flash content. No right-click menu on web pages, but otherwise it seems unrestricted.

 

Where possible it seems to make more sense to block them on the proxy.

 

Also, might it be an idea to move this thread into security?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...