Kyle Posted January 24, 2006 Posted January 24, 2006 Is there a way we can stop kids from using MSN Messenger. I will be posting a few basic questions tonight as i continue in building my test network( systems manager is too busy to help.....!) I want ostop the kids from runningn MSN messenger. I have gone to the GPO and change the settings in both Computer & User Configurations>Admin Templates>windows components>windows messenger> and enabled both settings, but the kids seem to get it to run. I have checked several yr11 kids who all seem to have the MSN program files in a folder on their home drives. ( I think they have been passing them round) They then launch the .exe from there. I deleted all files using NFS. We run ISA 2000 as well, is there another way to stop this from being used?
Ric_ Posted January 24, 2006 Posted January 24, 2006 Use ISA to block messenger - there are built in rules for the MSN Messenger protocols (as well as AIM and others) but you may need to check that the ports haven't changed - this is detailed somewhere on the MS website IIRC. Also block the messenger.msn.com website and the sites that allow you to run messenger through a web GUI. A warning that Internet access will be removed is also an option - Becta like you to use school policy to try to prevent misuse.
Dos_Box Posted January 24, 2006 Posted January 24, 2006 Block the exe via GPO. User config - admin templates - system - don't run specified windows applications.
Ric_ Posted January 24, 2006 Posted January 24, 2006 http://www.windowsecurity.com/articles/How_to_Block_Dangerous_Instant_Messengers_Using_ISA_Server.html
fooby Posted January 24, 2006 Posted January 24, 2006 Seriously.... They can even get that far? When I was learning group policy and stuff, I was admin'ing a windows 98 network with so many holes. I have gone over the top I think with my group policy. However, in its locked down'ness I think I stop a lot of problems added to the network I'll post my exported GPO fooby
Michael Posted January 24, 2006 Posted January 24, 2006 The policy you mentioned only works for Windows Messenger and not MSN Messenger! MSN Messenger's messaging port is TCP 1863. Blocking this port along with ports 6891 to 6900 will stop file transfers and port 6901 block voice communications. I'd also block the following websites: messenger.msn.co.uk messenger.msn.com webmessenger.msn.com webmessenger.msn.co.uk explorer.msn.com explorer.msn.co.uk http://www.imagine-msn.com http://www.mess.be messenger.msn.fr messenger.msn.it messenger.msn.de messenger.msn.es messenger.msn.nl messenger.msn.dk messenger.msn.ch messenger.msn.ca messenger.ninemsn.com.au http://www.msnvideodownloads.com There are still loads of sources they can download MSN, but these are some of the main sites.
m25man Posted January 24, 2006 Posted January 24, 2006 So what about all the web based gateways? ISA does a great job blocking all the protocols but you then need url detection and blocking to spot when the little buggers find a web gateway. Sorry, but you can throw thousands at this one and still never have a watertight single solution. Catch em and ban em !! Thats the way to do it! Not my favourite software but nevertheless Forensic's product cleverly alerts the admin when slang is being typed on screen be it in Word, Web, Email or messengers and bang! Gotcha.....
Kyle Posted January 24, 2006 Author Posted January 24, 2006 Forensic's product cleverly alerts the admin when slang is being typed on screen be it in Word, Web, Email or messengers and bang! Gotcha.. God helps us......................... 8O
m25man Posted January 25, 2006 Posted January 25, 2006 Forensic's product cleverly alerts the admin when slang is being typed on screen be it in Word, Web, Email or messengers and bang! Gotcha.. God helps us......................... 8O I realise now, that could amount to nearly everything a child types on the keyboard and probably 90% of what they use the computer for. One could be drowned in log files!
Geoff Posted January 25, 2006 Posted January 25, 2006 automagically blocked here when you add 'Intsant Messanging' Blacklists to Dansguardians filter list.
kingswood Posted January 25, 2006 Posted January 25, 2006 Doesn't ISA only block protocols when in Firewall mode? I really need to upgrade our ISA 2000 Server this year to 2004 because at the moment CSE have installed it only as a caching server- it doesn't do any kind of advanced level blocking (with the exception of web pages). Even so, I find that when I block login.passport.net and its IP address the little things get fair annoyed :-) Problem is, so do the staff and they moan like hell till you put it back on- and the moan again when the students figure out that it's back on!! Also I configured a GPO to block the msnmsgr.exe file on computers: Computer Configuration > Admin Templates > System > Don't run specified applications > add in any .exe files you want in there. It worked anyway. Could also use a registry key: HKLM\Software\Policies\microsoft Create your key called "Messenger" and another one called "Messenger Client"; create a DWORD under client call it PreventRun and give a value of 1. Export this key to a file and import it to your other machines. This worked for me too. Paul
DRogers Posted January 25, 2006 Posted January 25, 2006 One thing wrong with blocking it in the GPO is like the problem we have here with games, they just rename the .exe file to get it to work...
indie Posted January 25, 2006 Posted January 25, 2006 Exactly what I found, I ended up just putting a simple rule on the firewall and Symantec Web Security does a good job of blocking the web based sites.
fooby Posted January 25, 2006 Posted January 25, 2006 Edit your startup script to delete the files from the pc. If it isnt there it can't be run. When I built the image (ghost image) for our network, half the windows software dissappeared. Things like the games and other useless things are all removed. Also I have used a combination of the hidden attribute, and NTFS permissions to restrict file / folder access. Since by default a user cannot see hidden files, if they can find a workaround to see the contents of the C drive, they can't even see the files there anyway. Since they also cannot type an address in the addres bar, they can't browse at all. fooby
steve Posted January 25, 2006 Posted January 25, 2006 I bought a little package that deals with this in a different way. TerminatorX http://www.plevna.f9.co.uk/ It kills processess with specific windows titles, such fun watching the applications close infront of the kids eyes.
E1uSiV3 Posted January 25, 2006 Posted January 25, 2006 If the kids are storing exes in their home drives, put a blanket ban on running exe/pif/com/bat/cmd etc from there.
Kyle Posted February 6, 2006 Author Posted February 6, 2006 If the kids are storing exes in their home drives, put a blanket ban on running exe/pif/com/bat/cmd etc from there. How do i do this....sorry for bing a numpty...... :?
Geoff Posted February 6, 2006 Posted February 6, 2006 http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=1417
E1uSiV3 Posted February 6, 2006 Posted February 6, 2006 Use software restriction policy additional rules and add the UNC patch of the share the kids home drives map to.
DRogers Posted February 6, 2006 Posted February 6, 2006 If the kids are storing exes in their home drives, put a blanket ban on running exe/pif/com/bat/cmd etc from there. How do i do this....sorry for bing a numpty...... :? Ok me too, we want to do this, lame terms please
DRogers Posted February 6, 2006 Posted February 6, 2006 Didn't read my link then? Tbh I was scrolling fast through the page and missed it. Thanks 8)
Dos_Box Posted February 6, 2006 Posted February 6, 2006 Gently please Geoff. *For those who don't know, Geoff is actually a Google plug-in we run here, and as such he can be quite abrupt*
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now