broken_url Posted May 12, 2008 Posted May 12, 2008 (edited) ......... Edited May 15, 2008 by broken_url
Halfmad Posted May 12, 2008 Posted May 12, 2008 What application? Otherwise you'll probably never get an answer.
kesomir Posted May 12, 2008 Posted May 12, 2008 I'm not sure I understand your problem. Are you talking about running ranger admin on a client machine under your normal user account? What is the primary usergroup for that account? are the required security settings enabled for that user account in ranger? What do you mean by "full-control"? If you can access the ranger admin panel from a client machine, then your account's primary usergroup must have been granted access via the ranger admin panel - afaik there isn't a limited access mode for the ranger admin panel. Are you the administrator? The sentinel forums can be useful - if a solution isn't apparent from either the knowledgebase or admin manual.
cookie_monster Posted May 12, 2008 Posted May 12, 2008 I think Ranger Account Manager has a limited staff mode that is set using a config file. Can't remember more detail but there should be something on the Ranger site.
cookie_monster Posted May 12, 2008 Posted May 12, 2008 (edited) Where did you get the admin utility? So let me get this straight you're saying you're a student or staff member not allowed to use the Ranger Admin Utility but you want to use it? Is that not a breach of your acceptable use agreement? Edited May 12, 2008 by cookie_monster
joe90bass Posted May 12, 2008 Posted May 12, 2008 Can I ask what your role is in the school? If you only have a limited account are you are a techie? If so can't the NM or another techie give you access to Ranger admin?
kesomir Posted May 12, 2008 Posted May 12, 2008 I'd be interested to hear the specifics. Can you attach these "batch files and things"? If you can't access cmd, it's unlikely that ranger would permit executing batch scripts - that is after all, the whole point of ranger.
cookie_monster Posted May 12, 2008 Posted May 12, 2008 (edited) I think broken_url is saying that they have already used bat files to search network shares so ranger clearly isn't stopping that. @broken_url, CMD prompt can be stopped by Ranger or Group policy but the bat files still run via command.com you can exactly do much with a Read-Only program can you How do you mean read only most executable files are 'read only' as in you don't need to alter them to run them. Edited May 12, 2008 by cookie_monster
meastaugh1 Posted May 12, 2008 Posted May 12, 2008 Is it a good idea to be assisting a student (going by post content, the lack of any other posts) to circumvent the school's security? it doesnt really matter how i got to the program, i just need to give myself full access
kesomir Posted May 12, 2008 Posted May 12, 2008 Would have liked to have seen an example of one of the batch files though. @broken_url what school?
cookie_monster Posted May 12, 2008 Posted May 12, 2008 I did point out this issue Is that not a breach of your acceptable use agreement? I don't believe i/we have provided any technical assistance and there really isn't anything in the Ranger folder that can cause harm without admin rights.
azrael78 Posted May 13, 2008 Posted May 13, 2008 Basicly, i need to know if there is any way i can change the programs security options on an account that cant change it, in other words a batch file? or VB Script? that can change it without the admin doing so, it doesnt really matter how i got to the program, i just need to give myself full access because at the moment its Read-Only and you can exactly do much with a Read-Only program can you. In short: 1) You can't 'hack' rights to a program that you don't have access to. 2) It's clear that you shouldn't be even doing this - I understand that students can get curious and such - but the program is locked for a reason. If you really want it to work - venture toward a career in IT, take the exams, get a job and then you will be on the other side of the fence, you will be wanting to keep people out of your system, not try to find ways in. Az
cookie_monster Posted May 13, 2008 Posted May 13, 2008 You can't that's the point not without elevating your user rights i.e hacking the network or using someone’s admin account. Both which i'm sure will be forbidden by your acceptable user agreement and against the law.
Geoff Posted May 13, 2008 Posted May 13, 2008 I think your wasting your time here trying to get Ranger to run under your limited account. Ranger relies on the underlying active directory security levels to work, as such your better off attempting to compromise AD directly. You can do this a variety of ways, however in a school environment the simplest methods are usually the best. i.e. good old fashioned social engineering. Keep an eye out for teachers leaving computers logged on unattended or putting their passwords on post-it notes or notebooks. Be aware that machines that are in areas that pupils don't go usually have higher access to the network than those in classrooms. It's much higher personal risk, but with a much better payoff. Googling for social engineering will give you some ideas on how to pull this off effectively.
elsiegee40 Posted May 13, 2008 Posted May 13, 2008 I think your wasting your time here trying to get Ranger to run under your limited account. Ranger relies on the underlying active directory security levels to work, as such your better off attempting to compromise AD directly. You can do this a variety of ways, however in a school environment the simplest methods are usually the best. i.e. good old fashioned social engineering. Keep an eye out for teachers leaving computers logged on unattended or putting their passwords on post-it notes or notebooks. Be aware that machines that are in areas that pupils don't go usually have higher access to the network than those in classrooms. It's much higher personal risk, but with a much better payoff. Googling for social engineering will give you some ideas on how to pull this off effectively. Milton Keynes EduGeeks with Ranger on their sytems... BEWARE!
cookie_monster Posted May 13, 2008 Posted May 13, 2008 or even better getting an eval copy of windows server to play with at home.
Lesley_tech Posted May 14, 2008 Posted May 14, 2008 Hi broken_url see your from cape town that was a quick move because last time i looked at this forum you lived in milton keynes.. Where im from well anyway i suggest you stop what your doing if your a student because Ranger knows who you are muhaha hehe. on the serious note BE CAREFUL. because if us techs find out about students then they are in trouble!
Netman Posted May 14, 2008 Posted May 14, 2008 1(1) A person is guilty of an offence if: a) He/she causes a computer to perform any function with intent to secure access to any program or data held in a computer; b) the access he/she intends to secure is unauthorized; and c) he/she knows at the time when he/she causes the computer to perform the function that this is the case. 1(2) the intent a person has to commit an offence under this section need not be directed at a) any particular program or data b) a program or data of any particular kind; or c) a program or data held in any particular computer. If you wanna learn then build your own systems and do want you want to them....
cookie_monster Posted May 15, 2008 Posted May 15, 2008 @ Lesley_tech So you and broken_url one and the same person then?
elsiegee40 Posted May 15, 2008 Posted May 15, 2008 @ Lesley_tech So you and broken_url one and the same person then? Some people never learn! There are 5000 members here, most of whom have day-to-day experience of students and can spot one a mile off (even when in disguise!)
Lesley_tech Posted May 16, 2008 Posted May 16, 2008 No i dont know broken_url.. I think People should just leave this post please ..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now