Jump to content

Recommended Posts

Posted
I installed a piece of freeware called USB Drive Letter Management, which allows you to specifiy what letter a USB device gets when it is plugged in, then I crudely had to add into the Software Restrictions in GPO deny *.exe, then *.*\*.exe, then *.*\*.*\*.exe.... for a good few levels as there's no way to specify the whole drive. The students could get round it if they put an exe in a deep enough subfolder, but I'm hoping they'd give up before getting that far :)

 

I have to say, I think you're going about it back to front. Its much easier to deny everything then put in a whitelist of files you want run than it is to blacklist everything you don't want run. As long as you allow anything in Program Files and a couple of other choice directories (Kudos for example) you're laughing.

Posted
There are all sorts of exe's running - yes, a lot in program files, but also other places - i'd rather not develop huge lists of programs to exclude from the list and simply block the areas where i know they shouldn't be running exe's
Posted
You can add drive letters, however, something like: p:\*.exe only blocks exe's in the root, you have to specifiy a block on each level through the directory structure in software restrictions
  • 1 year later...
Posted
You have to lock down pretty hard if people change ports, but the firewall is a good place for this; prevent the IM working, and you remove the temptation to download :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...