mavhc Posted October 13, 2023 Posted October 13, 2023 The issue is that Windows/Domain security alone isn't really enough IME. We actually had a security company in and they literally demonstrated that with just a Windows AD account (which all pupils have [or possibly a "friends" AD credentials]) and the ability to run scripts/code and or hacking/cracking applications unrestricted you can literally wreck havoc on a fully patched Active Directory / File server and the local Windows install even assuming restricted network access to just the AD/SMB ports/protocols alone. Like you mention Microsoft couldn't even properly secure the root of the Windows system drive on clients! Did you implement all the fixes they gave you to fix the bad defaults? What were they?
6Foot2 Posted October 13, 2023 Posted October 13, 2023 Did you implement all the fixes they gave you to fix the bad defaults? What were they? Do we really want to list specifically what we think may be points of opportunity for potential exploitation on a network?
dmj Posted October 13, 2023 Posted October 13, 2023 My thoughts are that most school networks are not really fit for purpose in this regard, and should probably be re-thought from the ground up. I'd tackle if from the complete opposite perspective by securing access to the network so that public workstations can't actually do any damage if they are compromised, ie move teaching resources onto the internet and treat workstations as if they are coming from the internet. 1
mavhc Posted October 13, 2023 Posted October 13, 2023 Do we really want to list specifically what we think may be points of opportunity for potential exploitation on a network? If the original person had those flaws it's likely many others will, so yes, state the flaws the pentest found and how they were fixed, then everyone ends up with a more secure network
6Foot2 Posted October 13, 2023 Posted October 13, 2023 If the original person had those flaws it's likely many others will, so yes, state the flaws the pentest found and how they were fixed, then everyone ends up with a more secure network What I was saying, without stating it explicitly, was that perhaps it's not a good idea to be pointing out potential network weaknesses in this thread, as it is not BTRD. 1
chazzy2501 Posted October 13, 2023 Posted October 13, 2023 Something most people can't grasp.. I need the pupil to make / run any code they want BUT not do anything that would not do anything malicious... This is just someone who isn't even trying to understand what they've asked. Some web sites let you make code and run it on them, so no local access at all, disable command prompt. not too worries about powershell, time wasting yes, escalation attack probably not. A real attack that I couldn't mitigate easily is the shift+reset.. as the pupil could get the PC to boot from usb, even though it is disabled in the BIOS.
mavhc Posted October 13, 2023 Posted October 13, 2023 https://www.edugeek.net/forums/windows-10/201059-removing-windows-restore-repair-shift-restart.html
6Foot2 Posted October 13, 2023 Posted October 13, 2023 https://www.edugeek.net/forums/windows-10/201059-removing-windows-restore-repair-shift-restart.html This thread predates my tenure as moderator. Nevertheless, given your expressed concerns, I have moved the thread.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now