Jump to content

Recommended Posts

Posted
The biggest issue with local admin right is if you are able to see files on a remote computer, as this can allow you to see documents on the users desktop for example, and anything else stored in the profile
Posted

Webman -

AV runs on all w/stns & server. They may have attempted brute force (with my encouragement!) against the server, but have not succeeded.

 

E1uSiV3 -

No Reborn cards on server, we (like US Department of Defence) rely on Novell security.

If they do install games/P2P they're instantly deleted when the w/stn reboots.

 

ajbritton/NetworkGeezer/DMcCoy -

Remote access & file sharing are not enabled on w/stns - particularly the Head's!!

 

NetworkGeezer -

I see what you mean about having my rebellious ideas challenged!!!

 

Time to go home.

 

RoyG

Posted

Well, personally, I still see problem areas within the network model. Perhaps your AV fails or isn't updated for the latest threat.

 

If they can run whichever executables they wish and are able to browse the network, nothing good can come of this from a security point of view in my opinion. Snooping packets, spoofing IP addresses, browsing network shares, net-sending to people. Just becaus P2P apps are deleted on a reboot doesn't mean they aren't using them to illegally share files which could land the school/LEA in hot water. To me, it's like having your server's directly connected to the Internet without a firewall.

 

All it takes is a vulnerability in one of the server's services which is open on the LAN to be taken advantage of. And without software policies in place to stop them running things to give them access to this, it is a potential problem area.

Posted
Snooping packets, spoofing IP addresses,

This is important when Web filtering is IP based as with some RBCs rather than user authenticated e.g. ISA/Websense or Censornet.

 

net-sending to people.

The XP firewall should be up by default and blocking all inbound comms even on the LAN.

 

Just becaus P2P apps are deleted on a reboot doesn't mean they aren't using them to illegally share files which could land the school/LEA in hot water. To me, it's like having your server's directly connected to the Internet without a firewall.

 

To be fair, you'd normally block P2P at the proxy or the firewall.

Posted
Yes, a few good points NetworkGeezer. I had made presumptions about the network. I believe in prevention being better than cure, and preventing users from having free-reign over the network is better than sorting out the aftermath, in my eyes.
Posted

I'd be more worried about students installing key loggers onto pcs and then getting access to teacher accounts / SIMS et al.

 

Students should have no admin rights full stop.

Posted
I'd be more worried about students installing key loggers onto pcs and then getting access to teacher accounts / SIMS et al.

 

Roy's arguemnt was that he disabled logout so then the only way to exit a session was via-reboot which cleared out the malware.

 

Students should have no admin rights full stop.

 

This is probably still my default position, especially on general purpose PC suites.

That said it has been interesting to have another perspective on the matter.

Posted

ajbritton/NetworkGeezer/DMcCoy -

Remote access & file sharing are not enabled on w/stns - particularly the Head's!!

...and all the default shares turned off?

 

Agreed Geezer. It looks like a lot of fuss to set up - and not cheap ...apart from Netware :p

Posted

Webman -

 

"....Perhaps your AV fails or isn't updated for the latest threat..."

 

Let's face it, that could cause problems on any system!

 

"....Just because P2P apps are deleted on a reboot doesn't mean they aren't using them to illegally share files which could land the school/LEA in hot water..."

 

Paranoia squared!!!

 

"....To me, it's like having your server's directly connected to the Internet without a firewall..."

 

Overstatment, or what?!

 

"....and preventing users from having free-reign over the network is better than sorting out the aftermath..."

 

That's "free-rein" - sorry, ex-teacher speaking here!!

 

mark -

 

"....and all the default shares turned off?..."

 

Which?

 

"....Agreed Geezer. It looks like a lot of fuss to set up - and not cheap ...apart from Netware..."

 

Confused! What's a lot of fuss? What's not cheap?

 

 

The original post on this thread was "Does anyone use some software that undoes any changes to a local machine's hard drive on reboot?" The answer to that seems to be Reborn Card, EZ-Back, Deepfreeze or similar, however you choose to apply network policies.

 

The thread seems to have developed into "How can this silly old b*gger run a network without imposing huge restrictions on what users are allowed to do."

 

My final words on this topic are that our school has a system which has had only one unscheduled server down since 1999 (40 minutes), only 3 student workstations needing any attention this academic year, where kids can use USB drives, CDRs, floppies, Hotmail or whatever else they like to transfer work between work and home, where they have the freedom (within reason) to experiment & develop their IT skills & interests. We have had no instances of lost GCSE coursework or any other important data. When we were using the "restrict the b*stards to the bare minimum", workstation downtime & general hassle was a LOT greater.

 

The school has 860 students, 200+ desktop PCs, 100+ laptops - total ICT technical support staff, me! We have one ICT Manager who looks after Computer Room bookings and classroom support.

 

We are a Grammar School, which doesn't mean it's full of goody-goodies - just generally brighter villains!

 

I'll be 60 years old next month, enjoy my job immensely, enjoy the interaction with IT users of all ages, am not stressed (often!), don't have to work silly hours, enjoy the challenge of new technologies - I'm still learning loads new every day!

 

I'm not saying that the model we have is appropriate for every school, but worth consideration. For it to work it's important to have a good, co-operative relationship between SMT, ICT Department, ICT Support staff and a degree of trust for the kids. Don't fight 'em - talk to 'em!

 

Over & out.

 

RoyG

Posted
Webman -

 

"....Perhaps your AV fails or isn't updated for the latest threat..."

 

Let's face it, that could cause problems on any system!

 

Yes, it could, but even more so where users can execute anything they like!

 

If it works for you, that's great. But we do it the opposite way and have great results, too. Our only downtime has been due to heat in the past 4 years since the new network was installed and new Network Manager to manage it all (bossman).

Posted
For it to work it's important to have a good, co-operative relationship between SMT, ICT Department, ICT Support staff and a degree of trust for the kids.

 

Got it in a nutshell , Roy.

 

That's why your idea has met so much resistance - a lot of the techs on here don't have these luxuries ,as you may have noticed....

 

call it paranoia 'til it happens , but call it TROUBLE when it does!

Posted

I you create a domain security group (let us call is w00t_users for the moment) and give it local admin rights to individual machines (eg workstations in the Library) and them make students members of that group then there are all sorts of things they can see ...

 

But if your home areas are on the fileserver then no files (other than temp files) are on the local machine ... so they are safe.

 

I would seriously hope noone would make w00t_users local admins on any server ... and so they are protected.

 

GPOs can be used to lock down what is done with machines and if anyone is deleting system files remotely then use RIS and it will copy them back in on reboot (generally).

 

Area of concern would be using access to remotes shares (I won't describe who you access them here ... in case the little darlings look) and dropping alternate apps in for existing apps ... eg swapping excel for a keylogger.

 

There are about a few areas I would not want this securty group to have access to ... and so I set ACLs to make sure they don't have modify rights ...

 

And if in doubt ... use a cattleprod on the likely culprits ... it deters the others!! (only joking!)

Posted
I you create a domain security group (let us call is w00t_users for the moment) and give it local admin rights to individual machines (eg workstations in the Library) and them make students members of that group then there are all sorts of things they can see ...

 

But if your home areas are on the fileserver then no files (other than temp files) are on the local machine ... so they are safe.

 

 

That doesn't seem to be the case here - with redirected folders here - we still get profile areas left on the hard disk until we clean up!

Posted
They do when you are logged in and put them on your desktop, at least if you use roaming profiles. If you redirect the users desktop then they will be wherever that is
Posted

we don't give users access to stick things on their desktop ... partly for this reason.

 

Actually ... telling a lie ... we do give access to staff ... but will shortly be removing that since they have roaming profiles and keep complaining about the long logon times (Yes ... it will take a long time to logon over wireless IF YOU HAVE A FOLDER OF 6GB OF CRUD ON YOUR DESKTOP!!!)

Posted
we don't give users access to stick things on their desktop ... partly for this reason.

 

Actually ... telling a lie ... we do give access to staff ... but will shortly be removing that since they have roaming profiles and keep complaining about the long logon times (Yes ... it will take a long time to logon over wireless IF YOU HAVE A FOLDER OF 6GB OF CRUD ON YOUR DESKTOP!!!)

 

Excuse me you use roaming profiles with laptops or do you have some desktops with wireless NICs?

Posted
We don't redirect staff desktops to stop them moaning if they lose connectivity because they have done something like turn of the WiFi but that will be gone once we lock down their desktops too ... we don't redirect student desktops because there is simply no need to ... we have nothing on there that we need redirecting.
Posted

I use offline files to get round the staff desktops disappearing (also do mydocs and startmenu). But only applies to staff on staff laptops.

 

Students desktops are redirected to a read only folder with a few shortcuts in for the more common apps.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...