Gatt Posted June 20, 2006 Posted June 20, 2006 Ok this has no doubt been posted before, but how do i stop kids from using "File - Open.." to browse the network? When they do it it opens up the UNC & Tree to their home folder rather than their drive letter, and allows them to go into other kids folders.
plexer Posted June 20, 2006 Posted June 20, 2006 Allows them to go into other kids folders? that shouldn't be possible with correct security permissions anyway. Ben
Gatt Posted June 21, 2006 Author Posted June 21, 2006 Been thru NTFS permissions: Root Share: (\\\Pupils\\%username% - (Pupils = Shared Folder) \admininstrator (FC) \Administrator (FC) \Administrator (FC) Per user folder: \admininstrator (FC - Inherited from Root Share) \Administrator (FC - Inherited from Root Share) \Administrator (FC - Inherited from Root Share) \%username% (FC - by AD) The \\\Pupils share has share permissions of - Everyone (Read) When the user logs on it maps their home drive to H: have GPO set up to hide My Network Places, etc Kid opens up Word, goes to file-open and they see MNP, The file server, the Pupils share, their Year group folder, and their home dir they can then click all the way up and browse the lot! I tried this by BOFH'ing a kids user account and yep plain as day - i could get into the whole shebang! WTF is going on?? Gonna try stripping and re-applying NTFS i think
Geoff Posted June 21, 2006 Posted June 21, 2006 I much prefer per user shares personally. eg, you have each user's home folder shared as: \\server\username$ So that means if they somehow get 'up' from their My Documents they can only see their own files. If they go up further they just end up staring at the server shares. Which is no different from what they can see going the other direction from network neighbourhood. Also, if your using W2k3 server, have a look at installing the access based enumeration addon. This will 'hide' folders and shares on the server that a user cannot access. http://www.microsoft.com/windowsserver2003/techinfo/overview/abe.mspx
DMcCoy Posted June 21, 2006 Posted June 21, 2006 I put the access based enumeration on my main file server and enabled it for all the shares, works perfectly and now the students don't see anyone elses folder in the user directory (Not that that could access them before, but its just untidy).
Gatt Posted June 21, 2006 Author Posted June 21, 2006 Found the problem Office 2000 is defaulting to the full UNC fo rthe user instead of the drive letter - installed the ADm templatets and its solved that problem Though spent about 45 mins trying to solve an error about !!uDefFileLoc not bieng in the [scripts] section when it damn well was!! Sorted that by deleting the tabs tha had been entered into the file Only 2 programs i cant change are access & frontpage - no option to change the Default File Location in the adm files
Geoff Posted June 21, 2006 Posted June 21, 2006 Don't let them use Access and Frontpage then. Two of the worst bits of software I can think of.
Gatt Posted June 21, 2006 Author Posted June 21, 2006 tell me about it but TPTB keep overruling me on this one
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now