Jump to content

Recommended Posts

Posted

Right I'll ignore most of your sniggers at the title, but I've got an 'awkward' pupil just after some tips.

The kid's managed to successfully hack the network and change security rights on shared folders, how he's doing it I'm not entirely sure, he's either used a boot tool or somehow obtained an admin password. What he has managed to do is create local admin accounts on machines, I really reckon he's used a boot tool actually (the admin accounts he's set up are named 'adm' if it's of any significance).

 

Now firstly is there anyway of stopping him messing with the local admin passwords, I'm thinking the chances are slim. Secondly (mainly) how is he utilizing the local admin account to mess with the servers and how do I block him? I thought to do anything to files on the server he'd be prompted to enter network credentials upon connecting.

 

Help anyone?

:)

Posted (edited)

Well the first thing that you need to so is change the BIOS boot order and set a password so that the person can't boot your stations from any bootable media.

 

I'd probably also set this value to help stop local passwords being cracked "Do not store LAN Manager hash value on next password change"

 

Use restricted groups to stop local admins from being added to stations.

 

http://www.windowsecurity.com/articles/Using-Restricted-Groups.html

 

 

Make sure that all of your users are only ordinary users NOT power users or local admins. Then I'd audit all users in the domain with administrator rights and change the passwords.

Also run the MBSA on servers and a few clients this will highlight any obvious problems.

 

 

Oh and I'd also be sitting the student down for a 'chat' ;) it doesn't have to be nasty but they must be in breach of your AUP and could be suspended not to mention any seriouse breach of data should involve the police.

Edited by cookie_monster
  • Thanks 2
Posted

As above the BIOS boot sequence configuration needs to be changed and passworded. Secondly the local administrator account password should be changed to something random too. By default XP leaves the administrator password blank. You can specify what the local adminstrator password should be in an answer file when Sysprepping machines.

 

On your domain, if you're using 'administrator', you should really rename this. You could also introduce Access-based Enumeration (ABE), so you can hide shares based on permissions.

  • Thanks 2
Posted
Well the first thing that you need to so is change the BIOS boot order and set a password so that the person can't boot your stations from any bootable media.

 

I'd probably also set this value to help stop local passwords being cracked "Do not store LAN Manager hash value on next password change"

 

Use restricted groups to stop local admins from being added to stations.

 

Using Restricted Groups

 

 

Make sure that all of your users are only ordinary users NOT power users or local admins. Then I'd audit all users in the domain with administrator rights and change the passwords.

Also run the MBSA on servers and a few clients this will highlight any obvious problems.

 

 

Oh and I'd also be sitting the student down for a 'chat' ;) it doesn't have to be nasty but they must be in breach of your AUP and could be suspended not to mention any seriouse breach of data should involve the police.

 

Thanks for the above, I wasn't aware of the restricted groups setting I'll look into it and get it enforced. I'll nip round as many vulnerable stations as possible to alter the bios settings too (was hoping I could avoid that!) . Could you tell me where the 'do not store lan manager' value can be found?

 

I've had a chat with the pupil :rolleyes: All I could really say was 'don't be distructive it's pointless' he told me the machines he'd added the extra user account to and refused to give me much more information. He reckoned he could get on remotely from home and he reckoned he was using tools that automatically cleared the logs. He also reckoned his mate who works for the MOD would be launching a dos attack at 15.05 today. It's just trying to determine the truth...

 

I'm keen to know how he's using the local admin account he's made to mess with the shared folders too.

Posted (edited)
Yeah and I reckon he has 4 arms too. Too busy doing things he shouldn't.

 

Indeed it's frustrating, however I'm staying positive. I'm not a teacher I'm not allowed to discipline him, the teachers and head are well aware so it's up to them.

 

My main priority's getting stuff back on track and blocking him out, interesting episode too.

 

Thanks for your help michael, just renaming the admin now.

 

PS: I hadn't changed the admin account name previously as I thought it was pointless as the SID doesn't change for the account and they don't have the password. I take it I'm wrong just wondering if you know why though?

Edited by dave20046
Posted

Take a look here for Do not store LAN Manager hash value on next password change, read the notes about 9x clients if you have any.

 

Network security: Do not store LAN Manager hash value on next password change

 

PS: I hadn't changed the admin account name previously as I thought it was pointless as the SID doesn't change for the account and they don't have the password. I take it I'm wrong just wondering if you know why though?

 

The DA will still have the same SID but it's still an extra stumbling block, security in layers remember.

  • Thanks 1
Posted

PS: I hadn't changed the admin account name previously as I thought it was pointless as the SID doesn't change for the account and they don't have the password. I take it I'm wrong just wondering if you know why though?

 

If you know the username, you know half the login details. Admittedly the smaller half (!), but every little helps . . . .

 

If network folders have been changed, it means that either the compromised local accounts have access to the network folders (unlikely?), his account has access to do that to the network (unlikely?) OR that he's compromised a network account that has the relevant access. Given that many of your staff will be using their fave football team as their password, that won't have been rocket surgery.

 

Who has access to modify those folders? Enforce a password change, and for added fun scan the logs for failed login attempts in the next few days and see if you can catch him red-handed :-)

 

Good luck with the MOD ;-)

Posted
If you know the username, you know half the login details. Admittedly the smaller half (!), but every little helps . . . .

 

True, I've applied that GPO now however it doesn't seem to have changed the username:confused:

 

 

If network folders have been changed, it means that either the compromised local accounts have access to the network folders (unlikely?), his account has access to do that to the network (unlikely?) OR that he's compromised a network account that has the relevant access. Given that many of your staff will be using their fave football team as their password, that won't have been rocket surgery.

 

Who has access to modify those folders? Enforce a password change, and for added fun scan the logs for failed login attempts in the next few days and see if you can catch him red-handed :-)

 

Good luck with the MOD ;-)

What he's actually done to the network folders is removed rights, he stripped all the users of rights to their own my documents (folder redirected). Only an administrator could have done that...

Posted (edited)
True, I've applied that GPO now however it doesn't seem to have changed the username

 

I made the change in the default domain policy, I'd be temped to wait until scheduled downtime to try it and remember that the stations might need a policy refresh or reboot.

 

 

What he's actually done to the network folders is removed rights, he stripped all the users of rights to their own my documents (folder redirected). Only an administrator could have done that...

 

Again another task for the evening or hols but change all of the share permissions to 'change' rather than full control this stops users editing NTFS permissions remotely. I'd test this with folder redirection as I haven't tried it with that.

Edited by cookie_monster
Posted
We had this problem with kids adding local administrators accounts. It turned out that they had been bringing in the shortcut to computer managment in on a USB pen drive and running it. All as we done is set up software restricitons to stop them running lnk files. Was a pain as they also changed local admin passwords aswell as adding there own users.
Posted
We had this problem with kids adding local administrators accounts. It turned out that they had been bringing in the shortcut to computer managment in on a USB pen drive and running it. All as we done is set up software restricitons to stop them running lnk files. Was a pain as they also changed local admin passwords aswell as adding there own users.

 

 

They must have some form of admin rights already to be able to add users to the administrators group.

Posted
Indeed it's frustrating, however I'm staying positive. I'm not a teacher I'm not allowed to discipline him, the teachers and head are well aware so it's up to them.

 

I would say that depends on your role in the school. If it is your responsibility to maintain the network(inc security) I would say you should have the right to discipline a pupil(but I do acknowledge that every school is different). You have mentioned that you had a "chat" with him where he wasn't helpful at all and to me he's breaking not only your AUP but also the law. (And before it goes off on a tangent I dont want to start a discipline thread) But I assume that you have disabled his account while you look at increasing the security settings?

Posted
TBH, if he's being uncooperative, it's time to get plod involved. Don't take this lightly, if he's done this, what else has he done on the network which you haven't noticed/he's not admitting to? Full shutdown and secuirty audit time ;)
Posted
TBH, if he's being uncooperative, it's time to get plod involved. Don't take this lightly, if he's done this, what else has he done on the network which you haven't noticed/he's not admitting to? Full shutdown and secuirty audit time ;)

 

 

As I stated above (along the same lines as teejay) it's certainly parents time and technically police time especially if he continues. I'm sure most of the teachers would be more willing to do something if you mentioned data protection, of course at first they couldn't care less but when you mention protection of 'their' data e.g. SIMS or equivalent with their personal details in I'm sure that attitude would change. This of course is also why it would be a matter for the police if this kind of data was breached.

Guest TheLibrarian
Posted

I'd look at setting up auditing on the servers / drives.

 

Then when shares get hammered you know which account is responsible.

Posted

That's a good idea librarian cheers

 

Everyone else re. getting parents involved , the kid has 'special' circumstances, I'm not allowed to discipline them don't even know if the school are.

 

I'm not back in til' tuesday but had a call other day to let me know the kid had got the network admin password and changed it and had caused havoc on the server. Got the admin password back (by luck) and got things stabilized over the tellingbone.

 

Going to have a meeting with the head, to explain that to stop the fun and games I'm going to need to get round every machine, lock it down and add measures to the server. We're just going round in circles as is.

Posted (edited)
That's a good idea librarian cheers

 

Everyone else re. getting parents involved , the kid has 'special' circumstances, I'm not allowed to discipline them don't even know if the school are.

 

I'm not back in til' tuesday but had a call other day to let me know the kid had got the network admin password and changed it and had caused havoc on the server. Got the admin password back (by luck) and got things stabilized over the tellingbone.

 

Going to have a meeting with the head, to explain that to stop the fun and games I'm going to need to get round every machine, lock it down and add measures to the server. We're just going round in circles as is.

 

 

We have students here with 'special' circumstances BUT if they're breaking the law that's NOT an acceptable solution and not the schools call. It should certainly be bought to the attention of whoever is managing the 'special' case and told if it continues it will be a police matter.

If I had my data compromised (home address, salary, social security numbers, bank account number?) and I found out that a student had hacked the system and had been allowed to continue doing it after they were discovered I'd be pi55ed.

Edited by cookie_monster
Posted
Indeed it's frustrating, however I'm staying positive. I'm not a teacher I'm not allowed to discipline him, the teachers and head are well aware so it's up to them.

 

Says who? I issue students punishments if I catch them doing things they shouldn't. The last 3 students I caught trying to 'hack' the system had to write a 250 word essay on "The Computer Missuse act, and the consequenses if they got caught 'Hacking' "

 

Now I get regular e-mails from them in school when they find things not working, or discover a new flaw in the system - as a reward they get access to some of the games sites which are blocked for most of the rest of the school, but they are warned if I see them on them in lessons, it's back to square one - works quite well that arrangement does for the time being.

 

Mike.

Posted
That's a good idea librarian cheers

 

Everyone else re. getting parents involved , the kid has 'special' circumstances, I'm not allowed to discipline them don't even know if the school are.

 

I'm not back in til' tuesday but had a call other day to let me know the kid had got the network admin password and changed it and had caused havoc on the server. Got the admin password back (by luck) and got things stabilized over the tellingbone.

 

Going to have a meeting with the head, to explain that to stop the fun and games I'm going to need to get round every machine, lock it down and add measures to the server. We're just going round in circles as is.

 

If I were you, when the server breaks and nobody can do anything, I'd turn around to the head and tell him that due to 'special' circumstances, you are unable to fix it until a week on Friday (for example).

 

Why does it always take a disaster for people to wake up?

Posted
Getting stabbed most likely, this isn't a regular school I might add :p

 

If there is no consequence to their actions they will never learn that it is not acceptable to break the law. I am not saying that you need to discipline them, but if your SMT aren't willing to do anything for 1 problematic student your never going to get the support you need. However if your job entails ensuring the security of the network, I would start by ensuring he doesn't have access to it until you have increased the security settings and limited his account when his access is allowed again.

 

If you are not allowed to put security measures in place or are being undermined by you SMT then I would look at leaving and getting a new job elsewhere. I also think you need to document what has hapened as anything that the student does in the furture could be investigated as to why he had access to private information. You need to ensure that you have made recommendations but they were ignored and you were restricted in actions you could take.

 

And I would also be tempted to take the network down "for maintenance" until you can assess any "damage" that may have been caused by the student. Sometimes people just dont take things seriously until it's too late.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...