Jump to content

Recommended Posts

Posted
If you are not allowed to put security measures in place or are being undermined by you SMT then I would look at leaving and getting a new job elsewhere. I also think you need to document what has hapened as anything that the student does in the furture could be investigated as to why he had access to private information. You need to ensure that you have made recommendations but they were ignored and you were restricted in actions you could take.

 

 

I would agree with the above, cover your back as you can be certain that when the time comes no one on SMT will step forward to cover it for you "they thought you had it all under control"

Also if their dangerous ignorance of the dangers continues I’d make a full report of your ignored recommendations and send it to the governors and the LEA. Shortly before leaving of course ;)

Posted
Stupid idea probably, but what about shutting the server down at school closure tonight and switching it back on monday morn? Unless of course it's a 'school' without weekends. Wouldn't that lessen the immediate risk and give you some breathing space?
Posted

I'm keen to know how he's using the local admin account he's made to mess with the shared folders too.

 

Just ran some quick tests:

 

Presumably you have set Authenticated Users or Administrators to Full Control in the share permissions?

 

You need to remove both of those groups and specify others such as Domain Admins, and the specific user groups defined in your AD; students, teachers etc.

Posted
he's either used a boot tool or somehow obtained an admin password.

 

Other than locking down boot devices in BIOS, I would disable their access to unnecessary drives wherever possible through group policy and by physically unplugging any optical or floppy drives. When the BIOS battery on some of our computers die, a lot of the settings are returned to factory defaults including installed drives and boot order.

 

Also, investigate software restrictions on USB drives, using USBDLM to fix the assigned drive letter(s).

 

Check all of your computers for keyloggers plugged in between the keyboard and socket on the computer.

Posted

Not sure if this has been mentioned already but is there not some way to make it remove administrator rights from users who have not been specified those rights ie

 

specified administrators ( whether the accounts have been renamed ie supervisor or something else )

 

user 1

user 2

 

non specified administrator users

 

user 3

 

when user 3 logs on or the computer reboots or whenever the relevant group policy(s) apply it should remove user 3 from the administrator or relevant groups so as to take away those privileges ??

 

Is that apart of the restricted users thing mentioned above ?

Posted
Is that apart of the restricted users thing mentioned above ?

 

Yeah it is - another thing you should double check is that your Local Admin account does NOT have the same password as your Domain Admin account.

 

This is another way he could have potentially messed around with shares and NTFS permissions on the network - however in order to get that password, he'd either have to guess it, crack it or somehow take control of the account itself without a password change.

 

I've never heard of anything except perhaps an NT Service able to run-as an account without the need for the password (SYSTEM, NETWORK SERVICE, LOCAL SERVICE).

 

However that 'Do not store NTLM hashes' thing noted above sounds good - can't believe I overlooked it before now - will be turning that one on.

 

Az

Posted
I've never heard of anything except perhaps an NT Service able to run-as an account without the need for the password (SYSTEM, NETWORK SERVICE, LOCAL SERVICE).

 

 

They all still have a password but the password is managed by Windows.

Posted

Since changing the network password I've not heard a whisper, checked the kids docs again today he's got a few scripts for website cracking, injectors etc.

 

I'm concerned the restricted groups gpo hasn't worked though, I put it into place last week and logged onto a computer today and there was definiteley more than local groups that the one I specified.

Posted
Just ran some quick tests:

 

Presumably you have set Authenticated Users or Administrators to Full Control in the share permissions?

 

You need to remove both of those groups and specify others such as Domain Admins, and the specific user groups defined in your AD; students, teachers etc.

Yes you're right, I thought it was the ntfs perms that locked it down though?

What's your thinking?

Posted
Yes you're right, I thought it was the ntfs perms that locked it down though?

What's your thinking?

 

Maybe that is what he ment?

 

We have the share permissions set to Everyone 'Full Control' here then the folders NTFS permissions lock it down.

Posted
Maybe that is what he ment?

 

We have the share permissions set to Everyone 'Full Control' here then the folders NTFS permissions lock it down.

 

Yeah, I just want to make sure though.

Curretnyl I have the share perms, authenticated users full control and the ntfs perms are locked down to the correct security groups/users

Posted
Thanks for the above, I wasn't aware of the restricted groups setting I'll look into it and get it enforced. I'll nip round as many vulnerable stations as possible to alter the bios settings too (was hoping I could avoid that!)...
Most brands like dell have software packages so that you can remotely monitor/alter bios on client machines these days :wink:
Posted
Since changing the network password I've not heard a whisper, checked the kids docs again today he's got a few scripts for website cracking, injectors etc.

 

I'm concerned the restricted groups gpo hasn't worked though, I put it into place last week and logged onto a computer today and there was definiteley more than local groups that the one I specified.

 

 

I only manage the local administrators group to do that you need to open the GPO click add group and either browse for the local group or type it exactly, it should be the name of the local computer group so Administrators for 'Group Name', then add any domain groups that you want e.g. 'Domain\Domain Admins', 'Domain\ITSupport' AND you must name local users as well so 'Administrator' or the new name if you rename the local admin any accounts not listed will be removed.

The policy also needs to be a machine policy attached to an OU containing the computers you wish it to manage.

Posted
Most brands like dell have software packages so that you can remotely monitor/alter bios on client machines these days :wink:

 

Does the machine need vPro support (is there an AMD equivalent?) to do this?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...