Grommit Posted September 29, 2006 Posted September 29, 2006 Dunno where this goes .. sorry.. OK our little kiddies have this bat file to bypass the start up of Ranger net stop "Ranger Security Monitor" net stop "Ranger Network Client" taskkill /F /IM Rangertoolbar.exe How can this be stopped ? as blocking bat files would stop the logon scripts running to map the drives ? Any ideas
Geoff Posted September 29, 2006 Posted September 29, 2006 How about blocking access to the 'net' and 'taskkill' commands? You might also want to stop them from running programs from their area with TrustNoExe. It'll work for USB drives, etc too. http://www.beyondlogic.org/consulting/trust-no-exe/trust-no-exe.htm
plexer Posted September 29, 2006 Posted September 29, 2006 use vbs instead for your drive mappings? Ben
Grommit Posted September 29, 2006 Author Posted September 29, 2006 Dunno where this goes .. sorry.. OK our little kiddies have this bat file to bypass the start up of Ranger net stop "Ranger Security Monitor" net stop "Ranger Network Client" taskkill /F /IM Rangertoolbar.exe How can this be stopped ? as blocking bat files would stop the logon scripts running to map the drives ? Any ideas Is there a way to stop it being loaded at start up ? as a staff member is running it within environment variables.. and i don't want him to know i know and block them
ITWombat Posted September 29, 2006 Posted September 29, 2006 Eh? students shouldn't be able to affect services.
Grommit Posted September 30, 2006 Author Posted September 30, 2006 Eh? students shouldn't be able to affect services. Nah..its a member of the technical staff.. i don't want him to know that I know that he knows that a bat file can kill ranger Is there a way of forcing Ranger through ?
ZeroHour Posted September 30, 2006 Posted September 30, 2006 group policy is your friend it has built in protection if enabled which blocks execution of file types from locations if you want (aka there my docs or mem sticks) Not at work so cant remember all the details but the little kiddies here cant run jack unless its from a location we specify.
ITWombat Posted September 30, 2006 Posted September 30, 2006 .. i don't want him to know that I know that he knows that a bat file can kill ranger LOL sound's like the geek episode of Friends. As ZeroHours says you can use GPO to control which executables are run. The normal way is to set path rules in a Software Restriction Policy (SRP). But you are on hiding to nothing because the above assumes that someone can't put new files in the allowed folders or substitute standard executables for others with the same name. If this 'colleague' of yours has local admin rights what's to stop him from booting into safe mode and changing the Ranger services to manual start rather than automatic. He can aslo remove the RangerToolbar executable form the run key or just move it out of it's expected path. Basically just acquaint your colleague with his job description and the school's AUP. Just thank your stars it wasn't a student /me shivers
plexer Posted September 30, 2006 Posted September 30, 2006 OK our little kiddies have this bat file to bypass the start up of Ranger You said it was the kiddies then changed it to a member of staff. I think you should just beat him over the head with the aup just because he's a member of staff doesn't change things. Ben
ITWombat Posted September 30, 2006 Posted September 30, 2006 use vbs instead for your drive mappings? Ben This assunmes that kids will never workout how to wirte vbs scripts. "Domain Users", SRP and ACLs. It's the only way..
Grommit Posted September 30, 2006 Author Posted September 30, 2006 OK our little kiddies have this bat file to bypass the start up of Ranger You said it was the kiddies then changed it to a member of staff. I think you should just beat him over the head with the aup just because he's a member of staff doesn't change things. Ben Sorry I thought it was a kiddie.. but on investigation it turned out to be be a junior member of the Technical team ...
Sylv3r Posted September 30, 2006 Posted September 30, 2006 What reason is this Junior Technician wanting to remove the startup of Ranger anyway? Surely with him being a member of staff he must recognise that he has a duty to work and follow instructions from Senior Technician, Network Manager etc. If you are his senior why can't you just tell him to stop using the script why do you want to keep it such a secret from him that you are blocking it? As previous people have said, a copy of the staff AUP will come in handy here if you have one in place.
Geoff Posted September 30, 2006 Posted September 30, 2006 Oh dear. This thread is a good starting point. Has lots of useful links on the subject. http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=152 Also check the wiki http://www.russdev.com/edugeek/doku.php?id=aup_s
plexer Posted September 30, 2006 Posted September 30, 2006 Acceptable Use(age) Policy basically a document that the users agree too which outlines what they can and can't do on the system and the Internet. Ben
alonebfg Posted September 30, 2006 Posted September 30, 2006 i love aup we have not got one at the moment but i have put one in place and have upset a lot of people but i have got some backing.
Joedetic Posted October 1, 2006 Posted October 1, 2006 If this junior member of the ICT Services team is VI Former, just take away his admin access for a while and tell him that he's relegated to putting paper in printers and changing toner etc. If you really wanted to you could interpret his use of said batch file as an abuse of power. Clearly he's not using the access rights for what they were given to him for if he's got time to sit and play about with blocking ranger when he's meant to be working for ICT services! Sod the AUP...how's about an "if you're not doing what you're meant to be doing go home/sit in the common room" policy?
Andrew_C Posted October 1, 2006 Posted October 1, 2006 Acceptable User Policy. You do have one, don't you??
alan-d Posted October 2, 2006 Posted October 2, 2006 Slap him and remove all access rights - send him on printer and keyboard cleaning duties and any other long dirty task not involving the use of a PC.
Joedetic Posted October 2, 2006 Posted October 2, 2006 What makes a really horrid job is cleaning brick dust out of servers and switches etc. He'd have fun doing that. But of course...if there isnt any already in there then it's not recommended to add it to the mix I remember when we had some comms guys come to move the internet line to our server room...they didnt put a dust sheet over the servers and drilled through the wall right behind the main data cab. I was the smallest person in ICT Services at the time (but at 6' 2" I was possibly tallest!) so i was sent behind the server cab to vaccum dust...fun fun fun, I THINK NOT! I should probably just re-emphasise that although i was the VI Form techie, it was just because i could fit behind the cab and not because i'd been abusing my power LOL.
john Posted October 3, 2006 Posted October 3, 2006 You see being tall and slim has its advantages we can fit in amazingly small spaces and can generally be more flexible than more "enhanced" people.
Joedetic Posted October 3, 2006 Posted October 3, 2006 ROFL... "enhanced." Are we more diplomatic too?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now