steveo2000 Posted December 18, 2009 Posted December 18, 2009 Does anyone have a suggestion for .exe files on a windows 2003 domain. The kids are bringing in proxy anonymizers on them and i'm finding it hard to keep up with new ones! Our usb drives can map to random drive letters so it their a way of just blocking ALL exe files unless its from drives I specify for students! Thanks All!
bossman Posted December 18, 2009 Posted December 18, 2009 @stevieo2000: Already been a thread on this check out: http://www.edugeek.net/forums/windows-server-2000-2003/26230-preventing-file-extensions-through-gpo.html Check out User3204 post. 1
Danlewis3 Posted December 18, 2009 Posted December 18, 2009 Some AV do it too, We use sophos and it supports USB blocking of extensions. But what's stopping the students putting the .exe into there area and running it from there?
3s-gtech Posted December 18, 2009 Posted December 18, 2009 File Server Resource Manager can stop that^^
Danlewis3 Posted December 18, 2009 Posted December 18, 2009 File Server Resource Manager can stop that^^ thats only if you have r2 isnt it
pritchardavid Posted December 18, 2009 Posted December 18, 2009 best way, which im gonna setup soon, is to enable the allowed program list, which means anything on this list, they will not be able to run it So you will need to make a list of all the allowed programes on that, and it will stop them, installing & running programes you dont want them to use
chrisredfield93 Posted December 21, 2009 Posted December 21, 2009 best way, which im gonna setup soon, is to enable the allowed program list, which means anything on this list, they will not be able to run it So you will need to make a list of all the allowed programes on that, and it will stop them, installing & running programes you dont want them to use This be intresting keep us updated and how are you planning on doing this client and server based? like abtutor, is this be going by process name or titlebar? etc
Danlewis3 Posted December 21, 2009 Posted December 21, 2009 This be intresting keep us updated and how are you planning on doing this client and server based? like abtutor, is this be going by process name or titlebar? etc Its done via GPO, you'd set it on the OU with all the computers that the students use and then its done on process name. If the students are clever they can renamed there .exe on the memory stick to reflect an ok program and that will let it run though.
joe90bass Posted December 21, 2009 Posted December 21, 2009 best way, which im gonna setup soon, is to enable the allowed program list, which means anything on this list, they will not be able to run it So you will need to make a list of all the allowed programes on that, and it will stop them, installing & running programes you dont want them to use Good luck! I tried it a few years back, it takes a lot of setting up! There's normally more than one exe per program and they're not always in the same folder as the main program.... I ran with it for a while, but can't remember why I took it off.... Probably never got it right!
pritchardavid Posted December 21, 2009 Posted December 21, 2009 Dont think it will take that long to setup We havent got that many programes on the network anymore Been doing some maintance, got rid of all the software that dont get used any more, we havent havent got that much anymore gladly Question if I enable this, will I also have to put on the allowed list stuff like .doc, docx, swf, etc so they can run those questions? Or can I get away with swf? Will it be able to lanch throught internet explorer only and not from there memory sticks? Lol god know why im on this forum doing work stuff, hense im on my christmas holdiays now, bored already
pritchardavid Posted December 21, 2009 Posted December 21, 2009 Its done via GPO, you'd set it on the OU with all the computers that the students use and then its done on process name. If the students are clever they can renamed there .exe on the memory stick to reflect an ok program and that will let it run though. Not nessery, you can put in the file path cant you (Cant rembrer without looking) So that will stop that If not I doubt the students will know about renameing their exe to an allowed exe name (If they even know an allowed exe name)
GoldenWonder Posted December 21, 2009 Posted December 21, 2009 I did this with Software Restriction policies some time ago and its worked really well. Plan ahead and make sure you've got a good like of your networked applications. I made ours a whitelist unblocked C:\program files and c:\windows etc which meant most legitimate applications installed by us were ok. Watch out for SYSVOL and NETLOGON shares, as these will need to be allowed as well to run login scripts etc. Some apps are a pain as they create a file in the users application data folder and try and run it from there - once you know the app name though you can unblock it for any path.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now