Jump to content

Recommended Posts

Posted

Hi all,

 

Just seen that users can create shortcuts to network locations, e.g. on their desktop, right click, new shortcut and "\\dc1\netlogon".

They can then browse this folder in explorer.

 

Also if they knew the path they could browse to a new hidden mapped drive that I have setup for them, "\\server\resourses$".

They need read permissions on this folder but tese files are only to be opened from the intranet.

 

Just also see that they can also create a shortcut to "C:\" if they like???

 

Have I missed a big step in security here?

 

Thanks in advance!

Posted

You will need to disable the run command

 

User Configuration\Administrative Templates\Start Menu & Taskbar

 

its called something like remove run from start menu and it actually blocks unc paths i think

Posted

Have I missed a big step in security here?

 

I wouldn't worry about it. chances are they could plug in a mac/linux pc and see these shares anyway (without knowing the path)

(btw if you really want to hide shares, use SAMBA instead).

As long as the file permissions are set correctly you should be good to go. Let the kids explore as long as they can't do any harm

Posted
You will need to disable the run command

 

User Configuration\Administrative Templates\Start Menu & Taskbar

its called something like remove run from start menu and it actually blocks unc paths i think

 

Thanks for the replys, Run is already disbaled. If they try and type in the address they are not allowed, but for some reason creating a shortcut to it works?

 

We have an applications share that is hidden, the start menu links to it for certain applications, I dont want the students to be able to create a shortcut to it in the "Music" room and use applications that are meant for ICT lessons.

 

Does anyone please know how to disbale shortcut method please?

Posted

Creating shortcuts on the desktop: Are you redirecting your desktop? If so is the folder that contains your redirected desktop items read only to your students?

 

Access to/seeing the C: drive: There is a GPO setting that hides the C: drive to users. I am sure someone here will post it. If not I will have a look at our GPOs find it and post it tomorrow.

 

Creating shortcuts and saving them in My Documents [Network Home Folder] I have deployed FSRM [File Server Resources Manager] using this I can specify allowed/banned file types and disk space usage. Its a godsend.

Posted
Creating shortcuts on the desktop: Are you redirecting your desktop? If so is the folder that contains your redirected desktop items read only to your students?

 

Access to/seeing the C: drive: There is a GPO setting that hides the C: drive to users. I am sure someone here will post it. If not I will have a look at our GPOs find it and post it tomorrow.

 

Creating shortcuts and saving them in My Documents [Network Home Folder] I have deployed FSRM [File Server Resources Manager] using this I can specify allowed/banned file types and disk space usage. Its a godsend.

 

Hi dave,

We have the C drive hidden and restricted. We also have fsrm running on home drives. Students have a shared read only desktop but staff have a roaming desktop. This is the only place I've seen where it's possible to create shortened but I would like to stop it everywhere incase I have missed somewhere.

 

Can someone please try and create a shortcut to C:\ and see if they are stopped creating it or stopped browsing it after ??

If so how please!!

Posted

What O/S is on your PCs?

 

I ask because experimenting with the redirected staff desktop I find that I can add/delete items from the, theoretically, read only staff desktop on Windows 7. We had no such problem on XP.

 

I must say though that I haven't finished the Desktop/Start Menu redirection yet as under testing it works then it doesn't, then it works,...

 

:mad2:

Posted
What O/S is on your PCs?

 

I ask because experimenting with the redirected staff desktop I find that I can add/delete items from the, theoretically, read only staff desktop on Windows 7. We had no such problem on XP.

 

I must say though that I haven't finished the Desktop/Start Menu redirection yet as under testing it works then it doesn't, then it works,...

 

:mad2:

 

Hi dave,

This happens on both xp/vista/w7 but in w7 the shortcut needs to be run as admin......

 

I did play with list contents permission but it seems to cause all sorts of problems with the not so well coded educational apps.

 

I have hidden everything in netlogon but still there must be a way to stop this.

Posted

Disable right click on desktop.

 

Also are your shares done like this DC1\Netlogon\Username$?

 

If so, throw this in the mix

 

DC\Netlogon$ (hides the original folder as well)

 

Ideally you should be using samba though to truly hide shares, and also as Dave said there is a GPO that will allow you to hide the C:\ and any other drive you specify! :)

Posted (edited)

Thanks for the replies,

 

I dont think I am explaining the loophole clearly...

 

See screenshots.. C drive and hidden network shares (R & P) and restricted and do not allow access using GP.

As you can see from the GP screenshot1. They do not ever show in my computer and deny access (screenshot2)

If you try and browse to C or P or R you are not allowed (see screenshot2) "Acess to the resources XXX has been disallowed"

 

BUT there is a loophole.. If staff who have a roaming desktop right click and create shortcut, they can then open that shortcut and get into these dissallowed and hidden areas. (Screenshot2) You can see that opening the shortcut has given access to the C drive.

 

If they knew the names of the other hidden shares they could also browse any of these that they have permissions to.

Run is also disabled from the start menu.

Students currently cannot do this as they have a fixed desktop.

 

Can anyone else please test on there system?

I am hoping that there is a way that when they open a shortcut they have made to, eg. "\\dc1\netlogon" they get the "Acess to the resources XXX has been disallowed" (screenshot2)

 

Many thanks in advance.

Cdrive.jpg

demo.jpg

Edited by burgemaster
Posted

If you are explicitly giving people permission to read a share it isn't a loophole or a security problem if they can get to that share.

If you want to fix it either change the share permissions or add an ACL on your switches. there isn't much point in what you are trying to achieve, it's security through obscurity - as soon as you disable right click you'll find another 'hole' that users create a link through word or some other software, or plug in an unrestricted computer. Fix the file permission to the 'disallowed' shares.

Posted
If you are explicitly giving people permission to read a share it isn't a loophole or a security problem if they can get to that share.

If you want to fix it either change the share permissions or add an ACL on your switches. there isn't much point in what you are trying to achieve, it's security through obscurity - as soon as you disable right click you'll find another 'hole' that users create a link through word or some other software, or plug in an unrestricted computer. Fix the file permission to the 'disallowed' shares.

 

They do need access to these shares, I will look at NTFS security changes, are you saying that staff can also do this on your network? Thanks for your reply.

 

Those drives are "hidden" not set to "hide and deny access"...

 

They do need access to folders with these shares, they might be applications etc. but I do NOT want them to browse through them all.

 

 

Take a look at SRP as you could restrict lnk files in the areas where the user can write and that should block them.

Cheers mate, I looked at this, not sure what effect it would have as their desktops are part of their roaming profile. That will sort the shortucts, but as cybernerd said they might be able to just create shortcut in Word and view the share that way.... Can they do this on your network?

 

I have hidden all the folders in the P: Applications share and Netlogon, not an ideal solution.. Will look at NTFS permissions.

Posted
They do need access to these shares, I will look at NTFS security changes, are you saying that staff can also do this on your network? Thanks for your reply.

 

 

yes. If staff or students really wanted to they can create a hyperlink in word and read the entire contents of our netlogon shares, there's probably a hundred other bits of software floating around that can do it too. About the worst thing that I think could happen (and correct me if i'm wrong) is that they could fill up their home drives if they decided to copy it all. not really a big deal IMO.

Remember 'hidden' shares in windows are NOT a security feature, it's just to tidy things up.

Perhaps you could deny groups of computers (rather than users) accessing the shares?

We firewall non-domain machines from accessing certain shares.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...