Kcrowe Posted March 2, 2012 Posted March 2, 2012 Hi all, I have found a bit of a loop hole in regards to using Microsoft Office 2003 to navigate through the network to a shares such as Netlogon on the Server. A knowledgeable staff member or pupil could potentially navigate through the 'entire network' or even (having knowledge of the server name) use a hyperlink to get access to potentially dangerous folders. Does anyone have any ideas how this might be locked down? I have had a look through group policy and the MS Office ADM templates to see if there is a solution there but I haven't found anything. Thanks in Advance!!! Kieran.
6Foot2 Posted March 2, 2012 Posted March 2, 2012 A similar question came up yesterday. Link 1: http://www.edugeek.net/forums/windows/91228-stop-students-using-folder-up-xp.html I think the answer that @FN-GM gave will solve the problem: Link 2: http://www.edugeek.net/forums/windows/91228-stop-students-using-folder-up-xp.html#post797516
Kcrowe Posted March 2, 2012 Author Posted March 2, 2012 The suggestion to ensure the correct permissions are implemented to any network folders is valid it doesn't resolve the problem for Netlogon, which is set for student to have read access. The problem is that someone could potentially look at scripts that may be in the netlogon folder, and use any information gained to cause havoc on a network. It just seems to be an oversight within Office '03 that should have a work around to lock it down completely? Thanks for the response and suggestion though!
FN-GM Posted March 2, 2012 Posted March 2, 2012 The suggestion to ensure the correct permissions are implemented to any network folders is valid it doesn't resolve the problem for Netlogon, which is set for student to have read access. The problem is that someone could potentially look at scripts that may be in the netlogon folder, and use any information gained to cause havoc on a network. It just seems to be an oversight within Office '03 that should have a work around to lock it down completely? Thanks for the response and suggestion though! Well you shouldnt store any info like that in scripts. But if you do put it in another folder and set the parent folder so they dont have access but do have access to run stuff in sub folders. Problem solved.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now