tuns8 Posted May 2, 2012 Posted May 2, 2012 Hi all! I have created a gpo to block students from running specific .exe's tested it works fine however done another test by renaming the .exe and it bypasses the gpo which a student can do if he or she finds out does anyone know of a way to prevent this from happening or is their another gpo im am missing Thanks guys!
Steve21 Posted May 2, 2012 Posted May 2, 2012 Depends on what you're running, but you'd want hash rules really. As you found out "path" rules, are exactly that, the path or nothing Steve
tuns8 Posted May 2, 2012 Author Posted May 2, 2012 Yes thats true however I think hash rules only works for windows application i.e notepad, regedit etc. sorry didnt explain properly I mean programs e.g. if a user downloads utorrent.exe from the internet sorry its a new school network lol
Steve21 Posted May 2, 2012 Posted May 2, 2012 Yes thats true however I think hash rules only works for windows application i.e notepad, regedit etc. sorry didnt explain properly I mean programs e.g. if a user downloads utorrent.exe from the internet sorry its a new school network lol Hashes should work on anything, just means new utorrent versions will have seperate hashes etc Steve 1
Arthur Posted May 2, 2012 Posted May 2, 2012 You could also block by publisher if you have AppLocker? For µTorrent that would be BitTorrent Inc. http://i.imgur.com/ZAtzZ.png 1
tuns8 Posted May 3, 2012 Author Posted May 3, 2012 Thanks Steve your right! mate I created a hash rule for utorrent and it works
Steve21 Posted May 3, 2012 Posted May 3, 2012 Thanks Steve your right! mate I created a hash rule for utorrent and it works Just remember a hash is for "an exe", If there's new versions it'll most likely change hash. So if you can do publisher blocks as Arthur said above, might be worth doing it Saves updating hashes etc. Steve
Stuart_C Posted May 3, 2012 Posted May 3, 2012 I've gone for using USB Drive LEtter Manager (DSBDLM) to restrict USB drives to certain drive letters. Then I use Group Policy Software Restriction policies to block all exe and exe type files from those drive letters.
Steve21 Posted May 3, 2012 Posted May 3, 2012 I've gone for using USB Drive LEtter Manager (DSBDLM) to restrict USB drives to certain drive letters. Then I use Group Policy Software Restriction policies to block all exe and exe type files from those drive letters. Won't they still run if they just copy it locally then? (Or is their homedrive etc blocked seperately) Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now