dave20046
Members-
Posts
59 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by dave20046
-
Yeah, I just want to make sure though. Curretnyl I have the share perms, authenticated users full control and the ntfs perms are locked down to the correct security groups/users
-
Yes you're right, I thought it was the ntfs perms that locked it down though? What's your thinking?
-
Since changing the network password I've not heard a whisper, checked the kids docs again today he's got a few scripts for website cracking, injectors etc. I'm concerned the restricted groups gpo hasn't worked though, I put it into place last week and logged onto a computer today and there was definiteley more than local groups that the one I specified.
-
Getting stabbed most likely, this isn't a regular school I might add
-
Depending on the set up of your system (i.e if it's just pupils and staff you want to block from using rdp) you'll probably have the groups of users in relevant ou's already, if not do it. You can then apply a policy to the groups and block remote desktop (as said above, mstsc)
-
That's a good idea librarian cheers Everyone else re. getting parents involved , the kid has 'special' circumstances, I'm not allowed to discipline them don't even know if the school are. I'm not back in til' tuesday but had a call other day to let me know the kid had got the network admin password and changed it and had caused havoc on the server. Got the admin password back (by luck) and got things stabilized over the tellingbone. Going to have a meeting with the head, to explain that to stop the fun and games I'm going to need to get round every machine, lock it down and add measures to the server. We're just going round in circles as is.
-
True, I've applied that GPO now however it doesn't seem to have changed the username:confused: What he's actually done to the network folders is removed rights, he stripped all the users of rights to their own my documents (folder redirected). Only an administrator could have done that...
-
Indeed it's frustrating, however I'm staying positive. I'm not a teacher I'm not allowed to discipline him, the teachers and head are well aware so it's up to them. My main priority's getting stuff back on track and blocking him out, interesting episode too. Thanks for your help michael, just renaming the admin now. PS: I hadn't changed the admin account name previously as I thought it was pointless as the SID doesn't change for the account and they don't have the password. I take it I'm wrong just wondering if you know why though?
-
Thanks for the above, I wasn't aware of the restricted groups setting I'll look into it and get it enforced. I'll nip round as many vulnerable stations as possible to alter the bios settings too (was hoping I could avoid that!) . Could you tell me where the 'do not store lan manager' value can be found? I've had a chat with the pupil All I could really say was 'don't be distructive it's pointless' he told me the machines he'd added the extra user account to and refused to give me much more information. He reckoned he could get on remotely from home and he reckoned he was using tools that automatically cleared the logs. He also reckoned his mate who works for the MOD would be launching a dos attack at 15.05 today. It's just trying to determine the truth... I'm keen to know how he's using the local admin account he's made to mess with the shared folders too.
-
Sorry, forgot to add; the client machines are all XP. Pupils have command prompt blocked and haven't many priveledges.
-
Right I'll ignore most of your sniggers at the title, but I've got an 'awkward' pupil just after some tips. The kid's managed to successfully hack the network and change security rights on shared folders, how he's doing it I'm not entirely sure, he's either used a boot tool or somehow obtained an admin password. What he has managed to do is create local admin accounts on machines, I really reckon he's used a boot tool actually (the admin accounts he's set up are named 'adm' if it's of any significance). Now firstly is there anyway of stopping him messing with the local admin passwords, I'm thinking the chances are slim. Secondly (mainly) how is he utilizing the local admin account to mess with the servers and how do I block him? I thought to do anything to files on the server he'd be prompted to enter network credentials upon connecting. Help anyone?
-
Folder Redirection - Not working apparently at random
dave20046 replied to dave20046's topic in Windows Server 2000/2003
Thanks for your replies everyone, tried all of the above with no joy (apart from the client profile deletion which I'll give a shot tomorrow) The event viewer has some errors but I'll have to post them when I get back to work tomorrow. As a temporary fix I've been right clicking my documents for users and entering the correct path which gets the heat off for a bit. Doing a group policy results for the client and a logon also displays an issue with group policy but it seems to point towards permissions if I recall correctly but as users appear to work sometimes and not at others I'm thinking it's safe to rule permissions out as they would stay consistent. cheers again for the posts. -
Hi We've just setup a new server at our school, the rest of the network has stayed exactly the same but the DC(domain contoller) has had a new install of windows 2003 std. . I've rebuilt the active directory and group policies from fresh, all done properly (no cut corners). I've set up folder redirection with the advanced setting where by it is controlled by the groups, which affects where it redirects their documents to. All appeared to be working fine until staff tried logging into different machines (i.e not their everyday one). My documents appears blank. If I check the path on the blank my documents folders it's still looking at the c:\ as aposed to the correct shared folder path on the server. Appears to be happening randomly on different machines and different users, there seems to be no pattern. On a machine that successfully redirected one staff's my docs, when logged in as another staff it may not. Any ideas would be much appreciated! Thanks
-
cheers timzim I've done a search for ccsfms and it's uncovered lots of files so it looks like I am using he same sql
-
Thanks for that unfortunately it looks like I don't have the SA username and password "sql server does not exist or access denied"
-
I've also just noticed another fmsconnect.ini file is also stored in d:\simsroot\sims
-
Yes I know the SA password. There doesn't look to be the connect.ini file in the sims program files' folder but the way we have the simsroot mapped to the machines is by having a shared filed 'simsroot' on the D:. Inside simroot\sims there is a connect.ini file which reads: [sIMSConnection] ServerName=simsserver\SIMS DatabaseName=SIMS
-
I'm not sure I might try removing one fo the 2s and retrying I'm really not sure I'm new to this school, the servers are a mess, and I haven't really had to touch sims before, do you know how I could find out?
-
Thanks for your replies I'm trying to use solus update on the simsserver for the fms module but upon login I get the reason 0 problem. I've found my fmsconnect.ini file and it reads: [FMSConnection] Server=simsserver\FMS22005 Database=ccsfms Trusted_Connection=No Does this make sense to anyone, looks like it's missing something to me:confused: Also the bursar reckons the icon sims wanted me to put on the desktop was to back up the fms database to the server.
-
cheers I'll get those checked
-
Sims have been leaving messages at the school for a while now but they keep missing me and messages don't get relayed properly so I've rung them up today to be told I need to put an Icon on the bursers desktop that points at the server and I need to upgrade. They wouldn't give me any more info than that as they are useless. I've tried upgrading but I just get 'connection failed reason 0' and I haven't a clue what she meant by an icon that points at the server and neither did she apparently. Can anyone offer any wisdom? Cheers
-
cheers rush tec - a job for tomorrow now
-
Next problem; it's telling me the username and password supplied are invalid. grr
-
Thankyou! I just started the browser even though the server wasn't running and it showed me exactly what was causing it. I'm running spice works. Brilliant, now I can continue setting the thing up!
-
Hi cheers for your fast replies, yes I've configured the proxy and entered a username & password for it supplied by the council team. Some days it'll start some days it won't
