Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

pcstru

Members
  • Posts

    5,998
  • Joined

Everything posted by pcstru

  1. Perhaps I don't understand then. I thought schools could use the API reasonably freely so the licence to use the BO with your code was effectively with the school (and your licence to use the BO in development was presumably with your support unit). So I can see why with a change of job you no longer have access to the licensed facilities you need to develop the code. I don't see how that affects distribution of source code or object code you have previously compiled.
  2. So did the licence allow someone else to host it? If a few commercial companies can give it away, presumably anyone can?
  3. We now use Xibo with Android dongles running a client. There is a licence cost for each client but the overall cost is ~£80 per screen and we avoid cabling costs.
  4. We run NRS over a dedicated VLAN; I can't recall if that is their advice or not but it should be reasonably secure if that is recommended as part of the setup. I think the main reason Impero got slammed wasn't the fact of a security issue but rather the way they dealt with disclosure and the resolution. On the question of why these companies charge so much. The largest single cost for a business is generally staff. The engineers, sales, support etc are employed whether they are out earning or not. Equipment is sold in low volume so a higher mark-up compared to retail or consumer kit is not unreasonable. The companies probably pay their engineers a decent wage which might be a surprise to many who work in schools but which should be a good thing. A service like NRS offer requires quite a wide skill set since they cover everything from embedded components through OS though software development on multiple platforms. The service covers all aspects from pre-sales consultancy to having an engineer attend site at reasonably short notice regardless of the problem. You need quite a lot of people to do all that and deliver a reliable, consistent service that meets the contractual SLA you have with customers. Compared to something like Impero which is roughly the same annual cost for us but which is just software support (with documented periods where they can't respond to an email next day let alone have someone on site), I'd have to consider NRS to be reasonable value.
  5. Velcro.
  6. Same here. We have a number of support contracts for specific systems (surely everyone has a support contract for their MIS system!) but we do not contract out support generally. Even where we do have some external support, we tend to be the first point of contact so often enough we know what the solution is or can solve it quicker than it takes to call it in. We do have an agreement with a local networking company which gives us good rates on cabling, a bit of telephone support (I think up to 10 hours a year) and substantially reduced rates if we need to call them out. On the few occasions when we have had to call on it, the problems are generally so 'difficult' that there is a reasonable chance they will be stumped.
  7. Pot of yoghurt carefully poured (spooned) into a PC via the cooling slots on top.
  8. You might just want to ensure that such an upgrade can be done within the contract and does not require beginning another 1,3 or 5 year term. Ensure this is on an SLA and regularly tested. We tested ours when commissioning but it failed sometime in the 14 months between then and when it was actually needed.
  9. Trying to do exactly that I find it is not available on my local client machine. I admit we are not in any sense living on the bleeding edge. I prefer others to have the fun of that!
  10. pcstru

    My C issues

    I suspect jwinters is alluding to the fact that floats are problematic at either extreme (measuring very small values or measuring very large values) and in combination, (arithmetic in which both extremes are involved) floats can be hugely imprecise. So, you would never want to model financial transactions using floats.
  11. heh.To be fair, I put my AD scripts together a few years ago (~4) and sometimes it's just the quickest thing to work that gets the job. Was the Smbshare stuff actually available back then?
  12. I did see some lockers at BETT which can be operated by swipe/nfc card and probably biometrics that were supposedly for that purpose. Couldn't see it working well myself. We do loan laptops and if we weren't checking then at the point of return, I think we would see unsustainable levels of damage.
  13. I've posted most of the relevant code in the coding forum in one form or another, but the example DB pulls will be for the CMIS database. The actual code is unfortunately quite closely coupled to the way we do things (how we code tutor groups etc and how that is all processed into OU's, server paths etc). Not sure I could justify abstracting it so that it is generally usable (and easy to use).
  14. I'm obviously becoming too programmed by powershell and neglecting sometimes simpler, more elegant solutions. A bit like as they say, when all you have is a hammer, every problem looks like a nail!
  15. Very neat solution.
  16. No the first bit of code was a function. The whole thing would be : $fileserver = "" # Set for your situation $ServBase = "D:\users" # '' # --------------------------------------------------------------------------- # Create a share on the (presumed) remote fileserver and set full control # to everyone (control access via folder permissions) # --------------------------------------------------------------------------- function CreateShare2 { # cribbed from # http://social.technet.microsoft.com/Forums/scriptcenter/en-US/6aa558a6-f8b4-4cb5-bbb3-76eec9805681/powershell-remote-server-set-share-permissions-to-everyone-full-control Param ([string]$UserName, [string]$Target ) $Computer = $fileserver $Class = "Win32_Share" $Method = "Create" $name = "$UserName`$" $path = $ServBase + $UserName $description = "AutoCreated" $sd = ([WMIClass] "\\$Computer\root\cimv2:Win32_SecurityDescriptor").CreateInstance() $ACE = ([WMIClass] "\\$Computer\root\cimv2:Win32_ACE").CreateInstance() $Trustee = ([WMIClass] "\\$Computer\root\cimv2:Win32_Trustee").CreateInstance() $Trustee.Name = "EVERYONE" $Trustee.Domain = $Null $Trustee.SID = @(1, 1, 0, 0, 0, 0, 0, 1, 0, 0, 0, 0) $ace.AccessMask = 2032127 $ace.AceFlags = 3 $ace.AceType = 0 $ACE.Trustee = $Trustee $sd.DACL += $ACE.psObject.baseobject $mc = [WmiClass]"\\$Computer\ROOT\CIMV2:$Class" $InParams = $mc.psbase.GetMethodParameters($Method) $InParams.Access = $sd $InParams.Description = $description $InParams.MaximumAllowed = $Null $InParams.Name = $name $InParams.Password = $Null $InParams.Path = $path $InParams.Type = [uint32]0 $R = $mc.PSBase.InvokeMethod($Method, $InParams, $Null) switch ($($R.ReturnValue)) { 0 {$ret="Share:$name Path:$path Result:Success"; break} 2 {$ret="Share:$name Path:$path Result:Access Denied";break} 8 {$ret="Share:$name Path:$path Result:Unknown Failure";break} 9 {$ret="Share:$name Path:$path Result:Invalid Name";break} 10 {$ret="Share:$name Path:$path Result:Invalid Level";break} 21 {$ret="Share:$name Path:$path Result:Invalid Parameter";break} 22 {$ret="Share:$name Path:$path Result:Duplicate Share";break} 23 {$ret="Share:$name Path:$path Result:Reedirected Path";break} 24 {$ret="Share:$name Path:$path Result:Unknown Device or Directory";break} 25 {$ret="Share:$name Path:$path Result:Network Name Not Found";break} default {$ret="Share:$name Path:$path Result:*** Unknown Error ***";break} } $ret } # --------------------------------------------------------------------------- $infile = import-csv "" foreach $user in $infile { CreateShare2 $user.username "" } You can hard code "target" if they are all the same path on the server (target is the path as seen from the server). Your CSV would then just be the list of users.
  17. Sorry, I didn't supply the complete code you need so no, that is not there! It will just be a loop, something like : $infile = import-csv "" foreach $user in $infile { CreateShare2 $user.username "" } (sorry, am typing this in away from my main PC so can't actually test at the moment).
  18. You can do it in powershell. The function I have for creating shares : $fileserver = "OurServer" $ServBase = "D:\users" # --------------------------------------------------------------------------- # Create a share on the (presumed) remote fileserver and set full control # to everyone (control access via folder permissions) # --------------------------------------------------------------------------- function CreateShare2 { # cribbed from # http://social.technet.microsoft.com/Forums/scriptcenter/en-US/6aa558a6-f8b4-4cb5-bbb3-76eec9805681/powershell-remote-server-set-share-permissions-to-everyone-full-control Param ([string]$UserName, [string]$Target ) $Computer = $fileserver $Class = "Win32_Share" $Method = "Create" $name = "$UserName`$" $path = $ServBase + $UserName $description = "AutoCreated" $sd = ([WMIClass] "\\$Computer\root\cimv2:Win32_SecurityDescriptor").CreateInstance() $ACE = ([WMIClass] "\\$Computer\root\cimv2:Win32_ACE").CreateInstance() $Trustee = ([WMIClass] "\\$Computer\root\cimv2:Win32_Trustee").CreateInstance() $Trustee.Name = "EVERYONE" $Trustee.Domain = $Null $Trustee.SID = @(1, 1, 0, 0, 0, 0, 0, 1, 0, 0, 0, 0) $ace.AccessMask = 2032127 $ace.AceFlags = 3 $ace.AceType = 0 $ACE.Trustee = $Trustee $sd.DACL += $ACE.psObject.baseobject $mc = [WmiClass]"\\$Computer\ROOT\CIMV2:$Class" $InParams = $mc.psbase.GetMethodParameters($Method) $InParams.Access = $sd $InParams.Description = $description $InParams.MaximumAllowed = $Null $InParams.Name = $name $InParams.Password = $Null $InParams.Path = $path $InParams.Type = [uint32]0 $R = $mc.PSBase.InvokeMethod($Method, $InParams, $Null) switch ($($R.ReturnValue)) { 0 {$ret="Share:$name Path:$path Result:Success"; break} 2 {$ret="Share:$name Path:$path Result:Access Denied";break} 8 {$ret="Share:$name Path:$path Result:Unknown Failure";break} 9 {$ret="Share:$name Path:$path Result:Invalid Name";break} 10 {$ret="Share:$name Path:$path Result:Invalid Level";break} 21 {$ret="Share:$name Path:$path Result:Invalid Parameter";break} 22 {$ret="Share:$name Path:$path Result:Duplicate Share";break} 23 {$ret="Share:$name Path:$path Result:Reedirected Path";break} 24 {$ret="Share:$name Path:$path Result:Unknown Device or Directory";break} 25 {$ret="Share:$name Path:$path Result:Network Name Not Found";break} default {$ret="Share:$name Path:$path Result:*** Unknown Error ***";break} } $ret } # --------------------------------------------------------------------------- So I'd prep a CSV with the info and then for each item in the csv, just call that function passing the username and the target (\\$fileserver\) which would create the share.
  19. Scuse my ignorance, but with (say) an individuals network drive, how can you avoid creating a share per user?
  20. ^^this. Also ask the solicitor for advice on the law change in 2012 (did it/didn't it?). They may be able to point you in the right direction.
  21. No salary stated which I believe is asked for when you post an ad to this forum. There also seems to be some confusion on the website (once the reader figures out how to correct your link) as to whether this is a technician or a NM.
  22. I only know of one supplier that demands UPN (or another national identifier) and who is using it in a way that worries me - everything else I've dealt with asks for admission number. They say they have referred it to the ICO and I'm waiting for a response back from that.
  23. That depends. If they are running this from a command line, then the dump will be placed where they specify (usually the current working directory). If this is a unix type host, ftp, samba or rsync. [ETA - if you want to make it easy for them and are using windows client machines, grab mysqldump for a windows build and put it somewhere on the path and they can then dump to any file sytem the local machine can see (i.e. their network area).
  24. For export, they should be able to use mysqldump and access any databases they have permissions to. Just pipe the same file into mysql to restore.
  25. IMO you should be a little bit cautious, but it is not clear cut. There are some things to consider : UPN is not an ordinary bit of data as the DfE advice says it is a general identifier under the DPA and it's use is controlled by the Secretary of State. The advice also says you should use admission number where you need an ID to do data matching AND you should not give it out to data subjects even as part of a normal subject access request. That last bit I think just emphasises this is not a normal piece of data. That said, you are allowed to process it - so when you run a CTF file in, it will almost certainly match on UPN. Being part of a school to school transfer, it is covered by the guidance. As is sending it via ASC to central government. If your MIS is a cloud based system then your provider is simply acting as a 3rd party supplier under your DP registration so that should be OK (nothing else is being done with the data). The issue might arise with a 3rd party that was offering other services, so they are processing the UPN for reasons other than the purposes explicitly listed by the guidance, say to allow them to uniquely track an individual at a national level between different customers (i.e. when the student changes school/educational provider, they offer a service to 'transfer the previous schools data'). IMO this may be problematic in a number of ways and you should seek guidance from the ICO.
×
×
  • Create New...