Jump to content

eric.777

Members
  • Posts

    12
  • Joined

  • Last visited

Everything posted by eric.777

  1. Hi, Thanks for the responce but we should be able to stop *.Bat *.EXE *.CMD from a net work drive with GPO? Just to let you know if i use *.bat with no( H:\*.bat ) it works but no mapping drives or printers..
  2. Hi, GPO: User Configuration > Windows Settings > Security Settings > Softwrae Restriction Policies > Additional Rules Add a new path rule \\server2\users$ Disallowed We also add the profile path \\server2\profiles$ Disallowed. just looked at the GPO results for the students pc and it says Policy Setting Interactive logon: Number of previous logons to cache (in case domain controller is not available) 0 logons Software Restriction Policieshide Enforcement Policy Setting Apply software restriction policies to All software files except libraries (such as DLLs) Apply software restriction policies to the following users All users Designated File Types File Extension File Type ADE Microsoft Office Access Project Extension ADP Microsoft Office Access Project BAS BAS File BAT MS-DOS Batch File CHM Compiled HTML Help file CMD Windows NT Command Script COM MS-DOS Application CPL Control Panel extension CRT Security Certificate EXE Application HLP Help File HTA HTML Application INF Setup Information INS Internet Communication Settings ISP Internet Communication Settings LNK Shortcut MDB Microsoft Office Access Application MDE Microsoft Office Access MDE Database MSC Microsoft Common Console Document MSI Windows Installer Package MSP Windows Installer Patch MST MST File OCX ActiveX Control PCD PCD File PIF Shortcut to MS-DOS Program REG Registration Entries SCR SCR File SHS Scrap object URL Internet Shortcut VB VB File WSC Windows Script Component Trusted Publishers Allow the following users to select trusted publishers End users Before trusting a publisher, check the following to determine if the certificate is revoked None Software Restriction Policies/Security Levelshide Policy Setting Default Security Level Unrestricted Software Restriction Policies/Additional Ruleshide Hash Ruleshide LOGON.BAT; 5 KB; 27/05/2009 12:56:15 File hash 2FE2D2B3483A7C121F8A824CC9824F3C:4417:32771 Security level Unrestricted Description Date last modified 16/02/2011 11:10:24 Path Ruleshide %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% Security Level Unrestricted Description Date last modified 15/02/2011 16:23:27 %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe Security Level Unrestricted Description Date last modified 15/02/2011 16:23:27 %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe Security Level Unrestricted Description Date last modified 15/02/2011 16:23:27 %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% Security Level Unrestricted Description Date last modified 15/02/2011 16:23:27 H:\ bat Security Level Disallowed Description Date last modified 17/02/2011 12:45:46 H:\ exe Security Level Disallowed Description Date last modified 17/02/2011 12:45:52 H:\*.exe Security Level Disallowed Description Date last modified 15/02/2011 16:58:10 H:\*.exe Security Level Disallowed Description Date last modified 16/02/2011 13:09:21 H:\*bat Security Level Disallowed Description Date last modified 16/02/2011 11:07:06 H:\cmd Security Level Disallowed Description Date last modified 17/02/2011 12:46:28 logon.bat Security Level Unrestricted Description Date last modified 16/02/2011 10:52:11 But the student just rename the bat file and run it Example is open word then put a scrip command in it then save it as a plane text . word will then let you save it as a hack.BAT in the home drives Then run it. How can we stop them when we use Logon.bat to map printers and map drives? Any help please....
  3. Hi All, Want to stop bat files and other exe from student home drivers. Any one know the net work path and commands for this. Student home drives are map to \\server2\users$ on H. So i put in H:\*.bat or \\server2\users$\*.bat. Would like to do screening but server 2 is old win2000 server. So tryiug hash rules. Still no joy... Any help please.
  4. Nice link for the weather:D Aktuelle Satellitenbilder - Europa
  5. Yes did it in GPO. Thanks for the fast response. Just wanted to be smart and shut the computer down when a pupils try to logon.
  6. Hi, Does anyone know how to stop pupils logging on to a teacher computer? We want a script that shuts the computer down when the script see staff.txt on the root of c:\ Any ideas
  7. How can we get rid of Ms-Dos file conversion in word. It turns dos or net command copied into word documents and converts on save to whatever.exe that run. Can it be done in GPO? We have disabled Notepad.exe, CMD.exe Command.com and other bits in GPO. But Word2003 is Like a Notepad TXT editor. Just a bit annoying.
  8. All ok it was a teachers password. Pupil login then makes local account for later. Only probelm is stopping pupils making command.com bat files for cmd access In office2003 word.
  9. Pupils have no admin or local rights on the computers. Pupils should only login to the domain with no local login. All pupils login on the domain and are members of the pupil user group. The computer hard drives have default ms shares and no local users. When the computers join the domain we add domain administrators. Any help please.
  10. You try it. Login to computer as pupil with no admin or anything on the domain. Open office save command.com in word office as whatever .exe. office then converts to nice dos-exe little cmd. then run net commands on the domain. Use example net commands of YouTube. Log off domain. Then login local with admin nice.
  11. Thanks for the fast response. Yes the commands run. It's all over YouTube and is driving me mad. I have disabled notepad.exe but how to stop office plain text edit? You need to test it on your networks before the little angels do. The computers have a default Admin user for us and are on the domain. Could be why we get the odd BSD.
  12. We have a problem on our net work with pupils trying to hack the school computers with the Net Commands. Examples Save a document in plan txt in office word 2003 containing a cmd command.com then save it as a .exe.Office file converts it to a command promt. In cmd do this. net user whatever /add net localgroup administrator whatever /add You can see that this gives a new user to the computer with local admin rights. We have disabled cmd in GPO and have added command.com command.exe and cmd.exe in GP on the domain. We cannot stop scripts running because of a kix scrip for loading the printers. Any help please.
×
×
  • Create New...