Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

shadowx

Members
  • Posts

    230
  • Joined

  • Last visited

Everything posted by shadowx

  1. There's no practical use for it in a real world situation but I think it's a great idea to get the students to use it and understand it. ICT these days is just word processing and using dodgy fonts in powerpoints which are badly designed from the get-go. And let's be honest, the optical system is very similar to the old punch card program systems that computers started with (I admit, I have never, ever seen a punch card system! I'm far too young for ancient stuff like that ) so it could be a good opportunity to get the kids thinking about how far technology has come, like you said sdc, if you can get the students to "program" up a "card" for the machine to read and execute it would be a superb analogy. If you can get the software to interpret some form of symbolic code, even if it's simple stuff like "choose a colour RED:[ ] GREEN:[ ] BLUE:[ ]" and stuff like "Say: HELLO WORLD[ ] SYSTEM BOOTUP[ ]" and so on... just to make a simple multiple choice "program" ... Anyhoo... Probably quite ambitious if you are manually decoding serial output but you never know Wish I had one lying around now...
  2. The best option I can see is to get a PHP server with CURL enabled, fetch that page, then use something like str_pos to find the "Next train from blah blah is" then copy out the relevant info in PHP, discard the rest. Re-format it and then display it how you want. I don't know what XIBO is but you can use PHPGD to save the info you scraped into a JPG image however you want it to look then embed that on your screen someone purely as a JPG?
  3. shadowx

    php problem

    Everyone has to learn The amount of stupid mistakes I've made is ridiculous! My advice is just to code as much as possible, then you will lean as you go. Eventually you will be coding stuff for you to use in the office, here me and the NM made a nice little PHP helpdesk together which is really useful along with other random crap of course!
  4. shadowx

    php problem

    I think that should work but within a function you always need to use "return $variable" A function kinda of works like In your code you are not actually returning the variable so you would need to modify it to be either: Or you can make the function do the echo statement too, such as; Note that in the second option you dont need to use RETURN, that's because the function already does the ECHO itself, so RETURNing the value of $tmp is pointless. For me personally I would always go with the first option, the reason being that if you have a function which automatically echos out the variable $tmp, if you want to do something else with that variable, let's say you cant to check it and then insert it into a database then you need to write the code from scratch. If you tried to re-use the check_url function every single time it would blurt out "$tmp" into the page for no reason. But if you DIDNT use echo WITHIN the function then you can safely reuse that function elsewhere and instead of doing echo $tmp; you can use insert_into_database($tmp); Does that make sense? TLDR; Use the first option, not the second
  5. Stone are a brilliant supplier and I would highly recommend them. This year we went with a company called Zoostorm that make custom builds, I am not going to tell you that they are of the highest quality, the cases are lightweight and what not but actual components are all top notch intel type stuff and at £245 a pop for 4gb RAM, decent dual core CPU and 160gb-ish HDD you can't really go wrong (Can get actual specs off our quote sheet if anyone is interested) As for hardware support let's face it, 99.99% of hardware failure is either a DVD drive or a power supply. PSUs cost a fiver each and within the space of literally 5 minutes you can whip a machine out, replace PSU and put it back again. DVD drives in student machines *shrug* they dont use or need them so we don't bother replacing or repairing those, on staff machines again it's a fiver a time and 5 minutes in the office. i wouldn't bother sending off machines or getting an onsite repair unless it was something pricey like a processor or mobo. Everything else we have "in stock" and repair in house. We went with zoostorm due to the price, frankly if price was not an issue whatsoever I would always go with stone. If price is an issue go for Zoostorm. I wouldn't use Dell as personally I see them as a home desktop solution (and even then I would avoid them like the plague) and RM I have only heard bad things but each to their own really. I also hear that dell PSUs are a nightmare to get hold of...
  6. shadowx

    php problem

    Agreed, it could be a deliberate thing but "temp" is never used except in that last line, so unless there is more code somewhere "temp" == NULL hence you'll get no output Also "echo $feed" is outside the PHP code (comes after "?>") You also don't seem to be calling the function "check_url()", the code defines in but doesn't call it, try replacing With Then you are calling function and assigning it's returned value (Which is $tmp) to the variable $feed, if that makes sense?
  7. Epic reply I was wondering if we could do that and I was going to ask around so you've solved that problem! I've already spoken to Impero support with regards to remove staff entirely from the console. speckytecky: setting up the staff group is easy enough, just make a new group call it what you want, then on the properties under the membership rules (I cant remember the wording and don't have it on this machine) just change the drop down to AD Group and then enter the name of staff group (In our case "Staff") Next to ensure that staff dont show up anywhere else you can edit the membership of the other groups and choose AD Group again but put a "!" in front of the group name (So for us it's "!Staff") which equates to "NOT Staff" hence staff dont ever turn up in the "ICT Room X" groups. After speaking to Impero you can actually go one step further which is what I have done, in the Server GUI you can assign permissions to the "Entire Network" group, so if you set no permissions on it (IE everyone, including admins, is denied) then you are basically prevented from seeing staff at all. Im sure RussDev can explain it better or failing that send me a PM and I can talk you through it in a bit more detail Imero is really nice, one of the reasons we licensed staff (Well, THE reason) is to remotely assist staff with silly things like not being able to use spellcheck or something and to quickly deploy a program if we need to (SCCM is slow slow slow) so having the ability to request access to their screen etc.. is exactly what we wanted so thanks for that RussDev!
  8. Thanks for the links, about to head off home now but will have a read tomorrow. Draft version of the AUP is made too so it's been a fairly productive afternoon
  9. Interesting... I will write an AUP pretty soon and I will put that kinda thing in there, 99% of staff are aware of it but like you said, it needs to be above board and officially set out in an AUP. Luckily we get on with most of our staff here which helps!
  10. Excellent links, thanks for those! We already have filtering and internet/email logging in place which purely logs the pages accessed by all users and the external email routing system we use keeps a log of messages sent/received but not their content. I am now wondering... would this level of logging need to be announced to staff?...It's not actually kept to purposely log staff it's just a side effect of the way the systems work really. This also rings alarm bells... At the moment the CCTV is hosted in our office, when a member of staff asks to look back at recordings we just click the buttons and what not and let them see it.... Students are never permitted to watch it unless they are supervised by an appropriate member of staff but any member of staff can, and do, come in here and watch the recordings...
  11. This is true, but there's no AUP in place to stop me saying it, and it's non-identifiable etc... I will consider an edit though The old "by doing x you consent to y" is a bit grey, but in some places it's the only real option but in a situation with paid support etc... I guess unless it's stated in the contract at the time of purchase it's a bit dodgy
  12. ************ Redacted (though still accurate)
  13. I too believe this relates to what the media likes to call "hacking", in that the unauthorised access is equivalent to breaking and entering. As the school technically owns the devices it wouldn't be unauthorised. Although I have often wondered about licensed content, for example, if a member of staff was watching a licensed video clip which stated it could only be viewed on one device by one user, surely if I remote view their machine and watch then that would break the license and thus be illegal?... Probably not the case but it does make me wonder.
  14. I see your point but going back to CCTV, a shopping center can't legally put CCTV up and watch you without first telling you clearly. That gives you the decision that if you go inside you give consent to be watched, if you don't give consent then you can go elsewhere. I would expect that the same applies to computer monitoring. While the hardware and software does indeed belong to the employer they are still watching YOUR actions. A few sources online basically repeat what SYNACK said, that there should be an AUP in place that includes the fact that employee activity will be monitored. Then staff have the choice to give consent and keep the job or go elsewhere. On the subject of AUPs does anyone fancy sending me a copy of theirs in a PM? Or even a censored/draft version so I can get an idea of what a secondary school AUP should involve? (I wont use it as-is, I will only use it as a resource to see what should be on our AUP)
  15. Yes, BUT! Rather than sit and look through logs all day I can run up Impero and see from the thumbnails if a student is playing a game, check the full screen view, get the URL and block it. I don't look through student folders although if we get a sudden epidemic of students playing a game then we will sometimes do a "*.exe" search in their folders. I only pass on info about illegal/games/dangerous files. I think we are fair, it's up to teachers to keep the kids on track though, my job is to make sure the network stays as good as can be and if that means removing potentially dangerous or illegal files then that's part of what I am here for! Interesting, thanks for the heads up there, I will have to read the digital surveillance act. in a physical sense when CCTV is used there HAS to be signs or some other way of notifying visitors, employees, students etc... that CCTV is in use otherwise again I think it's illegal so it makes sense that the same rules apply to digital surveillance too. Will check it out, thanks!
  16. An AUP, whats that? Oh the thing that governs acceptable use, yup wish we had one of those I think It's time I drafted one up! I agree that computer use should not be monitored, however student access is different.... IMHO you should monitor students to stop them accessing porn etc... which is a legal requirement I believe and to keep a better eye on the cat-and-mouse game of tracking down bugs in software that allow them to get things they should (eg installing Chrome to their local "AppData" folder) and at the end of the day it does vastly increase the time spent doing work as opposed to playing about if the students know they are being watched by their teacher they might at least pretend to work Thanks for the link x-13, will check it out
  17. *sigh* *head explode* *face palm* *bang head against wall* We have just re-installed Impero after our trial (Excellent bit of software, highly recommended) but a certain member of leadership has caught on that they can now watch every member of staff's computer etc... Personally I am massively uncomfortable with this so I need a few spanners, what is the legality of monitoring staff and the general policies towards it? I know that legally an employer can do it but do we need to tell staff before hand? If so what do we have to tell them? I know for a fact that if I send out a blanket email to staff telling them that management are monitoring them it will cause an uprising and things will get messy and hopefully leadership would shelve the idea. So I am sincerely hoping there is a legal precedent or requirement for us to notify staff, is there? As for me I run a *nix box so I am in the clear *whistles contently* I would love to hear what other schools do and what policies and notices are given to staff with regards to the monitoring and if any major unions have any policies regarding it. Thanks chaps and chappettes.
  18. Personally would simply make guides and tutorials on how to back their own stuff up to the network and give them a few weeks to do it then blitz em. We replaced the hardware here so, as usual, we keep the old boxes around until we can get them recycled so we are able to recover stuff if we have to (though it means sorting through literally stacks and stacks of computers, checking asset labels and looking them up on the asset system to find the right machine etc...) but in all honesty they would probably just be reminded that they should have moved it and that's that. It might seem a bit harsh but your job is to maintain a secure and efficient network that facilitates the ability of the school to educate and protect the students. You aren't there to hold the staff's hands and do everything for them! If you are absolutely adamant on keeping their old data I would go with replacing hard drives. A lot less work and time than making images of the old hard drives IMHO.
  19. You could make a simple webpage to do it? To make it simpler make a static HTML page for each room, the webpage has the seating layout as an image background and in each "seat" is a text input box, the teacher types in the kid's name, clicks submit then PHP saves it all to a database such as: StudentName SeatNumber RoomNumber IssuesReported Date Then to display it out you can either simply list it or get into the PHPGD library and whack it out as an image. Or just give them a word document which is setup as a form and have them save a copy... Although that's not a searchable database.
  20. I definitely see what you are saying, we are lucky here in that we have a load of thin clients and a server sitting around not being used (an old project from before my time I believe that was outsourced and never sorted due to having a *nix backend), but provided you have enough test hardware, even just to setup a couple dozen over the course of a year, then you have a good basis to justify throwing out the big bucks. I wouldn't purchase hardware or software without testing it first on what we currently have otherwise like you say, it could be a massive pitful. I suppose at the end of the day it depends on your external partner and the sort of agreement you have, I wouldn't dream of completely oursourcing anything, I would always want heavy involvement to steer things the right way but more importantly to get the sort of understanding that you can only really get by being involved during the set up.
  21. From a non managerial role I don't see the problem with allowing it, yes there are issues but not issues that should result in it being blocked. We don't block any of that for staff, all we block for staff is adult/inappropriate and phishing/malware/dangerous type categories. Of course if you allow staff on to social networking and personal email your leadership need to lay out in concrete the expectations of staff and they draw the line. Sitting in the staff room sending a few emails or checking facebook a few times is a different story to sitting in a lesson and doing the same. There is a story floating around somewhere about a female teacher who was sending steamy messages to her partner in a lesson not realising she had the projector on and the whole class was watching. She didn't last long... So things like that are obviously an issue but that's what the staff handbooks and staff policies are for. The only issues I can see with filesharing are security and inappropriate/illegal files. Again the legality and morality is one for leadership to lay out to staff, security should be handled by your existing systems so it isn't an issue. Also make sure that illegal/inappropriate downloads are featured in your AUP. Forums and blogs are an absolutely amazing resource in any job, we are on one right now so again I see no need to block them. Provided you block adult/illegal etc.. categories with your filtering then the forums that staff can get to should all be safe, so again from leadership's point of view make sure that staff understand that they are not permitted to post as a representative of their employer and not to post anything that in any way could affect the school. A lot of the issues are mostly down to giving staff responsibility and trust. Provided that leadership can provide a clear set of policies and rules and show that they will enforce them strongly then staff should keep themselves in line. That's my two pence anyway. EDIT: Here we have strict policies as well as the staff handbook which cover things like facebook and representing the school, preventing staff getting into awkward situations with students (IE giving out personal contact details) and sheets made by staff for staff on hoe to make facebook more private and what not. I would say that our staff are professional in the way they use computers and there haven't been any issues to my knowledge that are a result of staff accessing these sites within the school but it does depend on your staff and how likely they are to push boundaries.
  22. But why? I see it as a challenge and a project to tailor exactly to our needs rather than buying something off a shelf and making do. I am a fan of linux and I think it's virtually a duty of schools to expose students to a variety of different bits of software including OS's and we have a server sitting around so when I get the chance I will be designing and making an edubuntu or similar server/client setup that's tailored to be exactly what we need it to be, that way me and my colleagues get a full and complete understanding of the system inside out so troubleshooting is 5x faster and we can apply tweaks whenever we need to. Outsourcing anything just leads to a lack of knowledge which in turns leads to longer troubleshooting and more headaches as well as getting a product that isn't what you wanted or expected. We do virtually everything in house here, cabling, hardware, software, internet filtering, security, email filtering and although it means I end up covered in crap from the lofts and what not we still get a much better result out of it! The thought of having to rely on someone else to run a handful of cables or change a filtering setting just makes me shudder! Though it does depend on how many techs you have and how much time you get (I speak like a network manager but I am just one of the lowly techs, I'm just lucky enough to have a NM that gets us all involved rather than keeping everything a secret)
  23. Spot on. For providing a school desktop outside of school just go with something like RDS. We use RDWebAccess here and can push out any application installed on the server individually (IE running an instance of Word on the remote machine which is actually being processed on the server, providing all their school drives etc...) and we can provide a full RDP connection using standard RDP to windows, Mac and a real computer I mean linux All for a LOT LOT less than £70k! If you want to go thin client in the school then firstly don't chuck the old machines, just use them as thin clients. Secondly buy your own servers and save probably a third of the price they would charge, then look again at Microsoft solutions or failing that something like VMWare. It would take more time but there is no reason why you couldn't do 90-100% of a thin client migration in house to be honest.
  24. It might also be worth trying to manually download the certificate from the site and manually install it into smoothie. I can't remember exactly where it gets added to smoothwall but with the new GUI you can search for certificates" and you should find a page where you can import certificate files. Just go to the site that is blocked, use the browser to view and download the certificate and then go to the smoothwall page and upload. Might work, or it might not!
  25. Laugh and return the USB stick. If you could access the file without the password or crack it then it wouldn't be very good encryption.
×
×
  • Create New...