Jump to content

sahmeepee

Members
  • Posts

    804
  • Joined

  • Last visited

Everything posted by sahmeepee

  1. Good work on that CN. I've replied to your other thread with some stuff that might be interesting to people from the SIMS side of the Force.
  2. Not quite right Geoff! Although you can't read from the database directly, you can read from the SIMS database via their reporting SDK gratis. They have fairly good reasons for this: (From Capita's Dan Clark on the SIMS forums) I've got the docs for this recently from Dan Clark (the tools are already in your SIMS install! The executables start with "command"). It's not perfect, but at least a csv/xml output could be imported into a database without human intervention given a little effort. The bad news - because it works via the reporting mechanism it's read-only. For the purposes of this thread that shouldn't be a problem. I'm somewhat surprised they can't find room in their 250MB SIMS install for this 50KB SDK manual. I will check with Dan Clark to see if I can post the file on here. You might also like to consider this post from Phil Neal on the moodle forums on Monday 26th June: Apologies for the long post, but I think some of these developments could really help people in here. (BTW Thanks to Karl for finding the 2nd quote )
  3. Can you tell me how to connect to an SSL site if it's on the opposite side of a firewall with 443 closed. I'm ignoring the case where you put your SSL site on a non-default port of course. Obviously the outside world would only be able to access one server (or possibly a selection) on 443 as we only have one outward facing IP - how exactly would they tunnel telnet (as a simple example) over HTTPS to my server which has 443 exposed if I hadn't configured the telnet tunnel beforehand? Even if I ran a telnet daemon they'd not be able to talk to it over my port 443 unless the server said so. I totally agree that anyone with direct access to your Windows network can get the name of the builtin Administrator account, but as I say that isn't the only scenario out there. With a school system we would traditionally be looking primarily at protecting against attacks from the inside. With all these wonderful advances in access by pupils/parents/babysitters/pets from home we have to spend more time protecting against the whole world. Thankfully it's simpler for us to reduce the "attack surface" for attacks from outside. "You do not address the possibility of a reverse tunnel either." Any outbound SSL connections are logged and blockable so although it is an issue it's one most schools can deal with reasonably well. I wouldn't consider disabling pupil/staff access to external HTTPS sites a viable security measure.
  4. Video editing over wireless is pretty brave in itself! Within those contraints I'm not sure I can suggest anything else. Possibly you could send the video clips to the laptops then decompress them to uncompressed AVIs on the laptop end. Although they'll be big files the laptops should probably have enough space. Possibly this search on videohelp will throw something useful up: http://tinyurl.com/hw2ac
  5. I read on the MS class server newsgroup that they are releasing a "replacement for class server" in July. Is that just MS Learning Gateway? SCORM compliant resources are a good idea in theory - it's just a shame that hardly anyone makes them. Perhaps when we've all had VLEs thrust upon us the market will be there and we'll start buying all the stuff we've had for years in swanky new SCORM format. Yet again, things have gone back to front - VLEs to be in place by next year or so, just in time for years of eLC funding to run out so you won't be able to afford any 3rd party content. VLEs all seem to be a tart to set up because there's nothing to tie your AD accounts into SIMS user data, so you have to break out Excel and do some voodoo to map the two together. Depending on your user naming system (another recent thread) this can be non-trivial . Any VLE which eased that burden somehow would get my vote (especially if it did nightly synchronisation).
  6. Not blocked by websense's "proxy avoidance" category either. Until I added it
  7. I'm getting a load from RocheAV this summer - their work in the past has been very good quality and their pricing is good. Our LEA used Smarter Solutions for a ton of SMART installs and the workmanship seemed fine even with some tricky ceilings.
  8. Our administrator accounts are all renamed and nothing bad has ever come of it, but we did it on day 1. To be honest I'm not sure I'd bother changing it now if it had been left as administrator for a year. The return is relatively small even in a building full of miscreants. There are some situations where it does offer a small amount of protection. For example, it's not always possible to enumerate the Domain Admins group, because you're not always in a position to query AD etc. Most situations where you'd use your domain credentials from outside the firewall would only be giving you access to one port, like 80 or 443. Knowing the SID in this case wouldn't usually help you much either.
  9. We use Koepi's xvid encoder here (free). Xvid is generally better than divx for size vs quality. To be honest you should try to avoid editing compressed files as it'll always be slow and annoying compared to uncompressed avis or DV. Try taking a look at videohelp.com - it has all sorts of useful guides, software etc.
  10. I'm planning on using them for a couple of 16-bay "Monarch" laptop charger trolleys. £449+VAT each.
  11. Norphy: Hope you don't mind, I've wikified your OWA with SSL method. Mostly so I can find it when I need to do it later on. If you typed all that lot from memory after 2 weeks 8O I'm v. impressed!
  12. As for "is it hard?" there's certainly a fairly steep learning curve when it comes to building complex interactivity into your animations. You should either set aside a good amount of time or look for examples of flash animations which are close to what you want. Unfortunately you can't edit a compiled flash file (a .swf) - you need the original authoring file (an .fla file) to do that. The guy who makes those excellent wordsearches also releases the fla files for his resources for non-commercial use: http://www.subtangent.com/flash/index.php There's probably some good material in there to use as a starting point to give you a feel for the interaction/scripting side of Flash.
  13. Presumably they ordered a number greater than zero. You wouldn't even get a tin of tuna off me!
  14. Ours is this one: http://www.digiappz.com/digirez.asp?id=1 It's got nice calendar views and runs off a fairly basic ASP + Access setup. The guy who makes it will do customizations fairly cheaply if you need them, but chances are you won't. The database doesn't have any annoying passwords on it (as if that would stop an edugeek!) and the tables are fairly understandable, so you can pump timetable data into it from SIMS with only minor hair loss.
  15. it depends what you're after really. If it's a sanction for a handful of kids in that OU and you're "brave" enough to let the chalkmongers have delegated control over the user accounts, can't you just tell them to disable the user accounts? The only downsides I can see with that are: It might screw up their ability to receive mail in exchange (?) if you use it It's not immediately obvious which accounts have been disabled by a teacher and which were disabled anyway. Amongst the many reasons I'd be wary of delegating that control to teachers is that you'd have a fun time keeping track of who disabled whom and why - you'd probably end up with a load of kids who couldn't log on and nobody would know why. The kids may well not be willing to tell you (if that means you have to put them back on). If you're determined, I'd give it to them via a script interface that logs the teachers username and prompts them for a reason why and a date when the pupil should be reinstated. We got loads of requests for kids to be taken off inet/network/email, but they never remembered to get them put back on again, so we always ask how long they should be off for.
  16. Is that 65Gb or 6.(point)5 Gb?? Ha! Neither! It's tiredness and I mean 65MB! :oops: Apologies.
  17. Our LEA use FE/BE for primaries, but we can't really justify the expense for ours. It'd give us more options for securing Exchange if we did.
  18. Yep, they're too cheap to buy one from a certificate authority, so they've just issued a wildcard one themselves. I'm hoping our LEA will buy a proper wildcard one for ourtown.sch.uk - I wouldn't object to stumping up part of the cost.
  19. If someone does take control of your LAMP box, they could (in theory) be able to collect the passwords that are passed into the application despite any SSL encryption. Assuming they can only hit the web server's external-facing port 80, they would probably have to know an exploit in either Apache or the Moodle application code. That would probably get them access on a fairly limited account, but one which has access to the passwords after they leave the protection of SSL and before Moodle sends them through the internal firewall to AD (securely or not). That said, if you keep Apache and Moodle fully patched and up-to-date you are doing about as much as you can.
  20. We had a similar case with a 6th former who sent a 20MB document to print. The spool file had reached 600MB by the time we killed it. The lesson being: make sure your print spool folder isn't on the c:\ drive of your print server or things will start to fall over.
  21. Any idiot running keyfinder (or similar) can get your VLKs. Assuming they can run the executable. No sense in handing it to them. Also, they'd have a fun time trying to run the MagicalJellyBean on one of my servers, which also have their license keys listed by NetPoint.
  22. tosca: should be fine, but I'm not sure how healthy it'd be if you use MSDE. The database was about 65Gb in total after scanning those 137 machines. plexer: I agree on all those counts - I think if you want that you should be talking to webman though! His Carbon Hardware app looks promising. I'm also wondering why this product is free and whether it's going to stay that way very long. Methinks it won't.
  23. KLUDGE ALERT I'm ashamed of myself for suggesting it but you could make your script schedule a task that runs once (i.e. now+2 seconds) then deletes itself. I've never scripted the creation of scheduled tasks, but everything's possible.
  24. And it's automatically trusted by their web browsers at home?? Presumably they have to agree to trust it as Norphy says.
  25. OK, I've just given it a trial run through tonight. It installed fine first time on this PC (my everyday desktop). I already had IIS and .NET 1.1 installed. I pointed it at an existing sql-server installation (on a different machine) and chose windows auth. Annoyingly this meant I had to use runas to run the installer. After starting the Neutex NetPoint service, the web UI was immediately available as advertised although there didn't seem to be any login procedure so that might need locking down: something to check as it lists your Windows and Office VLKs in the inventory! I set up a single schedule for 5pm, then started looking for the setting to tell it how to find my computers. There wasn't one: it just does it. I'm not sure whether it tries everything visible in "net view", every computer in the domain or just every IP address in the subnet. It started running at 5pm and by 7pm it'd done 137 PCs and servers, with the limiting factor being my groaning processor on this laptop (a P4 2.8, but possibly running slower). Network-wise it ate about 22Mbps solidly for the 2 hours. It'll be interesting to see how the speed compares on the second run through. With agentless inventory I think the gain of not having to deploy, maintain and run client software is balanced by the PITA of the computers actually having to be switched on when you run the inventory software. I might try doing a scan at lunchtime to see if any users complain - at ~1 minute per computer I don't imagine it'll cause much pain at the client end.
×
×
  • Create New...