maxymaxy
Members-
Posts
13 -
Joined
-
Last visited
Reputation
5 NeutralAbout maxymaxy

Personal Information
-
Occupation
ICT Coordinator
-
Renaming executables - Lanschool
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
We are stepping into unknown territory because the netbooks will be taken home and used by students on their own network. So screwing down security too much is going to be a problem. Students will also have plenty of time to try and bypass any policies we might try and set. So I am thinking that we have a whitelist for all the apps we are known to be using at school and then it doesn't matter if they have installed other undesirable apps once they step onto school property and they connect to the network. Zenworks can do this and so can Faronics AE. -
Renaming executables - Lanschool
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Just to reply to my own post... LanSchool technical support responded very quickly to this question. The suggestion was that while it was difficult to stop renamed exes, it was better to stop them from being installed in the first place. The distributor in Australia suggested Faronics Anti executable. This will run 24/7 on the student netbooks (which they take home) even when they are not being controlled or monitored in the classroom. It will stop any exe from running that is not in its whitelist. I have used this before in a very 'hostile' environment and it remained undefeated. Therefore, games cannot be installed or run from a USB device. -
We have begun our trial of LanSchool 7.4 Some students have figured out that if they rename an application to one on the allowed list it will run e.g a multiplayer game like Soldier of Fortune with an executable called: sof2mp-test.exe they renamed to notepad.exe. Is there a way to deal with this? regards Paul
-
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Thank you for the time you have taken to reply. I had an interview with the principal today and he was unaware of the what was happening behind the scenes. It was a worthwhile talk and he is now more aware of the different problems. The NW manager leaves in a few days time and a new one won't be appointed until next year. He has given me the go ahead with a trial of ABT with a view to rolling it out to the rest of the school in the short term. So the situation with the 'open policy' is on hold until the new NW arrives. I will certainly be up front there about my concerns when he/she arrives. The technician is now in charge and I don't think he will be making any changes to workstation images....steady as she goes. In the meantime I will set as many policies as I can with ABT to restrict the student's activities. I am looking forward to taking back a bit of control. From teacher's perspective this is about all I can do. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
I know this is a bit off topic, but has anyone used "Hidefolders XP"? I thought that I might give that a go to hide ABT install files until I can get proper group policies setup on the server...just trying to protect the client. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Hi all, I've got an interview with the principal on Monday. I have done a bit of canvassing and have support from library staff, a few teachers and my deputy head. So let's see what happens 8O I will post back and let you know what happened. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Hi all, Yes, I am a class room teacher TRYING to teach four senior IT subjects with at least one student who is way better than me. I get a small time allowance to help other teachers put teaching material onto our intranet. My title makes it sound like I have more say in how the network runs than I actually do. Our NW manager is not the easiest person to converse with but the light at the end of the tunnel is he is leaving at the end of the year. Yes I am asking a lot of the ABT client but it is able to deliver with the powerful registry editing function. I will stand my ground though and still think the client should be password protected to uninstall it and it should protect it's own install directory. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
mrphil, My main point for starting the thread was to point out that in SOME situations it would be an advantage to have the client password protected. I still think ABT should seriously consider this. Not all of us live in an ideal world. As you can see from my solution I am writing my own group policies 'round the backdoor'. If the NW manager was doing his job, the guest account would obviously have all the necessary restrictions. I don't need reminding that the students have too many privileges. I am being squeezed from both ends - the lack of security from the network, teachers in the middle complaining about students not being on task, and students at the other end just wanting to play games and muck around. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Thanks everyone for replying. I have taken some reasonable steps to protect the ABT client: 1. By making the /program files/abcontrol folder invisible 2. Using the registry function of the ABT control (a) prevented access to the control panel (b) disabled cmd.exe, run © prevented access to the task manager (d) made invisible msconfig, gpedit (e) disabled .bat files (f) disabled any access to network properties There are still ways around these things though. I have in my IT class a student who is rated one of the top 20 junior programmers in the world He was at the recent programming olympics! Luckily for me he is an ally rather than foe and lets me in on ways the other students are trying to get around the system. OK all of this not ideal but I can only do what I can and hope the next NW manager is better. I still think though the client and install files should be password protected. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
I have just tried the registry editing policy function in ABT and it works well From the control workstation I was able to easily remove access to add/remove programs. I will go ahead with my pilot plan, create a policy pack to tighten up security (just don't tell the network manager) and .... hope the new guy is more sympathetic to the teacher's plight 8O -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
I agree with all of you. Just to clarify though, the students log in to the workstation locally which means that they have the privileges to uninstall programs but it doesn't allow them to map the network drives hence privacy is not an issue. The novell network means that there are two login screens first to login to the network and the second to login to the workstation. Some problem with one of the servers means that students are able to ONLY login locally which means they can still play LAN games but not have any access to their home drives or network drives. Having calmed down a bit and thinking through some possible solutions, it may be that when ABT is installed the first time I can set up a some permanent policies in ABT and deploy them to the clients which deny students (who log in locally) access to run/cmd and the control panel. I can also do a registry hack to hide the icon in the add/remove programs. This is not ideal, I know, but is it feasible with ABT? The network manager is leaving at the end of this year so I hope the new person will take security a bit more seriously. -
AB Tutor easy to defeat ... just uninstall
maxymaxy replied to maxymaxy's topic in Network and Classroom Management
Hi, Thanks for the quick reply. The students can log onto the local workstation as teacher/teacher and simply uninstall from that group privilege. It is very frustrating for me as ICT coordinator to try and help teachers cope with students who are hell bent on getting around the system security (what little there is). The network manager believes in an 'open policy' and self regulation ...but he is not in the classroom is he I was getting very excited with AB Tutor because it seemed to do everything I wanted but this major major oversight in design leaves me speechless. AB Tutor should at least need a password or the original install program like Lanschool does to uninstall it. We are looking at getting 10 licenses so Lanschool is expensive. -
I am just trying out the trial version of AB Tutor after trialling Lanschool. Maybe I am doing something wrong but what stops students simply going to the control panel and uninstalling it? Lanschool was protected and needed the install program before uninstalling. Is this too obvious or am I doing something wrong? Shouldn't there be a password at least?
