Jump to content

MordyT

Members
  • Posts

    530
  • Joined

Everything posted by MordyT

  1. Realvnc worked well for us.
  2. V7.7? If I pmed you exploits, could you see if they still work? Since lanschool is cheaper to buy then the impero renewal is, I might be forced to go that way as well and want to know if some of the stuff I found is still valid....
  3. We use windows firewall and uac sitewide. No issues beyond the initial setup. Idea is to keep PCs isolated as much as possible in case of sharing. And we have a firewall rule allowing all traffic from the DC, Administrator boxes.
  4. Can you explain/expound on said issues. It's info I would need to know if more people get a Mac... That being said, the Mac user has had such a miserable time with the Mac and lack of our support I think we scared everyone back into windows. (Old captive portal used old java which apple blocked... He had no internet access for months... Fortunately for him we were in middle of replacing the whole system anyways and now it does SSO if a domain user)
  5. We have a Mac... On a .local domain. No issues with it 99% of time.
  6. Oops, my fail on reading... I thought he meant domain.
  7. Actually it shouldn't if all the PCs are in a domain - you could use GPO to control the settings. I think there is a thread here on this.
  8. Couple thoughts.... GPO order (which can be set)... Also Isn't the software GPO based on PC and the permission one based on user?
  9. You might need a generic login that can only run the tool. Don't think there is a native method in windows for this.
  10. We use local profiles, which are wiped all the time. Happens on a fresh profile too. No biggie.
  11. I am going to bet uac. Has to do with the standard token vs elevated token.
  12. Wait, the new app (not released yet) is a rebadge off of tapatalk still? From the screenshots, it looked like a new app altogether.
  13. What's it a rebadge of?
  14. So net send was replaced by msg and it needs a slight bit of work (a reg tweak) to make it work on win 7. Let me know if you want that. I did write a piece of software to handle messages, very similar to what you want, it is in the project section here. http://www.edugeek.net/showthread.php?t=127981
  15. We have this. Squid on a windows VM, Dansgardian on the pfsense box. We originally had squid there was well, but authentication was funny at times. I didn't do the setup, so can't help there, but it is possible
  16. Um, if all they need to do is click the c: to access tools such as command prompt, and actually do any harm with them, then you need to lock down a whole bunch more....
  17. It's a good idea, but any program would be closed on log off or restart. Unless I store the pulled cable state in a file and once the program starts back up it picks up from there.
  18. How about a RDP session to the VM? Different vlan. Or VNC to the VM if he needs console access.
  19. I don't want to direct appdata to the network... But everything important already is being redirected... I already set the local drives to hide/ prevent access, but the kids found ways around that... Make a new shortcut to \\localhost\c$ for one way to access the C drive when hidden... I'm going to try to deny write in the users folder and see what happens. In a VM of course.
  20. Hi there, Have somewhat of an odd request. We use local profiles - meaning that student a logs on, it makes a local profile. We redirect desktop, docs. Recently found that students can change permissions on these profiles... meaning that student a can give student b access to his local profile. This does NOT affect anything that is redirected as those acls are set correctly, but does give access to say appdata, or the favs folder... I need a way to block this. As a student is technically the creator of the profile, he is the owner and can change permissions or add people. So I am kinda lost on how to do this. Why is this important? We have some special accounts that are not allowed to access resources not on the network (external media is blocked for them). However, what they do is log on with an account on the network, save the files to the local c (everywhere but their profile is locked down hard, so they have to save to their profile), add in the special account so it can read their files, and then the special account has those files it should not have. Any ideas? The one idea I came up with was to somehow force everyone to use a temp profile. I know, crazy, most people are trying to prevent users from getting a temp profile, but imagine if you login -> temp profile -> deleted when you log off..... Thoughts?
  21. MordyT

    Windows Sleep

    Great. Could you perhaps take a look at the print issue I pmed you about? If you could fix that, I would be more then happy to renew support. Sorry, but that bug has been around for over a year now...
  22. I have this same issue. We use local profile though. I thought it was related to our software restriction policies though. Oh, and we ban pinning icons. We also have an issue when closing ms office programs that it freezes on a white screen. Do you ever see that?
  23. MordyT

    Windows Sleep

    That's great to know. I would like to mention some bugs that were fixed in v4 so I don't seem too negative. Like when a PC goes to sleep and there is let's say a log off timer scheduled and you put the PC to sleep... In v3.5 once it woke up, you were clear. In v4, once it wakes up, it then proceeds to follow that action.
  24. MordyT

    Windows Sleep

    Unfortunately our PCs have a sleep button on the physical keyboard Try this with impero. Start a log off with a timer. Right click and hold in the title bar of the timer. Watch timer freeze and be useless. Just one of many exploits I have found with the system.
×
×
  • Create New...