-
Posts
43 -
Joined
-
Last visited
Reputation
5 NeutralAbout FAA

Personal Information
-
Occupation
CEO
-
Homepage
http://www.isdecisions.com
Employer (optional)
-
Company Represented
IS Decisions
-
Restrict concurent logons but allow remote logoff
FAA replied to maestromasada's topic in Wired Networks
Thanks for mentioning UserLock FN-GM! UserLock will allow you to: - Limit or prevent concurrent logins to your Windows network, based on user, user groups, Organizational Units or session types. - Restrict user access to your network with multiple criteria: workstations, time, business hours, and connection type. - Follow the session activity on your network in real-time and get detailed, graphical reporting - Remotely close or lock user sessions, shutdown workstations, from anywhere using the Web console As you work in an academic organization, you might wanna read our whitepaper titled "Secure and Optimize a free access network". You can also download a free, fully-functional trial from our website. And, last but not least, educational discount apply! -
WIRELESS AUTHENTICATION USING RADIUS SERVER! SERVER 2008 STANDARD
FAA replied to kimbsan's topic in Windows Server 2008
Geoff is right, as UserLock will allow you to: - Limit or prevent concurrent logins to your Windows network, based on user, user groups, Organizational Units or session types. - Restrict user access to your network with multiple criteria: workstations, time, business hours, and connection type. - Follow the session activity on your network in real-time and get detailed, graphical reporting - Remotely close or lock user sessions, shutdown workstations, from anywhere using the Web console UserLock also provides educational organizations with specific features to secure and optimize a free access Windows network. You can download a free, fully-functional trial from IS Decisions website. -
Cconnect offers limited and poor functionality and is really complex to implement. Worse, Cconnect introduces new breaches: with very limited skills, it is possible to carry out several successful attacks. These attacks let an unskilled user log in despite CConnect measures, gain sensitive information, and finally run a Denial of Service attack. How to circumvent CConnect protection On every request, CConnect opens a fresh session in the first place, performs the authorization process, and then logs the user off if needed. - An illegitimate user can run a Ctr-Del-Alt, find and kill the CConnect process through the task manager before CConnect logs the user off. The illegitimate user is logged in. - Once a user is logged in, a regular user can edit a .bat file that launches the following command at startup: kill.exe –f CConnect. Kill.exe is provided in the Resource Kit, along with CConnect! This effectively stops CConnect during the subsequent connections, and lets illegitimate users log in despite CConnect protection. - Once a user is logged in, a regular user can edit a dummy string value pointing to an erroneous address under the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. As a result, Windows will prompt a message error that freezes the opening session process. This allows enough time for an attacker to do whatever he wants in order to circumvent CConnect protection, for instance to kill CConnect process. These attacks point out an obvious flaw in CConnect design - the security-related function, the authorization, is entirely performed by the agent. Amazingly enough, the agent can be killed by a user without any privileges. Arguably CConnect was designed with no security in mind. How to gather information for further attacks exploiting CConnect flaws In order to perform the authorization process, the agent has to send and retrieve information from the SQL Server database. To do so, it stores the worthy information in HKCU\Software\Microsoft\CConnect in the client register. An inquisitive attacker will very easily discover the server’s name, an account and its password, all in clear. Once in possession of this juicy information, he gets full access to that database. If poorly administrated, the attacker would also get full access to the entire database server. How to run a DoS attack exploiting CConnect flaw As just said above, any user has easy and full access to the database table that holds CConnect information, namely SYSIAD table in the master database. There are two easy ways to launch aDenial of Service attack: - The attacker logs in a workstation with User A´s account, improperly stops CConnect.exe, e.g. by killing it using the task manager (alternatively a dirtier option would be to crash the system). As CConnect stops unexpectedly, it does not clean its entry in the SYSIAD table, therefore from CConnect’s view User A is still logged in. With just one concurrent connection allowed, he cannot log in any more. Failsafe is not a CConnect feature… -A more ambitious attacker can launch a mass Denial of Service simply using MS Access. All he has to do is open a new project, connect to the database, overwrite the SYSIAD table, and prevent everybody, including the network administrators to log into the system!
-
LimitLogin is not compatible with Windows Server 2008 and Windows Server 2008 R2 (and was a bunch of crap anyway...). You should give a look to UserLock (fully compatible with Windows Server 2008, including R2 and Windows 7), that allows IT security teams to: - prevent or limit simultaneous logon (same ID, same password), per user or user group - record all session logging and locking events in an ODBC database (Access, SQL Server, Oracle, MySQL,…) for future reference - monitor user sessions in realtime (who is connected, from which workstation(s), for how long…) - remotely lock, logoff and reset all interactive sessions - define working hours and/or maximum session time for protected users and disconnect users with prior warning outside of the defined timeframe(s) and/or when time is up - restrict user group’s network access per workstation or IP range - notify all users prior to gaining access to a system with a tailor-made warning message (legal disclaimer, etc.) - … More, UserLock comes with specific features especially designed for educational organizations.
-
This issue has been rather extensively covered in this thread. Based on IS Decisions' experience and after having heavily invested in R&D on this specific issue for about 9 years, I can categorically affirm that logon scripts-based solutions present too many drawbacks and weaknesses to suit educational IT infrastructures' security requirements. With a logon scripts-based solution: - if a workstation is not connected to the network, scripts cannot run and sessions history is therefore lost - a logon script runs as a user, and an ill-disposed user can therefore kill the script - if an untimely reboot occurs, sessions are not suppressed from the database - ... I'd like to suggest that you give a look to UserLock and see how this software solution helps academic institutions securing and optimizing their free access network. Best,
-
Dear Edugeeks, I carefully reviewed this very interesting thread and noticed 2 things: 1) Most of you think that UserLock is the best software solution when it comes to securing and optimizing free access Windows networks in educational organizations. 2) Most of you experience serious budget issues and cannot afford purchasing UserLock licenses at their standard price. I'd like to make a proposal. As you may know: - UserLock’s licensing scheme is per maximum simultaneous sessions on your network. This usually amounts to the total workstations. A license is also required per terminal session (Terminal Server, Citrix...), if any. UserLock will not protect sessions exceeding the license count. - UserLock licenses price goes down as the amount of user session licenses purchased goes up. The more you purchase, the larger the discount! As CEO of IS Decisions, I am ready to consider all Edugeek forums members as a “unique virtual customer”.This means that we will apply volume discounts not to your individual UserLock order, but to the total amount of licenses ordered by all interested Edugeek forums members. And we will grant an exceptional 10% extra discount on top of that. Let’s take an example: - 10 Edugeek Forums members are interested in UserLock, with the following individual licenses requirements: 200, 300, 500, 800, 1 000, 1 200, 1 500, 2 000, 2 500, 4 000. - This amounts to a total of 14 000 UserLock licenses - Standard Unit Price for 14 000 UserLock licenses: € 1,69 (app. £ 1,51) - Educational Unit Price for 14 000 UserLock licenses: € 1,35 (app. £ 1,21) - Exceptional Unit Price for 14 000 UserLock licenses: € 1,21 (app. £ 1,08) This exceptional offer is valid for Purchase Orders placed until 28 May 2010. I therefore suggest that each interested Edugeek posts his/her individual licenses requirements in this thread and also sends this information to [email protected] before 16 April 2010. We will add all these licenses requirements and inform you in this thread about the Exceptional Unit Price that will result from this addition. We will then send an individual quotation based upon this Exceptional Unit Price to each interested educational institution and will process orders accordingly. Please let me know your thoughts and/or start posting your UserLock licenses requirements! Thanks in advance. Warm regards, François Amigorena CEO IS Decisions
-
You are right, but dozens of relevant events are manageable when hundreds are not. UserLock offers far more features than just limiting concurrent logins. Please check "Securing and optimizing a free access network", but I got your point. How many machines do you have in your network?
-
File servers usually show hundreds of logon and logoff events for the same user throughout the day, because each time a user maps a drive to a server, opens up a file on this server and then closes it, the file server closes (within just seconds or at the most a couple of minutes) that logon session and logs a logoff event … Good luck with the filtering! On the contrary, UserLock only logs an event when a user opens a desktop session, when he locks/unlocks his desktop and when he logs off. This will usually generate 4 events per day (maybe a bit more if a password protected screensaver is configured) and will allow SysAdmins to seamlessly analyze and archive session history.
-
Well, you can't have your cake and eat it ... More seriously, in this case you might want to: 1) restrict students to only login from classroom computers 2) not to set workstation restrictions for teachers (or at least not restricting them for log on from classroom PCs) 3) educate your teachers to carefully check the UserLock warning message. UserLock indeed allows notifying all users prior to gaining access to a system with a tailor-made warning message. These messages can for example include: - a tailor-made legal disclaimer or AUP - last workstation logged on - date and time of last successful logon - history of all logons denied by UserLock and Windows since last successful logon - number of logons denied by UserLock and Windows since last successful logon This is one of the most effective ways to detect people impersonating other user accounts, providing your teachers are reasonably security aware.
-
You have a point here, as I did not think of limiting concurrent logins but of implementing workstation restrictions. UserLock indeed allows user group's network access restriction per workstation or IP range. Thus, a student/pupil will not be able to login using a teacher’s credentials from a room equipped with free access workstations.
-
IMHO, not implementing efficient login session controls in an educational organization might cause serious problems. Think of these situations for example: - It’s very easy for students to disclose their credentials to unauthorized third parties as there is no consequence on their own access to the network. Thus, several workstations can unduly be blocked by one user and serious security flaws can occur (e.g.: server attacks). - A student/pupil having managed to get a teacher’s credentials will be able to access confidential information (exam questions, results, etc…) from any workstation on the network. - In the event of abnormal or suspicious behavior having been detected on a workstation, Windows native features will not allow the administrator to remotely disconnect the user or lock the session from a central console or any online computer - If a student/pupil leaves his session open or locked, the workstation is unavailable to all other students/pupils willing to login with their own account.
-
You will find detailed information in our whitepaper titled "8 Holes in Windows Login Controls"
-
You can indeed develop logon scripts allowing to enforce single logon however these scripts are based on a hidden share in which logon scripts create and delete files. This is a very dangerous solution because scripts run as logged on users, and all users therefore need full access to the hidden share. Once a rogue user has understood how it works and were the hidden share is located (path can easily be retrieved from the user registry), he/she can remove its own session, kill the whole session database or add sessions that don’t exist to other users as a (bad) joke. Consequently, such a solution adds more potential security problems than it solves ...
-
Dear Steve, Please find here UserLock detailed licensing and pricing. As you will see, the price goes down as the amount of user session licenses purchased goes up, and for 1,000 licenses, public unit price amounts to EUR 2.80 / USD 3.84 (app GPB 2.50). UserLock’s licensing scheme is per maximum simultaneous sessions on your network. This usually amounts to the total workstations, and NOT the total number of users. More, IS Decisions offers a 20% discount to academic and educational organizations and is ready to thoroughly consider any kind of special bid. Please feel free to directly contact IS Decisions: [email protected] to get a personalized quote. Warm regards, François
-
LimitLogin is cumbersome to set up and use: - For one thing, it performs an irreversible Active Directory Schema modification (!). - For another, it creates a new partition in Active Directory. It also requires configuring a Web server with the .NET Framework and ASP.NET and setting it up to perform delegated Kerberos authentication. - Finally, it requires distributing client packages that support communicating with the Web server via SOAP. In short, a Rube Goldberg-ish piece of software ... UserLock has just been reviewed in PC Mag and I cannot resist the pleasure of quoting 2 extracts from this review: - "BOTTOM LINE: it’s an impressive product" - "Overall, UserLock is a solid tool that any Windows Network Administrator should consider adding to their network management toolkit if tight user access control is mandatory for their organization." Additionally, UserLock offers specific features to secure and optimize free access networks.
