Jump to content

FAA

Members
  • Posts

    43
  • Joined

  • Last visited

Everything posted by FAA

  1. Thanks for mentioning UserLock FN-GM! UserLock will allow you to: - Limit or prevent concurrent logins to your Windows network, based on user, user groups, Organizational Units or session types. - Restrict user access to your network with multiple criteria: workstations, time, business hours, and connection type. - Follow the session activity on your network in real-time and get detailed, graphical reporting - Remotely close or lock user sessions, shutdown workstations, from anywhere using the Web console As you work in an academic organization, you might wanna read our whitepaper titled "Secure and Optimize a free access network". You can also download a free, fully-functional trial from our website. And, last but not least, educational discount apply!
  2. Geoff is right, as UserLock will allow you to: - Limit or prevent concurrent logins to your Windows network, based on user, user groups, Organizational Units or session types. - Restrict user access to your network with multiple criteria: workstations, time, business hours, and connection type. - Follow the session activity on your network in real-time and get detailed, graphical reporting - Remotely close or lock user sessions, shutdown workstations, from anywhere using the Web console UserLock also provides educational organizations with specific features to secure and optimize a free access Windows network. You can download a free, fully-functional trial from IS Decisions website.
  3. Cconnect offers limited and poor functionality and is really complex to implement. Worse, Cconnect introduces new breaches: with very limited skills, it is possible to carry out several successful attacks. These attacks let an unskilled user log in despite CConnect measures, gain sensitive information, and finally run a Denial of Service attack. How to circumvent CConnect protection On every request, CConnect opens a fresh session in the first place, performs the authorization process, and then logs the user off if needed. - An illegitimate user can run a Ctr-Del-Alt, find and kill the CConnect process through the task manager before CConnect logs the user off. The illegitimate user is logged in. - Once a user is logged in, a regular user can edit a .bat file that launches the following command at startup: kill.exe –f CConnect. Kill.exe is provided in the Resource Kit, along with CConnect! This effectively stops CConnect during the subsequent connections, and lets illegitimate users log in despite CConnect protection. - Once a user is logged in, a regular user can edit a dummy string value pointing to an erroneous address under the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. As a result, Windows will prompt a message error that freezes the opening session process. This allows enough time for an attacker to do whatever he wants in order to circumvent CConnect protection, for instance to kill CConnect process. These attacks point out an obvious flaw in CConnect design - the security-related function, the authorization, is entirely performed by the agent. Amazingly enough, the agent can be killed by a user without any privileges. Arguably CConnect was designed with no security in mind. How to gather information for further attacks exploiting CConnect flaws In order to perform the authorization process, the agent has to send and retrieve information from the SQL Server database. To do so, it stores the worthy information in HKCU\Software\Microsoft\CConnect in the client register. An inquisitive attacker will very easily discover the server’s name, an account and its password, all in clear. Once in possession of this juicy information, he gets full access to that database. If poorly administrated, the attacker would also get full access to the entire database server. How to run a DoS attack exploiting CConnect flaw As just said above, any user has easy and full access to the database table that holds CConnect information, namely SYSIAD table in the master database. There are two easy ways to launch aDenial of Service attack: - The attacker logs in a workstation with User A´s account, improperly stops CConnect.exe, e.g. by killing it using the task manager (alternatively a dirtier option would be to crash the system). As CConnect stops unexpectedly, it does not clean its entry in the SYSIAD table, therefore from CConnect’s view User A is still logged in. With just one concurrent connection allowed, he cannot log in any more. Failsafe is not a CConnect feature… -A more ambitious attacker can launch a mass Denial of Service simply using MS Access. All he has to do is open a new project, connect to the database, overwrite the SYSIAD table, and prevent everybody, including the network administrators to log into the system!
  4. LimitLogin is not compatible with Windows Server 2008 and Windows Server 2008 R2 (and was a bunch of crap anyway...). You should give a look to UserLock (fully compatible with Windows Server 2008, including R2 and Windows 7), that allows IT security teams to: - prevent or limit simultaneous logon (same ID, same password), per user or user group - record all session logging and locking events in an ODBC database (Access, SQL Server, Oracle, MySQL,…) for future reference - monitor user sessions in realtime (who is connected, from which workstation(s), for how long…) - remotely lock, logoff and reset all interactive sessions - define working hours and/or maximum session time for protected users and disconnect users with prior warning outside of the defined timeframe(s) and/or when time is up - restrict user group’s network access per workstation or IP range - notify all users prior to gaining access to a system with a tailor-made warning message (legal disclaimer, etc.) - … More, UserLock comes with specific features especially designed for educational organizations.
  5. This issue has been rather extensively covered in this thread. Based on IS Decisions' experience and after having heavily invested in R&D on this specific issue for about 9 years, I can categorically affirm that logon scripts-based solutions present too many drawbacks and weaknesses to suit educational IT infrastructures' security requirements. With a logon scripts-based solution: - if a workstation is not connected to the network, scripts cannot run and sessions history is therefore lost - a logon script runs as a user, and an ill-disposed user can therefore kill the script - if an untimely reboot occurs, sessions are not suppressed from the database - ... I'd like to suggest that you give a look to UserLock and see how this software solution helps academic institutions securing and optimizing their free access network. Best,
  6. Dear Edugeeks, I carefully reviewed this very interesting thread and noticed 2 things: 1) Most of you think that UserLock is the best software solution when it comes to securing and optimizing free access Windows networks in educational organizations. 2) Most of you experience serious budget issues and cannot afford purchasing UserLock licenses at their standard price. I'd like to make a proposal. As you may know: - UserLock’s licensing scheme is per maximum simultaneous sessions on your network. This usually amounts to the total workstations. A license is also required per terminal session (Terminal Server, Citrix...), if any. UserLock will not protect sessions exceeding the license count. - UserLock licenses price goes down as the amount of user session licenses purchased goes up. The more you purchase, the larger the discount! As CEO of IS Decisions, I am ready to consider all Edugeek forums members as a “unique virtual customer”.This means that we will apply volume discounts not to your individual UserLock order, but to the total amount of licenses ordered by all interested Edugeek forums members. And we will grant an exceptional 10% extra discount on top of that. Let’s take an example: - 10 Edugeek Forums members are interested in UserLock, with the following individual licenses requirements: 200, 300, 500, 800, 1 000, 1 200, 1 500, 2 000, 2 500, 4 000. - This amounts to a total of 14 000 UserLock licenses - Standard Unit Price for 14 000 UserLock licenses: € 1,69 (app. £ 1,51) - Educational Unit Price for 14 000 UserLock licenses: € 1,35 (app. £ 1,21) - Exceptional Unit Price for 14 000 UserLock licenses: € 1,21 (app. £ 1,08) This exceptional offer is valid for Purchase Orders placed until 28 May 2010. I therefore suggest that each interested Edugeek posts his/her individual licenses requirements in this thread and also sends this information to [email protected] before 16 April 2010. We will add all these licenses requirements and inform you in this thread about the Exceptional Unit Price that will result from this addition. We will then send an individual quotation based upon this Exceptional Unit Price to each interested educational institution and will process orders accordingly. Please let me know your thoughts and/or start posting your UserLock licenses requirements! Thanks in advance. Warm regards, François Amigorena CEO IS Decisions
  7. You are right, but dozens of relevant events are manageable when hundreds are not. UserLock offers far more features than just limiting concurrent logins. Please check "Securing and optimizing a free access network", but I got your point. How many machines do you have in your network?
  8. File servers usually show hundreds of logon and logoff events for the same user throughout the day, because each time a user maps a drive to a server, opens up a file on this server and then closes it, the file server closes (within just seconds or at the most a couple of minutes) that logon session and logs a logoff event … Good luck with the filtering! On the contrary, UserLock only logs an event when a user opens a desktop session, when he locks/unlocks his desktop and when he logs off. This will usually generate 4 events per day (maybe a bit more if a password protected screensaver is configured) and will allow SysAdmins to seamlessly analyze and archive session history.
  9. Well, you can't have your cake and eat it ... More seriously, in this case you might want to: 1) restrict students to only login from classroom computers 2) not to set workstation restrictions for teachers (or at least not restricting them for log on from classroom PCs) 3) educate your teachers to carefully check the UserLock warning message. UserLock indeed allows notifying all users prior to gaining access to a system with a tailor-made warning message. These messages can for example include: - a tailor-made legal disclaimer or AUP - last workstation logged on - date and time of last successful logon - history of all logons denied by UserLock and Windows since last successful logon - number of logons denied by UserLock and Windows since last successful logon This is one of the most effective ways to detect people impersonating other user accounts, providing your teachers are reasonably security aware.
  10. You have a point here, as I did not think of limiting concurrent logins but of implementing workstation restrictions. UserLock indeed allows user group's network access restriction per workstation or IP range. Thus, a student/pupil will not be able to login using a teacher’s credentials from a room equipped with free access workstations.
  11. IMHO, not implementing efficient login session controls in an educational organization might cause serious problems. Think of these situations for example: - It’s very easy for students to disclose their credentials to unauthorized third parties as there is no consequence on their own access to the network. Thus, several workstations can unduly be blocked by one user and serious security flaws can occur (e.g.: server attacks). - A student/pupil having managed to get a teacher’s credentials will be able to access confidential information (exam questions, results, etc…) from any workstation on the network. - In the event of abnormal or suspicious behavior having been detected on a workstation, Windows native features will not allow the administrator to remotely disconnect the user or lock the session from a central console or any online computer - If a student/pupil leaves his session open or locked, the workstation is unavailable to all other students/pupils willing to login with their own account.
  12. You will find detailed information in our whitepaper titled "8 Holes in Windows Login Controls"
  13. You can indeed develop logon scripts allowing to enforce single logon however these scripts are based on a hidden share in which logon scripts create and delete files. This is a very dangerous solution because scripts run as logged on users, and all users therefore need full access to the hidden share. Once a rogue user has understood how it works and were the hidden share is located (path can easily be retrieved from the user registry), he/she can remove its own session, kill the whole session database or add sessions that don’t exist to other users as a (bad) joke. Consequently, such a solution adds more potential security problems than it solves ...
  14. Dear Steve, Please find here UserLock detailed licensing and pricing. As you will see, the price goes down as the amount of user session licenses purchased goes up, and for 1,000 licenses, public unit price amounts to EUR 2.80 / USD 3.84 (app GPB 2.50). UserLock’s licensing scheme is per maximum simultaneous sessions on your network. This usually amounts to the total workstations, and NOT the total number of users. More, IS Decisions offers a 20% discount to academic and educational organizations and is ready to thoroughly consider any kind of special bid. Please feel free to directly contact IS Decisions: [email protected] to get a personalized quote. Warm regards, François
  15. LimitLogin is cumbersome to set up and use: - For one thing, it performs an irreversible Active Directory Schema modification (!). - For another, it creates a new partition in Active Directory. It also requires configuring a Web server with the .NET Framework and ASP.NET and setting it up to perform delegated Kerberos authentication. - Finally, it requires distributing client packages that support communicating with the Web server via SOAP. In short, a Rube Goldberg-ish piece of software ... UserLock has just been reviewed in PC Mag and I cannot resist the pleasure of quoting 2 extracts from this review: - "BOTTOM LINE: it’s an impressive product" - "Overall, UserLock is a solid tool that any Windows Network Administrator should consider adding to their network management toolkit if tight user access control is mandatory for their organization." Additionally, UserLock offers specific features to secure and optimize free access networks.
  16. Dear EduGeeks, I am happy to inform you that IS Decisions just released UserLock 5.0 beta version, our software solution for Windows-based networks that allows to: - Limit concurrent logins - Restrict user access - Monitor logins in real-time - Remotely lock and log off suspicious users - ... This major upgrade comes with numerous new features and enhancements including: - entirely revamped Graphical User Interface (console and Web) - dynamic display of the Active Directory tree - protection of RAS and VPN (RRAS and RADIUS) sessions - protection of WiFi Access Points - new and schedulable reports - … Please check our "What's new in UserLock 5.0 PDF" document to get a comprehensive list of new features and enhancements: http://www.isdecisions.com/download/userlock/Whats_New_in_UserLock_5.pdf UserLock 5.0 beta is freely downloadable from our Web site so you can evaluate it in a testing environment: UserLock Download - IS Decisions Would you like to test UserLock 5 beta in your production environment, please first join the UserLock 5.0 Beta Testing Program. In order to do so, please just fill in our UserLock 5.0 Beta Testing Online Form: UserLock 5.0 Beta Testing Program and we will send you every useful information and provide you with personalized Technical Support during your evaluation. Thank you in advance for your interest in UserLock! Warm regards, François Amigorena | CEO | IS Decisions | Network solution: Know, Control, Act - IS Decisions
  17. Dear Edugeeks, My company, security software vendor IS Decisions is seeking beta testers for UserLock 5.0, its solution to secure access to Windows-based networks by: - stopping or limiting concurrent sessions - limiting user access per workstation or customizable range - setting time restrictions - providing administrators with session control, alerts and full connectivity analysis and reporting features. UserLock 5.0 beta comes with numerous enhancements and new features, including: - entirely revamped Graphical User Interface (console and Web) - dynamic display of the Active Directory tree - protection of RAS and VPN (RRAS and RADIUS) sessions - protection of WiFi Access Points - … Interested in joining UserLock 5.0 Beta Testing Program? Please complete the brief registration process on IS Decisions’ Web site and we will send you every useful information and provide you with personalized Technical Support during your evaluation. Thank you in advance for your feedback about UserLock 5.0!
  18. Dear Edugeeks, My company, security software vendor IS Decisions is seeking beta testers for UserLock 5.0, its solution to secure access to Windows-based networks by: - stopping or limiting concurrent sessions - limiting user access per workstation or customizable range - setting time restrictions - providing administrators with session control, alerts and full connectivity analysis and reporting features. UserLock 5.0 beta comes with numerous enhancements and new features, including: - entirely revamped Graphical User Interface (console and Web) - dynamic display of the Active Directory tree - protection of RAS and VPN (RRAS and RADIUS) sessions - protection of WiFi Access Points - … Interested in joining UserLock 5.0 Beta Testing Program? Please complete the brief registration process on IS Decisions’ Web site and we will send you every useful information and provide you with personalized Technical Support during your evaluation. Thank you in advance for your feedback about UserLock 5.0!
  19. You might want to give a look to RemoteExec (downloadable free fully-functional trial version). RemoteExec is a versatile, schedulable, 100% agentless software solution that allows Systems Administrators to easily and quickly perform Windows Installer packages deployment, but also: - Remote execution of programs (.exe, .bat, .cmd, etc.), scripts (.vbs, .js, etc.) and files associated to executables (.txt, .doc, .wav, .reg, .inf, .msi, …) - Service Packs, patches, hotfixes and updates deployment - Remote Registry modification - Files and folders remote copy, update, or deletion - Local administrators passwords remote modification - Remote systems power off, wake up, reboot, shutdown ... - Lock or close user sessions - ... Regarding package installation status Once an execution is finished, RemoteExec will automatically generate a list of systems on which the execution failed (if any). This list can be directly reinserted to rerun the execution and complete the task. RemoteExec also collects and displays the return codes generated by the remote processes, allowing the administrator to check system status. More, RemoteExec logs execution history and results for future reference. RemoteExec pricing starts at EUR 3 (app. GBP 2,8) per system to remotely manage and educational organizations are entitled a 20% discount off list price.
  20. Dear EduGeeks, IS Decisions® offers “nocrisisdecisions” licensing for its software solutions. This new licensing scheme is designed to make IT investments into security and change management solutions software easy, even in difficult times. To communicate this message, IS Decisions has chosen a pastiche of the Supertramp album “Crisis? What crisis?”. http://www.isdecisions.com/images/photos-home/home_supertramp-en.jpg "nocrisisdecisions" is a limited time offer (from December 8th, 2008 till April 30th, 2009) available to new customers placing IS Decisions software purchase orders over EUR 3000 (app. USD 3,800). With this new licensing scheme, you can use IS Decisions software during 12 months for one third of the price of a standard license. After 12 months, you can at your choice: - either use the software 12 months more for one third of the price of a standard license (option 1) - or acquire a definitive license for two thirds of the price of a standard license (option 2) After 24 months (two 12 months periods), you can acquire a definitive license for one third of the price of a standard license. Detailed info on IS Decisions' Web site
  21. RemoteExec can do the job. You will also find tons of useful information about deployment on AppDeploy.com.
  22. LimitLogin is incredibly cumbersome to deploy and administer. It: - performs an irreversible Active Directory schema modification - requires an IIS server - does not come with an integrated deployer - does not support Windows NT 4.0 domains - does not provide E-mail and popup notifications - does not log lock/unlock events - does not allow to define login limits by group - does not allow to customize messages displayed to users - does not allow to set workstation restrictions - ... As an American friend of mine once told me: “LimitLogin looks like a Rube Goldberg’s machine”… http://img186.imageshack.us/my.php?image=rubegoldberggifjr9.gif You should have a look at UserLock.
  23. FAA

    Windows 7

    Here you are: First Look at Windows 7 | TechRepublic Photo Gallery
  24. That IS a discussion forum indeed! Here is my post back: A) Using Group Policy to deploy applications and stuff To my opinion, this method presents 3 drawbacks: 1/ GPO deployment is "asynchroneous", as you cannot precisely know when the installation has effectively been done 2/ There is no way to know for sure if the installation has been successful On the contrary, once an execution is finished, RemoteExec will automatically generate a list of systems on which the execution failed (if any). This list can be directly reinserted to rerun the execution and complete the task. RemoteExec also collects and displays the return codes generated by the remote processes, allowing the administrator to check system status. More, RemoteExec logs execution history and results for future reference. 3/ You need administrative permissions for Active Directory to create deployment GPOs B) Using GPO preferences Here are the requirements: - For managing Group Policy preferences, you need : Windows Server 2008 or later, or Windows Vista with Service Pack 1 or later - For being managed with Group Policy preferences you need : Windows Server 2008, Windows Vista, Windows Server 2003 with Service Pack 1, or Windows XP with Service Pack 2, or later - To use Group Policy preferences, the client-side extensions (CSEs) must be installed on the managed computers. - To successfully install the CSEs in Windows Server 2003 and in Windows XP, XmlLite is required. No further comments … C) Using RemoteExec RemoteExec will interact in a seamless way with any Windows system (NT 4.0, 2000, XP, 2003, Vista, 2008 - default installation) without having to install anything on target systems. The only thing to be previously parametered is the firewall for Windows XP SP2/SP3, Windows Vista and Windows Vista SP1. Due to modifications of the firewall’s activation setting on these OSs, all incoming network requests are indeed instantly blocked. This means complete loss of all remote access to the workstation, even a straightforward ping! The workstation also becomes completely invisible to all network tools, so you are no longer able to administer it. To fix this, firewall settings just need specific updating. You can simply do this using Group or System Policies as explained in this document. But well "acts speak louder than words", so feel free to download RemoteExec and give it a try. Would you need any assistance, please use our Technical Support Form and we will provide you with a prompt reply. Cheers, François
  25. Let me have my dinner and a good night's sleep first and I'll get back to you tomorrow morning
×
×
  • Create New...