kingswood
Members-
Posts
1,057 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by kingswood
-
Further to my post above, this is what the makers say: "[below are the results of the scan]. Be careful what you delete, Hijackthis cannot determine what is bad and what is merely customised by you. The best thing to do is to save a log file and show it to knowledgable folks." Kind of what Tarquel said. I quote: "Does that automated thing know about additional stuff that may be there due to tools you might not have normally on "home" computers? I'd be doubtful - so its why I suggested he attaches the log. It doesnt do us any harm now does it? lol" I agree. And that's what the Hijack software team say- post the log so that people can help you. I hazard a guess there are quite a few people on here who could help. Paul :-)
-
Wouldn't the generated log file be quite small anyway? Paul
-
I agree with Tony. When I started at our school the patch management went something like this: "a patch is out. Install it." I changed that. First, I installed SUS on our 2000 Server and started getting updates out that way (never had a problem there). But what I do is wait to authorise the patches for download to client machines until one week after the update is released. I also subscribe to the MS email lists for security and watch various forums on the internet for signs of trouble, and it works. Early this year I installed a new Dell Poweredge server (2003) for our admin network. It handles other things like internal email, intranet, and is a GC. After installing it though I momentarily forgot myself and nearly installed SP1. That would have been very bad, since an issue with SP1 on PE servers would have meant that my BIOS would have gone south and the server would have been unbootable. Luckily I checked myself and looked at the Dell support forums- voila! News of an issue with SP1. Don't install yet. So I didn't, and I therefore didn't encounter a CLM (Career Limiting Move). Moral- check those sites out and don't be too hasty to install those patches if you can't test them first. On the other hand, don't wait so long as to be too paranoid and then leave your systems unpatched! Paul
-
One of the biggest problems I have with downloading mutliple anti-spyware platforms onto XPee is that it slows your system down. One of the reasons I switched to Macs at home was that I got fed up having to buy utilities and tools just to keep the system in some kind of stable working state. The same with anti-virus tools too. However, needs must (I still have several Windows machines for testing server etc) so I use the M$ antispyware tool (currently free) and that's it. Of course I don't use windows to surf on and I generally don't use it for ordering stuff on, so it's probably not *as* vulnerable as some are. My advice: buy a mac or use Linux to surf through- much harder to tamper with and more secure by default ("out of the box"). The good news is Vista might go some way towards improving this situation. Here's hoping! Paul
-
Networknotepad looks really good actually- I think I might give it a go.. Thanks Russ!! Paul
-
errrmmmm......yes...well.... ;-)
-
Dsclient. That's the gubbin! Some info here: http://www.petri.co.il/dsclient_for_win98_nt.htm :-) Paul
-
..large plasma screens for reception areas...yeah, rings a bell that :-) Paul
-
Mmmmmm...that's a good idea Russ, because I *still* can't afford Vision and I *really* need to map our network... uh oh...brainwave... :-) Paul
-
Same here Ric- we still have those relics (98 machines) on our network and though they can be painful they do indeed authenticate against a 2003 server... Paul
-
Dia is really good- highly recommend it. When studying my HNC I needed Visio (and couldn't afford it) so I used Dia on Linux and it worked a treat ;-) Paul
-
What is your school policy for pupils who access porn?
kingswood replied to woody's topic in School ICT Policies
I think I have mentioned this to Shane too- but the policy in our school states that if the student is seen accessing porn, or if we in the course of looking through web access logs find that a student has accessed porn, they are taken off the internet and sometimes (depending on the severity) the head of ICT takes it to the head and/or the parents. @Tony:I have also been aware of the rule that when in a room on your own you always lock the door behind you. Teachers do it, and we aren't different. The idea about cameras is an excellent one Tony, and something I will look into for sure. Is there a good supplier of these that you have or are you just going to pick up some web-enabled cameras and use those? Good topic- it's nice to know that I haven't exhibited paranoia on a grand scale! As a dad of two daughters though, I would love that staff in a a school took these kinds of measure: not only to sageguard themselves but also the students around them... Paul -
I liked the "ways to piss of the IT Technician". I'd like to specialise please :-) Paul
-
Bit expensive just for p2p don't you think? And most decent security-minded admins would indeed block these protocols. Of course you could- "for educational purposes only"- use these apps at home for whatevfer reason you are doing so and bring the results into work.... Paul ;-)
-
"I did it Frazer's way" (singing- but not very well) I think there are lots of long ways around this, but go direct. I tried the GPO way, and couldn't seem to find an ADM template to do it- although I suppose you could make one (long way again for those of us without special skills). Simply, I would either edit it and save the changes to your mandatory profile, or find out which reg key it is using and lock that down in a script at startup. Good luck! Paul
-
It'll be slower than they would like, but that's their fault! If they aren't going to pay for someone to come in and sort it out (given that you aren't allowed to do it) then the speed they get is the speed they get. Switch to switch is fine if you use gigabit ports to connect them and they in turn are connected to your central switch via gigabit (copper or fibre). When you say this room is "at the end of the network" it sounds like you have a "chain" of switches each connected by cat5 and that because this is the last link in that chain, it will be very slow. Is that how your LAN is configured? It might be better to move to a wheel and spokes kind of configuration, with your server room being your middle of the universe and your switches being the bodies that orbit that middle. That way each of those switches would be connected directly to your central switch and get dedicated bandwidth to farm out to your clients. If your switches have good backplane speed (can shift huge amounts of data across the ports at one time), then even better. We use the HP Procurve 2650 for that job, and a central "core" switch by HP (8000m) as the middle of the LAN universe. The 2650s then farm out to 2124s in some places (24 port switches). In Cisco terms, your middle of the universe would be your "Main Concentration" point, and your switch cupboards the "Horizontal Cross Connects" all connected via a "backbone or vertical cabling". Each building will connect to this MC via an IC (Intermediate Cross Connect) which in turn feeds the horizontal cross-connects to each room...if that makses sense. You might already have done this and I might (therefore) be rambling and looking stupid. Nothing new. It comes from working with those "professionals" in teaching ;-) Good luck with your task! Paul
-
Yep. They would. Paul :-)
-
Hey. Here goes: you can restrict software for specific users (never tried that myself) or for all users on a specific machine. You can find the templates for controlling software access in: Computer Configuration > Windows Settings > Security Settings > Software Restriction Policies. Right click the node and choose "New Software Restriction Policy" I usually tie the GPO for software restriction to an OU where computer accounts are stored that I want to have the policy apply to. Generally it will depend on your restriction policy as to how you will handle the whole affair. There's the: "Allow everything to run except specified items" outlook, and this lets users run everything you haven't locked down freely. You could enter your doom.exe file etc here and make sure that users can't run that specified application/tool/utility. There is also the "don't allow applications of a certain type to run" thinking, and here you can stop all files of a type (say all .VBS files) but you can at the same time tell XP to allow VBS files that are signed digitally from your department to run (that way you can still get the flexibility of a script but stop users from executing them). There is also a "full lockdown" philosophy. The "disallowed" option is selected in the GPO rather than "unrestricted", and so nothing is allowed to run except the OS and items you explicitly name. It's heavy handed, high octane stuff- and can get you into trouble fast! You can find out lots of ways of restricting software too- there is the "hash" method whereby even if a user ranames doom.exe to gloom.exe the file still won't execute (there are ways around this though). There's a "path rule" where you can specify to restrict applications based on where they are on the hard drive; there's certificate rules (don't know that much about these type); and zone rules- you're probably familiar with these in IE. You could find out about these methods by searching Google etc. Phew! I type this quickly, so accept my apologies if there are errors in there. IN any case, use the ADM template path given above and poke around. Do you have a copy of the 2000/2003 Server resource kit? If so there is an excellent book in there about Group Policies. I would also recommend "Group Policy, Profiles, and Intellimirror" by Jeremy Moskowitz which has taught me pretty much all I needed to know as far as GPOs are concerned. If you get stuck- shout and I'll see if I can help! Paul
-
If you are using Windows XP you can pretty much get quite granular control over which applications your users can install and run (but with 2000 and pre-2000 machines it is more difficult). If you need more information on how to do this, and no-one else replies before I get home from work, I can help. Good luck! Paul
-
As do I *grins more* However- what's the point? We all have the telephone number of MS UK who are usually only too happy to send out evaluation software... Paul :-)
-
"From what I am finding with regards to porting / converting vb 6 to .NET it looks like it is a lot easier just to re write the code then to port it just as an FYI and it probably isnt an issue for you anyway since you dont use vb 6 " VB 6 first came out when--1998? If you haven't started moving over yet you have some serious issues to contend with (not least moving from COM to .NET framework). But here's a page that will help: http://www.microsoft.com/downloads/details.aspx?familyid=A656371A-B5C0-4D40-B015-0CAA02634FAE&displaylang=en MS have plenty to help the VB 6 programmer get their apps as far in to .NET as they can. But that won't matter to you much since you don't program for VB 6 in any case- learning VB with 6 is different from being a developer in need of some porting or at the least transition tools... Paul
-
"I thought vb.net and vb 2005 express edition beta 2 ( or whatever version of vb 2005 you have ) are different ( 2005 obviously being the newer version ). If that's the case then why do you want vb.net books ?" Because: (1) VB 2005 is only beta (2) Documentation in the form of manuals and training materials for VB 2005 are in short supply at the moment (3) My HND requires that I learn VB 2003 .NET since programming courses of this nature tend to run behind a little Hope that answers your point. Paul
-
Thanks Russ- I'll look into that- sounds like ours would be similar, but I just want to be sure... Paul
-
Schools Workforce Agreement - Head Teacher = Network Manager
kingswood replied to MkII's topic in School ICT Policies
I have a Systems Manager over me- and it's getting more confusing by the day. I don't get to make purchase decisions at all, don't know how much we have in budget left, don't get to order essentials, and when (like today) cablers etc come around I'm rarely in on the process. And they call that being the "network manager". What I am allowed to do (it seems) is be a jumped up technician with low pay who does the hard slog, and who then facilitates the systems' manager getting the praise and solidifying his position. I like the guy (a lot), and we have a great working relationship, but the politics of it are driving me mad and the sense of being left out of an important loop is making me start to look elsewhere... Is it just me, or are there other NMs who feel this way? Paul :-( -
I think that site is just for US use- I couldn't get it to respond without a US post code... Paul
