Jump to content

Tamarside

Members
  • Posts

    64
  • Joined

  • Last visited

Reputation

83 Excellent

About Tamarside

Personal Information

  • Location
    Plymouth
  1. Go have a look at post 5 in the thread I've linked to above. As I said, there are detailed steps there.
  2. You'll find detailed instructions on this thread, which several others have linked to further above: http://www.edugeek.net/forums/windows/7041-stopping-exe-files-being-run-usb-stick.html
  3. Surely a better and infinately more practical solution would be to simply export te ISA config and save it onto the backup server?
  4. If you're going to try and custom write a GINA replacement, be aware of what exactly this file does, in addition to displaying pretty pictures. One of the easiest ways to subvert an entire network is through an insecure custom GINA as the GINA receives the user's password in plain text. A custom GINA could for example write username & password combinations to a central log, or even upload via HTTPS. Your firewall won't interfere with that at all, and even if your firewall asks for authentication the custom GINA could simply hand over the credentials it is about to upload somewhere. I'm not trying to spook you, but instead wanted to make you aware of the risks. My advice would be to RESHACK the msGina and push it out under a different name, as a custom GINA, alongside with the relevant reg entries, then if ever queried by Microsoft claim ignorance and state you believe by leaving the original untouched you remained with your EULA.
  5. I'm presuming you're pinging from within your network? If so, 15 ms is slow and 57 ms is VERY slow - pinging IFL.NET I get 32 ms from inside our network and we are geographically placed more or less where you'd need to insert the tube, were you to give the UK an enema. Internally you should have an average ping response of 1 ms or less. I'd start looking at your infrastructure - - What cabling do you have in place? - Are you using any hubs instead of managed switches? Switches must be at least Layer2 devices, and ideally you'd have at least one Layer3 switch at the core of your network - Do some packet sniffing to see what exactly is on the wire. For all you know you may have infected hosts currently attacking the Pentagon!
  6. Assign the .MSI to computers, then a day or two later add a few lines to a startup batch script assigned to the computers to copy your edited .INI file into place on all workstations, from your NETLOGON share. Take the example .INI file and tweak it to suit your needs - the app has a great deal of documentation to show you how to do this.
  7. Actually you're completely wrong! It takes around 30 SECONDS to completely compromise a Windows 2000 PC remotely, simply because the OS is so insecure. By compromise, I mean to have full, unrestricted local admin access. Attackers fingerprint machines before attacking. This makes sense as you wouldn't want to be running XP eploits against a Linux machine, would you. The minute they detect an older, less secure OS you've made their lives SO much easier. Add to that the fact that your network isn't a secure fortress anymore, and you're in serious trouble. See, network security used to be like a castle keep. We'd have a portcullis, drawbridge, pots of hot oil, etc. protecting the ONLY access route in and out of the keep. Inside the keep everything was pretty much trusted. With mobile broadband making inroads, and all manner of portable apps being carried into YOUR network, we can't use that model anymore. It's dead. Especially mobile broadband means students can open various other ways into and out of the network, at the drop of a hat. Instead, network security has become more like modern city. Most people are good and honest, but there are thieves, robbers and even salespeople lurking about. As a result, we cannot treat the entire city as safe - it simply has too many entry and exit points to secure and most of those aren't under our control. Instead we have front door locks, and sometimes even safe rooms inside locked buildings. Our security must become so much more granular, and therefore more complex. We must have a strategy that clearly defines what we are prepared to sacrifice, and what we'd defend almost at any cost, because we don't have the resources to defend everything. In this environment security through OS geriatrics is not exactly the best way forward. Do yourself a favour and run Nessus against your network, but from INSIDE. You may be worried when you see the results!
  8. What exactly are you trying to achieve?
  9. We're a community college with around 1 250 students and 180 staff. We support three primaries at present, with another one joining us soon. In total we support about 1000 computers (desktop/laptop mix), 16 servers, 85 interactive whiteboards and around 95 projectors, with 80-ish printers thrown in for good measure. We have a site-wide WiFi network (some 50 WAP's) on a DMZ that is set to prioritise VoIP traffic over normal data and we support the VoIP setup, including the WinMo handsets. Additionally we have several WAP's that are on the "proper" network dotted around. The department consists of me and four technicians. We have a lot of automation, but in some respects we're still very primitive. Sadly documentation is nowhere near as detailed and accurate as I'd like it to be, but we've made good progress.
  10. Yes, newer Nokias have the scanning software to read QR Codes installed as default.
  11. Microsoft's released their Tag technology (Microsoft Tag - Linking real life with the digital world) and at a glance it look quite good. Obviously they're looking at marketing it heavily and history teaches us that when Microsoft sets its mind to something it normally ends up getting its own way. This is all fine and dandy so far and I must admit that I'm impressed with Microsoft Tag, especially the fact that it scans tags correctly even when oblique and out of focus. The pain is that I'm well down the road with implementing QR Codes. So much so that I've completed a browser toolbar intended to be deployed on our student PC's. The toolbar has (amongst other things) a button that, when clicked, displays the student's timetable for the day. The timetable contains a hyperlink that displayes a dynamically-created QR Code containing the timetable data, so that students only need to scan it with their phones. I can just see in future Microsoft will overpower what I'm doing with their Tags, so I'm thinking that perhaps I should look at changing NOW, seeing as we've not yet gone live with QR Codes. What do you think?
  12. Actually Simon I think you'll find you took a massive performance hit, but the DB wasn't damaged, so my point stands that read-only access to a DB will not destroy it. SQL optimisation is a different topic altogether. Obviously you'd need to evaluate any queries run against the DB by getting a baseline of the server's performance before, then again while the query is running, so you can evaluate how much of a performance hit you'd be taking. That should form part of your normal tasks anyhow and should slot in under your change management processes.
  13. Actually I beg to differ. READ ONLY access cannot in any way, shape or form damage the DB. And the vendors don't simply own the responsibility for support, they actually get paid for it. Nobody is expecting vendors to support every app that links to their DB, but if they started a) delivering more of what their customers actually need and b) being more transparent towards their customers this whole issue can go away. For example, if Capita released a proper API to dynamically read data from their DB and also provide AD integration (or some other identity management solution, e.g. Shiboleth, or others) then the DB would remain totally protected, while schools would enjoy a great deal more in terms of freedom and functionality. Capita aren't the only ones behaving in this manner - Serco does exactly the same. Having said that, I also have to point out that Serco's CMIS DB is FAR cleaner and easier to work with than the SIMS one.
  14. Provided there is a valid backup of AD somewhere, or at least one other DC there is no need whatsoever to rebuild the domain from scratch. Even if there is no other DC and the backup is older than the tombstone date for AD it remains possible to recover AD from such a backup.
  15. Not too sure what you mean by monitoring shares, but all the rest (and a GREAT deal more!) you can do using Spiceworks - get it at Spiceworks - Free Network Monitoring Software for Network Management It is an absolutely suberb tool. In fact we use it on our school network and it copes just fine (even though they say it was meant for smaller networks). We now know what printer consumable levels are at any point just by running a report and we get all sorts of automated alerts. Best of all, it's free. Well, ad-supported, but the ads are off to the side.
×
×
  • Create New...