PC Education User Group 1997 PC Education Conference

Securing Network Workstations Yarra Valley Anglican School

Mark Dods, Computer Technician

Listed below are the techniques used at Yarra Valley to try and maintain the standard configuration ofnetwork workstations.
  1. The following entries are put in the PROGMAN.INI file:

    [Restrictions]
    NoFileMenu=1
    NoSaveSettings=1

  2. PROGMAN.INI has the Read-Only attribute set.
  3. No File Manager icon in the hard disk drive copy of Windows.
  4. .GRP, .INI, and NORMAL.DOT files are copied from a write-protected directory on the network whenever WINDOWS is logged into.
  5. Vet and VetRes are run in 'Invisible' mode whenever a user logs in.
  6. User prompted to insert a floppy disk during the login process. This is checked for macro viruses using VetMacro.
  7. Vet, VetNex and VetMacro are run on all network station hard drives once a week.
  8. When windows is exited, the workstation logs out of the network and cold boots to ensure that no viruses are left in memory for the next user.
  9. All student network stations boot from the ethernet card boot ROM to avoid boot sector viruses.
  10. The NORMAL.DOT copied from the network contains the Microsoft ScanProt macros that guard against opening Word documents containing macros.
  11. Hard drive contents are backed up to a .LZH archive on the network. When a user logs into REST_WIN, the hard drive is formatted, and the contents of the archive are restored to the hard disk.