Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   Tilted Technology (https://thetfp.com/tfp/tilted-technology/)
-   -   disabling AIM (https://thetfp.com/tfp/tilted-technology/82059-disabling-aim.html)

AquaFox 01-27-2005 07:15 PM

disabling AIM
 
okay, i want to prevent AIM from being installed and used on a computer.... i tried blocking out the site using security, but it still lets you download it with max security... is there anything i can do to restrict AIM from being installed or opened on windows XP???


...it's for a school classroom, to prevent students from putting it on

shadowalker 01-27-2005 07:27 PM

get the system admin to block all aol websites? Thats all i can think of. Or if you catch the students installing "unauthorized" programs on the computers at school you can always send them to detention.

AquaFox 01-27-2005 07:28 PM

Quote:

Originally Posted by shadowalker
get the system admin to block all aol websites? Thats all i can think of.


that wouldn't quite work, i use aim on my computer :D

R3d 01-27-2005 08:47 PM

try setting access rights to the user profiles.. disable downloading or installing..

soccerchamp76 01-28-2005 12:04 AM

I have no idea how my school admin did it but they had this setup:
We had several accounts created on our school laptops:
Home (unrestricted), School (restricted), and Administrator (administrator).
On the school account, WMP, AIM, KaZaA Lite, any non-school; program was denied from opening with some message like "Your account has been restricted from opening this program."

There has to be a way to limit certain programs individually.

arch13 01-28-2005 01:25 AM

Quote:

Originally Posted by soccerchamp76
I have no idea how my school admin did it but they had this setup:
We had several accounts created on our school laptops:
Home (unrestricted), School (restricted), and Administrator (administrator).
On the school account, WMP, AIM, KaZaA Lite, any non-school; program was denied from opening with some message like "Your account has been restricted from opening this program."

There has to be a way to limit certain programs individually.


Once the machine is configured to the spec wanted by the school, edit the permissions. Create a list of the currently installed products and their associated program files folders. Gives these folders and programs usual access rights. Set rules to deny all others.
Unless a student was crafty enough to install aim into say the photoshop folder in program files, you've killed it's access.

Kadath 01-28-2005 06:53 AM

Quote:

Originally Posted by arch13
Once the machine is configured to the spec wanted by the school, edit the permissions. Create a list of the currently installed products and their associated program files folders. Gives these folders and programs usual access rights. Set rules to deny all others.
Unless a student was crafty enough to install aim into say the photoshop folder in program files, you've killed it's access.

The problem is, kids are crafty enough to do that. I would think you'd want to deny program installation rights to their login group, since you never want them installing anything.

Wingless 01-28-2005 08:11 AM

Quote:

Originally Posted by arch13
Unless a student was crafty enough to install aim into say the photoshop folder in program files, you've killed it's access.

That was the first thing that went through my head in figuring out how to get around it. I was one of those "crafty" students in high school :thumbsup:

AquaFox 01-28-2005 12:46 PM

i'll see if theres anyway to deny rights to that folder


lol, the one person keeps installing it and hiding the files, by renaming the start menu folder to names that resemble educational software, but i know the computer like the back of my hand soo that doesn't work, and they also hide the installer in random places like programfiles and my documents

Dilbert1234567 01-28-2005 05:41 PM

what perms do the students have, they dont have full admin do they?

if they dont, instal aim, then remove the perms for the folder it is installed to. that should stop it from running and they.

is it xp home or pro?

ill toy around with it and ill get back to you.

glytch 01-28-2005 08:01 PM

Why not just set a group policy at the domain to disallow the AIM executable file from being run? You could do it per machine if you wanted, providing you're using XP pro.

ShaniFaye 01-28-2005 08:02 PM

keep in mind aim express.....they have blocked all usage of yahoo, msn, and aim where I work....but aim express (I guess since its web based) has no problem at all working

glytch 01-28-2005 08:14 PM

Good point ShaniFaye. Maybe an ACL at the firewall to disallow all traffic to and from the AIM port ranges. Unless AIM express runs over port 80. In which case, restrict the site. I'm sure there will always be a way to get around it but hopefully the kids would give up after being met with such resistance.

On another note, take a look at <a href="http://www.faronics.com/">Deep Freeze</a>. If they install AIM, walk up behind them and restart the computer. Bye bye AIM.

AquaFox 01-28-2005 08:34 PM

Quote:

Originally Posted by glytch
Good point ShaniFaye. Maybe an ACL at the firewall to disallow all traffic to and from the AIM port ranges. Unless AIM express runs over port 80. In which case, restrict the site. I'm sure there will always be a way to get around it but hopefully the kids would give up after being met with such resistance.

On another note, take a look at <a href="http://www.faronics.com/">Deep Freeze</a>. If they install AIM, walk up behind them and restart the computer. Bye bye AIM.


awsome awsome, i've seen a computer lab that reset itself like that alll the time, nothing would ever hold on it, i just never knew how they managed it



i know its XP, not sure if it's pro or not... most likely it's not pro... i forget! there is only one acess level and you can do anything on it

Dilbert1234567 01-28-2005 11:30 PM

deep freeze is great. we are starting to use it where i work, even with administrative privliges i cant screw up the system with out the password for deepfreeze.

ShaniFaye 01-29-2005 04:19 AM

Quote:

Originally Posted by glytch
Good point ShaniFaye. Maybe an ACL at the firewall to disallow all traffic to and from the AIM port ranges. Unless AIM express runs over port 80. In which case, restrict the site. I'm sure there will always be a way to get around it but hopefully the kids would give up after being met with such resistance.

On another note, take a look at <a href="http://www.faronics.com/">Deep Freeze</a>. If they install AIM, walk up behind them and restart the computer. Bye bye AIM.


Im 99% positive it runs over port 80

AquaFox 01-29-2005 11:26 AM

hehe, soo many things to do, only think about deep freeze is that it will still let them do it, they will still end up upstalling it just as much as before, since i removed it all the time before

Pragma 01-29-2005 12:03 PM

AIM actually runs over any port that you tell it to. For a while, I ran mine over port 13 (daytime port), or the finger port - just for fun. AIM is built to get around any and every firewall you have set up. Short of flat out blocking all traffic to AOL's netblock, you'll be very hard-pressed to stop AIM.

The best solution is an operating system/active directory solution, restricting the user's rights to install programs. Unless you're running in an Active Directory/XP Professional or Win2000 Professional environment, you'll be hard-pressed to set up effective policies. A user can always install AIM onto a USB memory stick at home and bring it in, plug in the memory stick, and off he goes.

ShaniFaye 01-29-2005 12:28 PM

But wouldnt the web based client run off port 80? I know the program itself can be configured for any port...

arch13 01-29-2005 03:13 PM

Quote:

Originally Posted by Pragma
AIM is built to get around any and every firewall you have set up. Short of flat out blocking all traffic to AOL's netblock...

Is there a problem with that? :hmm:

Dilbert1234567 01-29-2005 04:23 PM

Create a second user account for the students, make them just be a user, and not an administrator.

Right click on my computer and click manage

On the left side of the window look for the local users and groups, it is under system tools. Expand it and click on users.

In the right pane, it will show the user accounts on the system.

Right click and click new user.

Give it a name, like Student
Don’t give it a password, deselect 'user must change password...'
Select user cannot change password
And select password never expires

Click creates and then click done.

Next open the control panel and open user accounts

Click change the way users log on and off
Make sure the use the welcome screen is not selected.

Lastly for each of the other accounts on the computer besides the student one, give them a password.

Click on them and select create a password.


This will give them access only as a user which can not install programs.

Slavakion 01-29-2005 06:52 PM

You could also try Fortres 101. One of my old schools had this on the computers. Kept the kids from ripping the computers apart, but still let us do work. Keep your computer normal, and run AIM whenever.

Fortres 101 is damn near impossible to crack. Believe me, I tried. ;) I do, however, have some workarounds (somewhere) that you might be interested in.

hawkeye 01-30-2005 06:18 PM

something you might look at is X-setup Pro, it's a free windows tweak program, and you can use it to block access to a lot of programs. I've used it to give my little bro an account on my system that can keep him off of the 'net

killeena 01-31-2005 09:34 AM

The problem is that there are so many other programs that run AIM, like trillian, gaim, etc....

What I did (before we got a layer 7 filter) was block AIM using Snort. You can set it up to send a RST packet every time it sees an AIM packet, therefore never allowing it to fully connect (PM me if you want to know how to set this up). Unfortunately, this blocks the whole network, so if you want to allow other people, this may not be the way to go (unless you want to set up SSH tunnels for those people).


All times are GMT -8. The time now is 12:50 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360