Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Academia Headaches
Scott Granneman, 2004-09-15

Academic institutions who have to add, manage, and secure thousands of new users within a period of just a few days face political and social issues on top of the immense technical ones.

Comments Mode:
Academia Headaches 2004-09-15
Anonymous (1 replies)
Academia Headaches 2004-09-25
Anonymous
Academia Headaches 2004-09-16
Billy
Academia Headaches 2004-09-16
Anonymous
Academia Headaches 2004-09-16
IT Tech
Academia Headaches 2004-09-16
Corporate Security Engineer
Academia Headaches 2004-09-16
Travis Barlow
Academia Headaches 2004-09-16
Perry
Academia Headaches 2004-09-16
Anonymous
Academia Headaches 2004-09-16
Erik Norgaard (1 replies)
Academia Headaches 2004-09-16
Anonymous
Academia Headaches 2004-09-16
Anonymous
Academia Headaches 2004-09-16
Anonymous (3 replies)
Mandatory computer classes? As a former student from the dorms, and having spent nearly four years at a helpdesk--this is insane, utter nonsense.

First, many people will never even grasp the basics, and if they do--they won't take the time to actually monitor them. Once the AV scanner and firewall are installed, they'd better work flawlessly and never pop up again. I can't tell you how many times I saw people install zonealarm and then hit "yes" every single time something popped up without a moment of thought. What a way to render a decent product useless.

Secondly, I can tell you my school *technically* didn't allow anything but windows installations on the residential network, under the premise that network ops knew how to check the security remotely. Bridges and routers were off course strictly off limits. If their scans found anything that looked like remote admin/access they'd find an excuse to pull the port... Except for the idiots that had a world writeable C$. Let me tell you how much this made me want to cooperate with the network people...

Inside the first week (I'm slow) I had redhat up with full iptables, and portsentry--I caught the system scans from the network ops, and stealth scans from a rooted DNS they ran (what's that...the campus secondary DNS is serving Crouching Tiger.divx ?) --added filters to drop all traffic from their portion of campus, and appropriate masquerading going through to the internal network. A quick check of google for emails and search of usenet revealed the three sysadmins home dsl and cable addresses. Added those to the script too just in case they do any scanning from home. Of course, the systems people stopped by my dorm a few times--it seemed a non-existant ip address on an unregistered MAC was being *very* noisy about portscanning every system resembling a server whenever a sweep went through the dorm. Go figure, somebody felt that it must have been okay to check their security for them since they were doing such a good job themself... Had to stop that unfortunately...

Don't knock the college kids--the only thing my system was ever open to was the SSH exploit, and the daemon was chrooted anyway.

Go ahead, make a mandatory computer hygiene class, I dare you...By the end of the semester I'll be using every drive in the lab to serve warez--not because I believe in it, but because I can't stand 101 classes taught by people who simply don't have a clue.

If you can't educate your users (and believe me, you can't), maybe you should lock your network down--it's easier and cheaper anyway

How do you expect new art/english, or even CS and IT majors whose experience consists of using microsoft word to secure their computer when half the sys-admins in the world can't do it anyway?

It's your network--you protect it. 'Cause I can't stand hearing another lecture from some misguided idiot on how to use McAfee and not open attachments. At least *my* SMTP server authenticated its users and didn't have relaying enabled...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/267/28483#28483
Academia Headaches 2004-09-17
Erik Norgaard
grow up 2004-09-17
Anonymous (1 replies)
grow up 2004-09-17
Erik Norgaard (3 replies)
grow up 2004-09-19
Original Anonymous In SubThread
grow up 2004-09-20
Wremes (1 replies)
Why don't universities... 2004-09-21
Erik Norgaard
grow up 2004-09-20
Anonymous (1 replies)
grow up 2004-09-22
Orig Anonymous (1 replies)
Real world 2004-09-23
Erik Norgaard
Academia Headaches 2004-09-22
A new anonymous (1 replies)
Academia Headaches 2004-09-23
Orgiginal Anonymous
Special Thanks 2004-09-17
Anonymous
Mistake? 2004-09-17
Anonymous
Academia Headaches 2004-09-17
enforcer
Academia Headaches 2004-09-17
C. Wilson
Academia Headaches 2004-09-17
Anonymous
Academia Headaches 2004-09-18
Anonymous
Academia Headaches 2004-09-18
Gill
Academia Headaches 2004-09-18
Anonymous
Academia Headaches 2004-09-18
Anonymous
Been done @ UF 2004-09-20
a student (2 replies)
Been done @ UF 2004-09-22
Anonymous (1 replies)
UF stepped in 2004-09-22
student
UF ICARUS 2004-09-20
uf student
Macintosh perspective? 2004-09-20
Anonymous (2 replies)
Macintosh perspective? 2004-09-22
Student/Tech
Macintosh perspective? 2004-09-23
Anonymous
Academia Headaches 2004-09-21
Anonymous
Academia Headaches 2004-09-22
IT Guy
Academia Headaches 2004-09-22
Anonymous
Academia Headaches 2004-09-22
Anonymous
Academia Headaches 2004-09-22
DM Orrick
Academia Headaches 2004-09-22
Anonymous
Academia Headaches 2004-09-22
Anonymous
Cyber Security with Absolute Certainty 2004-09-22
Dennis Meharchand (1 replies)
resources Re: Academia Headaches 2004-09-23
Internet2 SALSA Chair..
Security Trainer, Penn State 2004-09-23
Ken Layng
Academia Headaches 2004-09-23
Anonymous
Academia Headaches 2004-09-24
Insider







 

Privacy Statement
Copyright 2009, SecurityFocus