Security Basics mailing list archives

RE: Internet Cafe


From: "Stephen A. Santos" <ssantos () wachsco com>
Date: Thu, 16 Jan 2003 12:07:12 -0600

I agree with Nicko.  Terminal Services would work great.  Then you just
setup group policies for the security aspect.  To block Kazaa set your
firewall to block protocol TCP port 1214.  For downloading to certain
folders, you can use folder redirection.  Definitely something to take a
look at.

===================
Stephen A Santos
Network Administrator


-----Original Message-----
From: Nicko Demeter [mailto:nicko () siterra com] 
Sent: Wednesday, January 15, 2003 2:44 PM
To: 'Ferry van Steen'; security-basics () securityfocus com
Subject: RE: Internet Cafe


Why Win2k on every station? You could run terminals that communicate
with a Terminal Server or even a cluster of terminal servers and then
simply restrict what the users can access over the terminals. 

Nicko

-----Original Message-----
From: Ferry van Steen [mailto:ferry.van.steen () InfoPart nl] 
Sent: Tuesday, January 14, 2003 11:38 PM
To: security-basics () securityfocus com
Subject: Internet Cafe


Hey there,

for the first time I have to setup an internet cafe. I want to use Win2k
on the workstations and "cripple" it using the policies it has, then use
linux as a firewall/proxy with squid. Having only a proxy and not a
gateway should already narrow down a lot of security issues, but I
believe kazaa and some others still work through proxies and I have
hardly any idea on how secure the win2k policies are... Basically all I
want to allow them is using IE on websites/ftp sites, they should be
able to download, but only to a single folder and msn messenger should
work.

Anyways, anyone got any suggestions/comments on what I really have to
look out for? I'm thinking it should be reasonably secure, but in places
like this you always have the added risc of people wanting to damage the
OS/system or use it as a place from which to attack others.

Kind regards and TIA,

Ferry van Steen



Current thread: