At my school, you can install stuff, they didn't block port 443 (so just change the url to
https://... and you can access any site that allows https), you can run batch files, you can boot from cds, you can run programs off of flash drives, they tell you how to get ftp access to the server, the it guy didnt know the server was down (it literally died) until 2 weeks after it died, they didn't block hacking websites (they blocked google for like a month last year though, they didn't know they could just block video.google.com, so they blocked google.com).
And the list continues, and their server runs on either Win2000 or Win98. Oh, and the it guy accedentally set me up with semi-admin privleges a while ago, so I can start system processes, stop system processes, and modify some settings that affect all users. Also I know a kid (goes to a different school) who knows the admin password.
Overall: their security sucks, bad.
EDIT: And alot of people use worse passwords than my pe teacher (his pass is his username). For example a girl in my class is named Emma Rose, her username is erose, her password is rose.