Re: Remote connections

From: GuidoZ (uberguidoz_at_gmail.com)
Date: 10/15/04

  • Next message: Jesse Weigert: "RE: Can we really block users from installing applications through Group policy?"
    Date: Thu, 14 Oct 2004 23:54:37 -0700
    To: focus-ms@securityfocus.com
    
    

    > Why not? I don't know of any current exploit for RDP set to high
    > encryption, and even if there were any, connections may very well be
    > shielded by encrypted tunnels.

    I'm not aware of any currently either, but as their track record
    proves, that's meaningless. It was more of a retorical question and a
    snide remark - please excuse it.

    > RDP can be tunneled thru SSH as well and has much better performance
    > than VNC (don't know about Radmin).

    This may very well be true. I'm not up to par as much as I'd like on
    RDP, although I'm quite well learned on VNC and such. TightVNC has
    some of the best compression I've ever seen on a remote control app,
    aside from some of the trojans out there. I've used TightVNC through
    Dial-up many a times without delay or a problem. I'd love to see RDP
    perform the same feat.

    But I digress. Again, I very well could be wrong about RDP. I've
    always leaned towards other remote control programs due to problems
    that usually arises with proprietary programs. (I've been using a form
    of WinVNC since before RDP was even thought of.) I'm biased - I'll
    admit it. No harm in suggesting an alternative and letting the user
    decide.

    > Regards
    > Ansgar Wiechers

    Thanks for the intelligent reply, as usual. =) Take care.

    --
    Peace. ~G
    On Thu, 14 Oct 2004 17:43:41 +0200, Ansgar -59cobalt- Wiechers
    <bugtraq@planetcobalt.net> wrote:
    > On 2004-10-13 GuidoZ wrote:
    > > Can the terms "Microsoft Remote Desktop" and "Secure" even be used in
    > > the same discussion? =)
    > 
    > Why not? I don't know of any current exploit for RDP set to high
    > encryption, and even if there were any, connections may very well be
    > shielded by encrypted tunnels.
    > 
    > > The only way I could see applying any form of security is to do it
    > > under the protection of a VPN. As for not having the active user
    > > logged off, I don't have an answer for that.
    > >
    > > Personally, I'd recommend one of the many other remote desktop tools
    > > out there. WinVNC and Radmin both come to midn quickly. (WinVNC can be
    > > done through SSH. Though I'm not positive, I believe you can encrypt
    > > Radmin sessions as well.) Google both for more info.
    > 
    > RDP can be tunneled thru SSH as well and has much better performance
    > than VNC (don't know about Radmin).
    > 
    > Regards
    > Ansgar Wiechers
    > --
    > "Those who would give up liberty for a little temporary safety
    > deserve neither liberty nor safety, and will lose both."
    > --Benjamin Franklin
    > 
    > ---------------------------------------------------------------------------
    > ---------------------------------------------------------------------------
    > 
    >
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Jesse Weigert: "RE: Can we really block users from installing applications through Group policy?"

    Relevant Pages

    • RE: Windows Remote Desktop
      ... The first packet must ... This is what RDP is using to setup the encryption. ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
      (Security-Basics)
    • Re: RDP Data Encryption Error
      ... If we make a remote connection to the server at work and then RDP into one ... we get this "encryption error" after a few seconds. ... the client will drop the connection ...
      (microsoft.public.windows.terminal_services)
    • Re: Win2k3 Web Edition, where is the protection?
      ... You said exactly what I would have anyway - RDP ... Not that adding IPSec isn't a bad idea, but encryption is already ... Using the RDP client included with XP Pro or XP Home (or ...
      (microsoft.public.security)
    • Re: RDP vs pcAnywhere tradeoffs?
      ... Read some detailed information about RDP. ... or XP Pro and Windows Server 2003 (or, for that matter Windows 2000 Server ... within the OS--they are building on the foundation of Terminal Services, ... > security application and can use passwords and encryption to give moderate ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: win XP Pro SP2 with latest RDP. Workgroup vs. domain
      ... I do not need to setup RDP port forwarding in the Belkin router. ... the firewall did have in the exceptions screen "Remote Desktop" ... think that the "Allow remote connections RDP" and/or having the firewall RDP ... for network connections. ...
      (microsoft.public.windowsxp.work_remotely)