Re: Terminal Services Holes

From: M. Burnett (mburnett@xato.net)
Date: 11/17/01


Message-ID: <20011117224920.23822.qmail@securityfocus.com>
From: "M. Burnett" <mburnett@xato.net>
To: <dan.richardson@paradise.net.nz>, <pen-test@securityfocus.com>
Date: Sat, 17 Nov 2001 15:46:51 GMT
Subject: Re: Terminal Services Holes


> if anyone has any information on how to better
> log (on the Win2k box itself), please let me know.

Xato recently posted an advisory that shows how to use windump to log
TCP/IP addresses of terminal services connections (even before the
user logs in).

You can read the advisory at
http://www.xato.net/reference/xato-112001-01.txt

WinDump can be found at
http://netgroup-serv.polito.it/windump/

And the command to run is:
C:\>windump "tcp dst port 3389 and tcp[13] & 3 !=0"

Mark Burnett
www.xato.net
www.iis-insider.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: MS Terminal Services open to the world
    ... but facts, facts, and more facts would be my choice. ... You may find the terminal services [with version control, ... not to have servers / services / clients exposed ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Secure / Encrypt Terminal Services
    ... There was a pretty decent paper on securityfocus about 2 months ago ... encryption, and I believe zebedee to work fine for terminal services. ... (gotta love security made insecure by politics) ...
    (Focus-Microsoft)
  • W2K Terminal Services pwd cracker
    ... W2K Terminal Services pwd cracker ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: W2K Terminal Services pwd cracker
    ... W2K Terminal Services pwd cracker ... > Does anyone know of a password cracker for Win2K ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)