RE: MS Terminal Services open to the world

From: Curt Purdy (purdy@tecman.com)
Date: 04/11/02

  • Next message: Indian Tiger: "Penetration Testing using OSSTMM"
    From: "Curt Purdy" <purdy@tecman.com>
    To: "'Ralph Los'" <RLos@enteredge.com>, <Pen-test@securityfocus.com>
    Date: Thu, 11 Apr 2002 08:35:11 -0500
    
    

    Actually we prefer TS to VNC with unencrypted passwords and PC-Anywhere that
    broadcasts it's existance on the Internet.

    Curt Purdy CISSP, MCSE+I, CNE, CCDA
    Senior Systems Engineer
    Information Security Engineer
    DP Solutions

    ----------------------------------------

    If you spend more on coffee than on IT security, you will be hacked.
    What's more, you deserve to be hacked.
    -- White House cybersecurity adviser Richard Clarke

    -----Original Message-----
    From: Ralph Los [mailto:RLos@enteredge.com]
    Sent: Friday, January 10, 2003 9:09 AM
    To: 'Pen-test@securityfocus.com'
    Subject: MS Terminal Services open to the world
    Sensitivity: Confidential

    Hello all,

            I've got a pretty good client of mine who absolutely refuses to heed
    my warnings about keeping Terminal Services open to the world. They rely on
    Windows passwords and figure that's strong enough for all their servers
    (management). Now I'm given the task of auditing their
    security/infrastructure and would like to come up some creative ways to back
    up my point about MS TS open to the Internet being a bad idea.

    Any thoughts or input is appreciated.

    Ralph

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • RE: SQL
      ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • RE: Insurance
      ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • RE: Pen-Testing Lotus Notes/Domino
      ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • R: Pen-Testing help (Compaq Insight & htsearch)
      ... This web server happens to be in front of their ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: Application & Iplanet/Apache web server vulnerability and penetration testing
      ... I don't know what to do on the web servers other than delete example ... Any suggestions on iPlanet and Apache security? ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)