RE: Terminal Services

From: Jerry Shenk (jshenk_at_decommunications.com)
Date: 03/11/05

  • Next message: Scovetta, Michael V: "RE: Terminal Services"
    To: "'AEHeald'" <arianheald@bellsouth.net>, <pen-test@securityfocus.com>
    Date: Fri, 11 Mar 2005 11:23:49 -0500
    
    

    One common problem with TS is that often it's configured so that all
    users are allowed to use it. It's best to recommend that that they set
    up restrictions so that not everybody can use it. If an attacker were
    to enumerate their usernames in some manner (e-mail addresses perhaps),
    that could give a lot of IDs to try and the probability of having one or
    more with a bad password is pretty high.

    I understand that TS can also be compromised with Man-in-the-Middle
    attacks but I haven't worked that angle myself.

    -----Original Message-----
    From: AEHeald [mailto:arianheald@bellsouth.net]
    Sent: Thursday, March 10, 2005 5:13 PM
    To: pen-test@securityfocus.com
    Subject: Terminal Services

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Greetings, group!

    I am de-lurking to inquire if anyone has some pointers on Microsoft
    Terminal Services. I'm testing a client who allows 3389 into their
    terminal server for the Remote Desktop Client.

    Other than the Bad Thing of allowing inbound traffic onto their LAN,
    I'm trying to hunt down ways to enter all the way in. I have seen
    TSCrack referenced, but the program is nowhere to be found.

    Any suggestions gratefully received.

    Eigen

    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

    iQA/AwUBQjDGeQGhZ4M3hyK+EQIh2QCg8y1LWs/oc4B303gBM5CLAD0BG4QAoJ+A
    QyWBGr7piv9nmNmHjFIUuRVi
    =xKXQ
    -----END PGP SIGNATURE-----


  • Next message: Scovetta, Michael V: "RE: Terminal Services"

    Relevant Pages

    • Re: Remote control
      ... run the Remote Desktop client on ... your workstation. ... > Use Terminal Services. ... > exist under W2K to do this or you recommend some other software to me? ...
      (microsoft.public.win2000.general)
    • Re: Terminal Services
      ... I was able to download the tscrack.exe from the second link, ... > Terminal Services. ... > terminal server for the Remote Desktop Client. ...
      (Pen-Test)
    • Re: terminal service book
      ... BTW: What changes would you recommend for my book;-) ... Author of "Windows Server 2003 Terminal Services", ...
      (microsoft.public.windows.terminal_services)
    • Re: Connecting to server across the internet
      ... > The recommended and only practical way is to use Terminal Services. ... > For any version of Project Server use public. ... > For Microsoft Project companion projects, ... >> I know that Microsoft do not recommend it but I need to configure ...
      (microsoft.public.project.pro_and_server)
    • Re: Windows Server 2003 Terminal Service
      ... your environment is unique (unique in that every environment is unique and ... Your Terminal Services Security Website ... > - Applications that will be installed on the Terminal Server. ... >>> that you would recommend. ...
      (microsoft.public.windows.terminal_services)