RE: Windows Remote Desktop

From: Shawn Jackson (sjackson_at_horizonusa.com)
Date: 01/14/04

  • Next message: DeGennaro, Gregory: "RE: OWA security"
    Date: Wed, 14 Jan 2004 10:14:15 -0800
    To: "Michael Gale" <michael@bluesuperman.com>, <security-basics@securityfocus.com>
    
    

            Eh' for 'Testing' I use a remote SSH server off my backbone. I
    do 'periodically' login to my remote XP workstation and do some work.
    Because only screen information is transmitted even if that system was
    hacked or infected with a virus it won't affect my network at work. My
    XP system doesn't sit directly on the Internet through; it goes through
    a Debian box running iptables.

    Shawn Jackson
    Systems Administrator
    Horizon USA
    1190 Trademark Dr #107
    Reno NV 89521
    www.horizonusa.com
     
    Email: sjackson@horizonusa.com
    Phone: (775) 858-2338
           (800) 325-1199 x338

    -----Original Message-----
    From: Michael Gale [mailto:michael@bluesuperman.com]
    Sent: Tuesday, January 13, 2004 8:35 PM
    To: security-basics@securityfocus.com
    Subject: Windows Remote Desktop

    Hello,

            I have a question, I have locked down a company network allowing
    only
    web browsing, SSH and FTP. Nothing else is need and soon SSH and FTP
    will be gone hopefully once the VPN is final.

    Right now a internal user is complaining about the fact their remote
    desktop connection to their home PC is no longer working.

    The justification is that a remote PC out side the network is needed for
    testing. At which point I gladly offered to setup a out side box for
    testing. :)

    Any ways the question I have is, do you feel that Remote Desktop (into
    WinXP) is a secure enough connection to allow it. I mind you that this
    is supposed to be a outbound connection only but you never know with
    windows.

    -- 
    Hand over the Slackware CD's and back AWAY from the computer, your geek
    rights have been revoked !!!
    Michael Gale
    Slackware user :)
    Bluesuperman.com 
    ------------------------------------------------------------------------
    ---
    Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off
    any 
    course! All of our class sizes are guaranteed to be 10 students or less.
    We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion
    Prevention, 
    and many other technical hands on courses. 
    Visit us at http://www.infosecinstitute.com/securityfocus to get $720
    off 
    any course!  
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any 
    course! All of our class sizes are guaranteed to be 10 students or less. 
    We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, 
    and many other technical hands on courses. 
    Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off 
    any course!  
    ----------------------------------------------------------------------------
    

  • Next message: DeGennaro, Gregory: "RE: OWA security"

    Relevant Pages

    • RE: Windows Remote Desktop
      ... Talk about the ability to transfer company data out... ... >do 'periodically' login to my remote XP workstation and do some work. ... >We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ... >and many other technical hands on courses. ...
      (Security-Basics)
    • Re: Windows Remote Desktop
      ... > Right now a internal user is complaining about the fact their remote ... > desktop connection to their home PC is no longer working. ... RDP does use encryption, but I wouldn't want to rely on it. ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, ...
      (Security-Basics)
    • Re: Connecting a remote workstation to a domain
      ... If you have more than a couple of remote workstations connecting to the SBS ... server via VPN, you really need to consider a Terminal Server in the main ... "Log in using a dial up connection" checkbox, ... roaming profile then synchronizes with the server over the VPN); ...
      (microsoft.public.windows.server.sbs)
    • Re: Connecting a remote workstation to a domain
      ... I can remotely join XP Pro computers at the remote ... connection" checkbox so that any user can logon remotely. ... "Log in using a dial up connection" checkbox, either way it loads her cached ... roaming profile then synchronizes with the server over the VPN); ...
      (microsoft.public.windows.server.sbs)
    • Re: autoRepeating Error log ID 20111 (Remote Access)
      ... PPPoE connection software on the server turns what could/should be a full ... >> A Demand Dial connection to the remote interface Small Business ... >> Event Type: Warning ... >> Event Source: MSSQL$SBSMONITORING ...
      (microsoft.public.windows.server.sbs)

    Loading