Re: Remote Desktop vs VPN on Windows 2003

From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 01/17/05

  • Next message: dave kleiman: "RE: port listner"
    Date: Mon, 17 Jan 2005 18:51:51 +0100
    To: security-basics@securityfocus.com
    
    

    On 2005-01-14 Roger A. Grimes wrote:
    > I can think of NO reason not to use Remote Desktop. Remote Desktop is
    > fast and secure.

    Fast: yes. But secure? AFAIK terminal services use RC4 for encryption
    which is known to be weak for quite a few years now. Better set up an
    SSH server and establish the RDP session through an SSH tunnel. That's
    easy to setup, easy to use and secure as well.

    > Everything is encrypted past the logon name. To get additional
    > security assurance, change the default TCP port from 3389 to something
    > randomly high...like 58645 (which you can do with a regedit on the
    > server...just google it). Then add the new port number to your server
    > address...like www.example.com:58645.

    Switching ports is just adding obscurity, not security.

    Regards
    Ansgar Wiechers

    -- 
    "Those who would give up liberty for a little temporary safety
    deserve neither liberty nor safety, and will lose both."
    --Benjamin Franklin
    

  • Next message: dave kleiman: "RE: port listner"

    Relevant Pages

    • Re: Remote desktop secure?
      ... If you set it up correctly you'll be very secure. ... First - you should change the listen port that remote desktop listens on. ... firewall sees my ip and says, this ip is ok go ahead and forward it, it lets ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Created on Access 2003, but.......................
      ... But that's not secure under any scenario, as any port scanner ... Well, you still need a userid, password and database name. ... You're assuming the server remains in a secured configuration. ...
      (comp.databases.ms-access)
    • Re: 553 sorry, relaying denied from your location
      ... connection on port 465. ... Newly created server is on port 465, ... iterations of secure, always secure, 128 bit encryption, etc. ... that doesn't appear to be an Exchange response. ...
      (microsoft.public.exchange.setup)
    • Re: Help, my machine has been hacked
      ... > being used to perform port scans on a bank. ... > closed HTTP) ... > DSLReports and they all report that my machine is secure. ... > 4) Recommendations for a hardware firewall? ...
      (comp.os.linux.security)
    • RE: Remote Desktop & Terminal Services Security
      ... RDP is as secure as your password policy, i.e. if users have strong passwords ... RDP is natively encrypted via 128-bit, ... one port is required for TS to operate, ... I have never seen or heard of a cracked network due to vulnerability in the ...
      (microsoft.public.windows.terminal_services)

  • Quantcast