Re: Securing RDP - Is this possible?
RDP is absolutley not secure in Windows 2003 and Windows XP. It is easy to use i.e. Cain to sniff the password i clear text.
You can use RDP over SSL. It's builtin to Windows and is default in Windows 2008.
------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute
Find the source of cybercrime! Almost every crime today involves a computer or mobile device. Learn how to become a Computer Forensics Examiner in InfoSec Institute's hands-on Computer Forensics Course. Up to three industry recognized certs available, online computer forensics training available.
http://www.infosecinstitute.com/courses/computer_forensics_training.html
------------------------------------------------------------------------
Relevant Pages
- [NT] Cryptographic Flaw in RDP Protocol Can Lead to Information Disclosure
... The Remote Data Protocol (RDP) provides the means by which Windows systems ... The first involves how session encryption is implemented in certain ... An attacker who was able to eavesdrop on and record ... (Securiteam) - RE: Remote Desktop vs VPN on Windows 2003
... I didn't invite the world to hack me...just to find a port. ... Remote Desktop vs VPN on Windows 2003 ... "Come hack at my mail server." ... RDP does not have a known vulnerability against it...you mention ... (Security-Basics) - Re: RDP challenge after changing "main" profiles password, cant access any longer with RDP in XP SP2
... erase the cached password in your instance of Windows. ... and see it it works (without using an .rdp file). ... connection to an account on the remote host that has a null password. ... count of 2 sessions gets consumed so you can no longer get onto that host. ... (microsoft.public.windowsxp.general) - RE: Remote Desktop vs VPN on Windows 2003
... "Come hack at my mail server." ... Remote Desktop vs VPN on Windows 2003 ... RDP does not have a known vulnerability against it...you mention ... The "patch" for SSH was to completely remove RC4 support. ... (Security-Basics) - network problem terminal server?
... 2003 sp1 terminal servers (rdp) ... Windows cannot log you on because your profile cannot be loaded. ... - instead of using a router all rdp servers are equiped with double network ... (microsoft.public.win2000.networking) |
|