RE: Windows Remote Desktop - any known vulnerabilities?



Could you please write the evenid and it if was a security or system
event?

/Marc Munk


-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Chuck Mayers
Sent: 28. november 2010 03:21
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Windows Remote Desktop - any known vulnerabilities?


About 6 months ago, I wanted to connect to my home computer (which runs
Windows 7) from work, so I enabled Remote Desktop, with the option
"Allow connections from computers running any version of Remote Desktop
(less secure)". It was a one time thing, and I've never used it since. I
left these options on.

Today I noticed an event in the event log:

The RDP protocol component X.224 detected an error in the protocol
stream and has disconnected the client.

This same error also appears one other time, 2 months ago.

I've googled the message, it sounds like it could simply be an error
you'd get if a remote user closed his session... except that there
shouldn't be any remote users! At the time of the event, I'm not even
sure if I was using the computer, but I know that I have not used RDP
for 6 months and no one else should be connecting.

Are there any known Remote Desktop vulnerabilities (for a PC acting as
the server) that I should be worried about?

Is there any other way this event would be in the event log, besides the
obvious - someone had connected to my PC?

I looked in the event log for anything obviously strange around the
times of these events, and I don't see anything. The PC seems fine and I
don't have any reason to think it was compromised except for this
strange event message.

I'm wondering if there is anything else I can check for, to figure out
what this cryptic message means.

Thanks

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an
SSL certificate. We look at how SSL works, how it benefits your company
and how your customers can tell if a site is secure. You will find out
how to test, purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for set-up are
highlighted to help you ensure efficient ongoing management of your
encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



Relevant Pages

  • Re: Windows Remote Desktop - any known vulnerabilities?
    ... RDP is not encrypted; ... Windows Remote Desktop - any known vulnerabilities? ... Securing Apache Web Server with thawte Digital Certificate In this guide we ...
    (Security-Basics)
  • RE: Windows Remote Desktop - any known vulnerabilities?
    ... Windows Remote Desktop - any known vulnerabilities? ... The RDP protocol component X.224 detected an error in the protocol stream ... Securing Apache Web Server with thawte Digital Certificate In this guide we ...
    (Security-Basics)
  • Re: Security Toolkit for dummies
    ... Subject: Security Toolkit for dummies ... Securing Apache Web Server with thawte Digital Certificate ...
    (Security-Basics)
  • Re: Huge hidden process and port in Linux server
    ... I install rootkinhunter, chkrootkit and unhide in my local linux box. ... Securing Apache Web Server with thawte Digital Certificate ...
    (Security-Basics)
  • Re: Botnet Servers
    ... Subject: Firewall Review ... -- Securing Apache Web Server with thawte Digital Certificate In this ... Securing Apache Web Server with thawte Digital Certificate ...
    (Security-Basics)