Re: Securtiy of forwarding RDP




"Mike Bailey" <mbailey@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:43c531e6$1_3@xxxxxxxxxxxxxxxxxxxxx
> In my PIX, I have a rule set up to forward Remote Desktop (port 3389)
> through to one of my servers:
>
> static (inside,outside) tcp interface 3389 192.168.1.5 3389 netmask
> 255.255.255.255 0 0
>
> Another rule was created to allow RDP to another server. Since 3389 was
> already used, we used 3390, which is forward through to 3389 on the other
> server:
>
> static (inside,outside) tcp interface 3390 192.168.1.6 3389 netmask
> 255.255.255.255 0 0
>
> My question is - is this safe? And would it be safe to do the same thing
> to allow RDP directly to my workstation - say forward 3391 to my ip
> address?
>
> Thanks,
> Mike

Well, no it's not safe. Is it safe enough for you? I can't answer that.

It's succeptible to man in the middle, you've made no mention of enryption,
anyone can poke away at the password, you've made no mention of strong
authentication.

Were I to be tasked with hacking your network, this would be by far the
easiest route, since simply getting your username and password (insert dozen
different methods here) would yield me complete control of a workstation
inside the LAN.

-Russ.


.



Relevant Pages

  • Re: Securtiy of forwarding RDP
    ... > In my PIX, I have a rule set up to forward Remote Desktop ... > Another rule was created to allow RDP to another server. ... And would it be safe to do the same thing ...
    (comp.security.firewalls)
  • Securtiy of forwarding RDP
    ... I have a rule set up to forward Remote Desktop ... Another rule was created to allow RDP to another server. ... And would it be safe to do the same thing to allow RDP directly to my workstation - say forward 3391 to my ip address? ...
    (comp.security.firewalls)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... Firewall Rule Set not allowing access to DNS servers? ... ...allow udp from any to any 53 keep-state ... Start of IPFW rules file ... > # Allow out access to my ISP's Domain name server. ...
    (freebsd-questions)
  • Re: Winsock 10061
    ... or some kind of permissions issue relative to resolving the IP -- the socket ... DevDiagnostics With Safe For Scripting, ... > Host not found" when trying to connect to our server. ... I had her edit the hosts file to add an entry for our server. ...
    (microsoft.public.vb.controls.internet)
  • Re: Turn off services outside the Windows
    ... In regards to Safe mode, it was not about the issue, I am able to get into ... And now I am able to log on that server, ... I suspect the Exchange info store service is the cause. ...
    (microsoft.public.windows.server.general)

Quantcast