Re: virus through vpn



From: "Leythos" <void@xxxxxxxxxxx>


|
| If you use MS Remote Desktop you only need to expose TCP3389 through the
| VPN. This is how we allow remote users to use their personal Windows XP
| computer to access some company networks - they PPTP into the firewall
| and the firewall limits them to TCP/3398 and the single destination IP
| of their dedicated workstation. We don't allow drive mapping or sharing
| of printer/com, so there is only 3389 permitted.
|

OK then he is not in Remote Node mode but in Remote Control mode like PC AnyWhere or other
third party products.

This is more secure and would not "tend" to be a vector of infection. However, knowing the
way things are, I am sure that an Internet worm will be written to take advantage of this
open port. As of right now, there are no worms using this port.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


.



Relevant Pages

  • RE: Windows 2003 Server access from the Internet
    ... open port 3389 on router to point to the server in which you want to remote ... > I can successfully access it on my LAN. ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Remote Web
    ... > worried about the security issues. ... The server that we want to run this ... We have always been told to NEVER open port 80 on a ... but yet we need to open it to publish the Remote Web. ...
    (microsoft.public.windows.server.sbs)
  • Re: ssh tunnel - remote access through nat
    ... I've got a box that's nat'd out to the internet. ... run from the nat'd box where remote box is a place I pretty much always have access too from anywhere, ... Why not forward an open port like ... If the NAT gateway is being assigned a dynamic IP, use dyndns.org & and update script... ...
    (freebsd-questions)
  • packet filter problem
    ... I have to permit my LAN pc to open port 3390 on a remote internet server ... On my Isa server 2000 I set an esplicit IP packet filter rule: ...
    (microsoft.public.isa.configuration)
  • Ip packet filter problem
    ... I have to permit my LAN pc to open port 3390 on a remote internet server ... On my Isa server 2000 I set an esplicit IP packet filter rule: ...
    (microsoft.public.isaserver)