Re: Terminal server security issue with screen cache?



If you feel that is a security risk then you may want to enable a logoff
screen saver in your environment being sure to train users because a logoff
screen saver will need to shut down open applications. Winexeit.scr is
available in the RK and there are many third party logoff screen
avers. --- Steve


"Gary" <phoneticallyitsgeemoonatsaratogacaredotorg> wrote in message
news:eOnD6BMBGHA.2896@xxxxxxxxxxxxxxxxxxxxxxx
> Hi,
> I've never seen this mentioned anywhere, but at the hospital I work for,
> we use a lot of thin clients with Terminal Servers. We also have PC's that
> connect to them. When the client PC screen locks with the default
> logon.scr screen saver while the session is idle in the background, if you
> switch back to the Terminal Server session screen, there is about a 1/2
> second where the previously viewed screen is visible, then it updates to
> show the new screen, which is the login screen. The problem is, it's
> pretty trivial to just click on the taskbar icon of the session, bring it
> to the foreground, and hit print screen in that half second, then paste it
> into paint, or something like that. I've done it many times just to
> demonstrate the method. If there is patient information in that screen (or
> any other sensitive info) it's easy to snap a shot of it, and walk away
> with the data. I have tried DE-selecting using bitmap caching in the TS
> client, but that doesn't affect it.
> Has anyone ever heard of alleviating this gap using settings on the
> client?
> Thanks,
>
>


.



Relevant Pages

  • Re: How to make a user close a program when they disconnect a TS Session
    ... >> close and simply call the Logoffwithin the session, ... >> opportunity to shut down applications or cancel the logoff. ... Upgrade to a recent client to get prompting when closing the session ... "This will disconnect your Windows session. ...
    (microsoft.public.scripting.wsh)
  • "screen saver timeout?"
    ... A client connected via RDP gets a screen saver login screen after 20 minutes on a MAC client. ... The terminal session is still active but he can not get back in from the login screen. ...
    (microsoft.public.windows.terminal_services)
  • RE: Windows XP Automatic Log-off in SBS 2003 Domain
    ... The Logoff of the user will lead to lost data, ... Since those machines are shared, ... Windows 2000 Resource Kit provides a tool that you can use to ... Please follow the steps to configure the Winexit.scr Screen Saver: ...
    (microsoft.public.windows.server.sbs)
  • Re: Force logoff after inactive timeout period?
    ... You can do that by using Winexit.scr Screen Saver that it included in the Windows Server 2003 Resource Kit. ... The user believes that each PC does automatically logoff because of the requirement to re-enter the logon password. ...
    (microsoft.public.windows.server.sbs)
  • Client Account keeps loging in and off all the time
    ... The domain account I set up for the client is now saturating my NT DCs' ... I scaned a bit the details for the events of today and login and logoff ... occurs apparently randomly on all the client computers and almost all ...
    (microsoft.public.sms.admin)

Loading