Return prts on Remote Desktop

From: Chuck (chucnb@ix.netcom.com)
Date: 04/21/03


From: "Chuck" <chucnb@ix.netcom.com>
Date: Mon, 21 Apr 2003 10:04:32 -0700


Hi,

No body in the terminal services post seems to know what
ports Terminal Services uses to return info to client. I
know that 3389 must be open but I am told that arbitrary
ports are opened for the return of data but know one seems
to know what ports these are? The setup is this:
Cisco firewall with NAT. Outgoing ports are all blocked
except HTTP, HTTP, DNS, 3389, FTP, H323, some ICMP for
limited ping and SMTP. Terminal services remote desktop
connects to the server via a VPN (VPN terminates on
router) with no problem when blocking is turned off. As
soon as I turn it on remote desktop stops working. I can
ping the server with the blocking on or off.

Thanks



Relevant Pages

  • Re: pen-test on a windows 2003 server box whit MS-SQL and Terminal Services
    ... Running automated tools ... and expecting to be successful is bad practice. ... manual testing on these ports. ... > also tried the tsgrinder for terminal services, ...
    (Pen-Test)
  • Re: Extranet/SSL setup
    ... They just want to "Open UP" some ports to allow connectivity to a few ... clients that have tasks updates to enter in on a particular project. ... (Web access of course) ... The Citrix or Terminal Services is an option but they would have to do ...
    (microsoft.public.project.pro_and_server)
  • RE: SQL injection
    ... No confidentiality or privilege is waived or lost by erroneous ... monitor all e-mail communications through its networks. ... >> Terminal Services ... >> determine what UDP ports are open. ...
    (Pen-Test)
  • RE: SQL injection
    ... Yep IDS can nowadays detect SQL injection attempts, famous Snort can do this for instance. ... >> Terminal Services ... >> determine what UDP ports are open. ... >> facilitating the firewalling that is hiding juicy MS specific ports ...
    (Pen-Test)
  • Re: Security discussion regarding hubs, firewalls, anti-virus and Vista Security
    ... For the average homeuser it is suggested blocking both TCP and UDP ... user) routers available. ... but you probably meant blocking *outbound* packets ... for mentioned ports. ...
    (microsoft.public.windows.vista.security)