Re: Being hacked...

From: Andrew Mitchell (amitchel_at_removecasey.vic.gov.au)
Date: 03/20/04


Date: Sat, 20 Mar 2004 10:16:35 -0800


"Steven L Umbach" <sumbach@N0spam.ameritech.net> said

> If possible restrict access
> to port 3389 from only authorized public IP addresses instead of "all".

I would recommend closing 3389 altogether and implementing the Citrix Secure
Gateway to stop users even getting to metaframe until they have been
authenticated. Much better to have a blackhat bring down a HTTPS server than
to lockout all of your accounts.
http://www.citrix.com/products/securegateway/

Andy.