Security Basics mailing list archives
Re: RDP over the internet
From: Ansgar Wiechers <bugtraq () planetcobalt net>
Date: Sat, 17 Mar 2012 19:04:43 +0100
On 2012-03-17 Thugzclub wrote:
On 16 Mar 2012, at 09:29, Ansgar Wiechers <bugtraq () planetcobalt net> wrote:On 2012-03-14 Alex Fiuvertiz wrote:http://www.securityfocus.com/bid/52353New vulnerabilities will be discovered every now and then. Duh. The question is: do they get fixed in a timely manner?The fact is that "open port" is a potential attack vector because a vulnerability may be discovered in the application.
I'm sorry to have to break this to you, but as long as you're using TCP/IP you need an open port if you want to be able to establish a connection.
This is why you need to rely application execution control products like (Lumension, App Blocker) to prevent execution of unknown binaries!
Software Restriction Policies exist. However, application control is unlikely to be of much help when malware is run in the context of privileged accounts. Regards Ansgar Wiechers -- "All vulnerabilities deserve a public fear period prior to patches becoming available." --Jason Coombs on Bugtraq ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- Re: RDP over the internet Alex Fiuvertiz (Mar 15)
- Re: RDP over the internet Mike Hale (Mar 15)
- Re: RDP over the internet Thugzclub (Mar 15)
- Re: RDP over the internet Banyan He (Mar 16)
- Re: RDP over the internet Melissa Augustine (Mar 16)
- RE: RDP over the internet Dave Wray (Mar 16)
- Re: RDP over the internet synja (Mar 17)
- Re: RDP over the internet David J2 (Mar 17)
- Re: RDP over the internet Thugzclub (Mar 15)
- Re: RDP over the internet Mike Hale (Mar 15)
- Re: RDP over the internet Ansgar Wiechers (Mar 16)
- Re: RDP over the internet Thugzclub (Mar 19)
- Re: RDP over the internet Ansgar Wiechers (Mar 19)
- RE: RDP over the internet Dan Lynch (Mar 19)
- Re: RDP over the internet Ansgar Wiechers (Mar 19)
- Re: RDP over the internet Thugzclub Thugzclub (Mar 21)
- Re: RDP over the internet Thugzclub (Mar 19)
- Message not available
- Re: RDP over the internet Ansgar Wiechers (Mar 19)