Firewall Wizards mailing list archives

RE: RDP and security


From: GChen () allianz ca
Date: Tue, 6 Jan 2004 09:20:47 -0500




Windows 2003 Server may fixed the issue. It supports SSL for Terminal
Services over the web.


                                                                                                                        
                            
                      TSimons () Delphi-Tech com                                                                        
                               
                      Sent by:                              To:       morty () frakir org                               
                               
                      firewall-wizards-admin@honor.i        cc:       firewall-wizards () nfr com                       
                               
                      csalabs.com                           Subject:  RE: [fw-wiz] RDP and security                     
                            
                                                                                                                        
                            
                                                                                                                        
                            
                      01/05/2004 08:24 AM                                                                               
                            
                                                                                                                        
                            
                                                                                                                        
                            
                                                                                                                        
                            
                                                                                                                        
                            
                                                                                                                        
                            
                                                                                                                        
                            
                                                                                                                        
                            




In our eyes the biggest design flaw is that there is no authentication
prior
to the windows authentication.  PCs in a locked office are more secure than
a Terminal Server out on the public internet... because you need a key to
get into the office.

-----Original Message-----
From: Mordechai T. Abzug [mailto:morty () frakir org]
Sent: Friday, November 21, 2003 12:48 AM
To: firewall-wizards () nfr com
Subject: [fw-wiz] RDP and security



Anyone have any strong opinions on the security of RDP (Microsoft's
terminal server/remote desktop protocol)?  Poking around on the net, I
see that they've had at least one design flaw that supposedly hasn't
been fixed (ie. server identification.)  Any other design problems?

Thanks!

- Morty
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards




                      *******************************

This e-mail and any files transmitted with it are confidential and may be
privileged and are intended solely for the use of the individual or entity
to whom they are addressed.  If you have received this e-mail in error,
please notify the sender immediately.  Please note that any views or
opinions presented in this e-mail are solely those of the author and do not
necessarily represent those of Allianz Canada.  Allianz Canada accepts no
liability for any damage caused by the transmission of this e-mail.


Ce courriel et tous fichiers qui l'accompagneraient sont confidentiels et
peuvent faire l'objet d'un privilège.  Ils sont destinés uniquement à la
personne ou à l'entité à qui ils sont adressés.  Si vous avez reçu ce
courriel par erreur, veuillez en avertir l'expéditeur immédiatement.
Veuillez noter que tous points de vue ou opinions contenus dans ce courriel
sont uniquement ceux de l'auteur et ne représentent pas nécessairement ceux
d'Allianz Canada.  Allianz Canada rejette toute responsabilité au titre de
dommages entraînés par la transmission de ce courriel.


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: