Penetration Testing mailing list archives

Remote Desktop/Term. Serv information leakage


From: kuffya () gmail com
Date: 1 Jul 2005 14:41:45 -0000

Hi list, 
One of our recent clients has a seperate 'isolated' network where they keep sensitive material. This network is not 
connected to the internet, is not physically accessible and you can only connect to it using remote desktop. They asked 
us to test if the isolated network was adequately protected.
Here's what I discovered: When you start a Rem Desktop session from the main network to the isolated one you can 
actually copy and paste stuff across...this is only true for text not for complete files, and seems to be by design. 
What is more worrisome is that you can even copy across executables doing simple tricks such as 
1)download an executable 
2)change extension to .txt
3) copy (the text version) across to a notepad. 
4)change it back to .exe
So literally we have a significant leakage over here, introducing threats to the isolated network. 
I am posting this to ask your opinion on how this could be mitigated......I think that Remote Desktop is not possible 
to configure securely since it's not designed as such...and hence it transfers across anything it receives , be it 
mouse movements or copied & pasted text...
So I was trying to think what would be the best solution, without spending a fortune on a 'secure' commercial solution, 
that is. Maybe something like SSH tunneling then Rem. Desktop or VNC or what?   
And do you think this 'bug' is something investigating any further? Is it something you people knew of?

Thanks a lot.  


Current thread: