Security Basics mailing list archives

RE: Terminal Services over VPN


From: "Han Valk" <Han.Valk () falconhouse net>
Date: Mon, 18 Aug 2003 19:03:20 +0200

Hi,

Have a look here:
http://www.securitytracker.com/alerts/2003/Apr/1006447.html,
and here
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2003-04/0049.htm
l, and learn why you don't want to trust RDP over an untrusted network.

Best regards,
Han Valk.

-----Original Message-----
From: Paul Farag [mailto:paul () farag ws] 
Sent: Friday, August 15, 2003 18:55
To: David Y. Ng
Cc: security-basics () securityfocus com
Subject: Re: Terminal Services over VPN


If i recall correctly, TS uses something like 128-bit encryption.   
However, since I know nothing about the encryption method, nor do I  
trust Microsoft's security reputation whatsoever, I tunnel my TS  
connections through SSH.  You'd have to use something like 
WinSSHD if  
it's a Windows server though, as I don't know of any free SSH 
servers  
for Windows.  My connection point to every network I work on 
is a Linux  
box from which I can SSH anywhere I want inside the network.  
SSH is my  
best friend...until an exploit is found... =)

On Thursday, August 14, 2003, at 12:42  PM, David Y. Ng wrote:

Has anyone used Terminal Services over Microsoft's VPN
server? I need to run some program off the server and when I
used just the VPN, it was terribly slow. The solution on paper
is to run the program off Terminal Services and just let it
pass through the VPN which could be faster, supposedly.

Any experiences with this? Is Terminal Services in itself
secure? I read there's some form of encryption also but
is it comparable to VPN in a way?



--------------------------------------------------------------
--------- 
----

--------------------------------------------------------------
--------- 
-----



--------------------------------------------------------------
-------------
--------------------------------------------------------------
--------------




---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: