Re: Remote Desktop Connection Security

From: Sooner Al (SoonerAl_at_somewhere.net.invalid)
Date: 06/09/04


Date: Wed, 9 Jun 2004 10:34:55 -0500

Remote Desktop is natively encrypted at a 128-bits...

http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/pree_rem_quaq.asp

You might consider changing the default client connection encryption level to "High" versus the
default "Client compatible" and *ALWAYS* prompt for a password.... Note this is done on the XP Pro
host machine...

http://www.microsoft.com/resources/documentation/Windows/XP/all/reskit/en-us/pree_rem_uvnl.asp

If you need to feel a bit safer you can always change the listening port on the XP Pro box to
something other than the default TCP Port 3389 or run RD through a VPN tunnel. If you do change the
listening port then make sure you a) reboot the PC after making the change and b) make the change to
the router forwarding also.

http://support.microsoft.com/default.aspx?scid=kb;EN-US;256986
http://support.microsoft.com/default.aspx?scid=kb;EN-US;322756

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q306759
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q304304

Why do you have a second port open for XP Home? XP Home can *NOT* act as a RD host so you will not
be able to connect to it anyway using RD from a remote site...

Using a strong password with multiple character types is always a good thing...

I do not see any advantage in using PCAnywhere over Remote Desktop...

-- 
    Al Jarvi (MS-MVP Windows Networking)
Please post *ALL* questions and replies to the news group for the mutual benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no rights...
"Superfly1611" <Superfly1611@discussions.microsoft.com> wrote in message 
news:0CE79CC6-AA78-4109-AC48-4241B1F9D23B@microsoft.com...
> Hi,
>
> I'd like to know how secure Windows Remote Desktop Connection is.
> Here is my scenario.
>
> There are two compunters behind a standard net gear router.
> One computer has Windows XP Pro and another has Windows XP Home.
> Both computers are kept uptodate with the latest windows update critical patches.
> There are two ports open (one for each machine) that allow RDC traffic through the built in 
> firewall of teh router.
> User Accounts on both machine have a strong password (more than 8 characters and 3 different 
> character types)
>
> How secure is this set up?
> And if not secure how do I go about securing it?
> Or would I be better off using stand alone software like Norton's PC Anywhere?
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.701 / Virus Database: 458 - Release Date: 6/7/2004 


Relevant Pages

  • RE: Remote Desktop vs VPN on Windows 2003
    ... Honeypots for Windows book. ... So, if a RDP buffer overflow worm came out, it would probably attack TCP port 3389. ... Now tell me again how changing the default port doesn't add ANY security value? ... Remote Desktop vs VPN on Windows 2003 ...
    (Security-Basics)
  • RE: Remote Desktop vs VPN on Windows 2003
    ... Remote Desktop vs VPN on Windows 2003 ... PORT STATE SERVICE ... If someone was looking to hack your network your security through obscurity ...
    (Security-Basics)
  • Re: Network from home to office, etc.
    ... I have an 8 port router at the office ... This entails finding out if those routers have static or dynamic IPs. ... I suggest port 3389 for remote desktop to be your easiest solution. ... (Of course, that assumes Windows XP Professional, Windows 2000 Server ...
    (microsoft.public.windowsxp.work_remotely)
  • RE: Remote Desktop vs VPN on Windows 2003
    ... Remote Desktop vs VPN on Windows 2003 ... Security through obscurity is a type of security, ... simply changing the port number one port up. ...
    (Security-Basics)
  • RE: Remote Desktop vs VPN on Windows 2003
    ... Remote Desktop vs VPN on Windows 2003 ... PORT STATE SERVICE ... If someone was looking to hack your network your security through obscurity ...
    (Security-Basics)