Re: Terminal Services Security using Remote Desktop Client

From: Alex K. Angelopoulos [MVP] (aka-at-mvps-dot-org)
Date: 08/27/04


Date: Fri, 27 Aug 2004 18:08:15 -0500

Cláudio Rodrigues wrote:
> Although there were some DoS available through the RDP protocol, after
> years of experience deploying TS, I am still to see one single case
> where a TS was hacked using the RDP protocol only.
> The RDP encryption is enough for sure and more than that is needed if
> your company is paranoic.
> A VPN is way a bigger, huge risk these days than a terminal server.

Since I generally agree with Cláudio, I'm piggybacking on his post. :)

I tend to prefer using VPN/SSH, but the reasons for that have nothing to do
with specifics of TS security; it's simply because those connections allow
me to tunnel in remotely and access many different points on a LAN, with
only one external configured connection.

This brings us around to the reason why a VPN might be a security risk. The
single most significant vulnerability that is exploited is not someone
decrypting your traffic: it's brute force attacks succeeding against poorly
selected passwords. In that scenario, you can argue that a VPN is LESS
secure simply because the attacker would have direct access to anything on
your LAN accessible from the VPN.



Relevant Pages

  • Re: Terminal Services Security using Remote Desktop Client
    ... you may start infecting everything there. ... Cláudio Rodrigues ... >> where a TS was hacked using the RDP protocol only. ... >> A VPN is way a bigger, huge risk these days than a terminal server. ...
    (microsoft.public.windows.terminal_services)
  • Re: 3rd time trying to get an answer to Term services problems through ISA
    ... Thanks Stefan. ... we do publish the rdp protocol at ... The thing is this is through a vpn, so if I can access terminal ... >> any server at work and it just keeps trying, ...
    (microsoft.public.isa.configuration)
  • Re: Is terminal server secure?
    ... >TS uses the RDP protocol and has 3 levels of encryption, ... >>Is terminal server secure in its own right? ... >>though you do not use VPN? ...
    (microsoft.public.win2000.security)