Re: Hacking Terminal Services

From: johnfli (john_at_here.com)
Date: 02/01/05


Date: Tue, 1 Feb 2005 13:19:16 -0800

Thanks. As for passwords, people have at least 6 characters. I have the
lockout attempts set at 3 times with a auto reset of 30 min.

"Will" <Will@discussions.microsoft.com> wrote in message
news:71224DCE-7594-485A-8128-C65982C2C5F3@microsoft.com...
> There is a nice program to hack TS from a WAN connection, but I will not
> mention it here. I could crack 2 and 3 letter passwords easily in several
> hours, however, 7 and 8 letter passwords would take years. I did a term
paper
> on hacking last summer and found that if you use at least 8 letter complex
> passwords you are real safe. Additionally I use group policy to prevent
last
> user name display (default domain controller policy), and account lockout
> thresholds of 6 bad tries. That is set in default domain policy.
>
> Good Luck
>
>
> "johnfli" wrote:
>
> > How hard would it be for a hacker to hack into a Terminal Server that is
> > Available to people on the WAN?
> >
> > I have it set so that with a person logs into the session, they user
there
> > own username and password and they are only able to log onto the server
via
> > terminal services. The one program they are to use starts
automatically,
> > and when the close the program, the session closes as well.
> >
> >
> >
> >



Relevant Pages

  • Re: Strong passwords and user locking?
    ... I've been asked to force our users to use strong passwords with user ... which in turn set the duration and Reset Account ... Lockout Counter After to 30 minutes. ... The policy is linked to my OU ...
    (microsoft.public.windows.server.security)
  • User Account
    ... The policy for passwords has a ... lockout after 3 tries. ... Why would it keep locking him out? ...
    (microsoft.public.security)
  • Re: Locking down database accounts
    ... Personally it sounds to me that your company has established a policy and is ... But bottom line if you have to use SQL Server logins and passwords, ... Whether it's an encrypted flat file or an encrypted XML file, ...
    (microsoft.public.sqlserver.security)
  • RE: policy-based password cracker
    ... that required at least one upper, one lower and one number in all passwords. ... password checks can be eliminated due to the policy. ... Since the vast majority of the time for a brute-force attack is ... most brute-force attacks are very fast. ...
    (Pen-Test)
  • Hacking demo - most spectacular techniques
    ... I think one of the more fun & spectacular techniques ... is to show them session hijacking of a telnet session ... passwords in a couple days, ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)