RE: Remote Desktop & Terminal Services Security



RDP is as secure as your password policy, i.e. if users have strong passwords
TS is very secure, if you have simple passwords, then it's somewhat
vulnerable to password attack, although TS will drop repeated failed logon
attempts.

RDP is natively encrypted via 128-bit, bi-directional RC4 encryption. Only
one port is required for TS to operate, the default port is 3389. I assume
the second port you're referring to is for Remote Desktop Web, i.e. port 80
or 443.

I have never seen or heard of a cracked network due to vulnerability in the
current RDP protocol.

Patrick Rouse
Microsoft MVP - Terminal Server
http://www.workthin.com

"Ron Boetger" wrote:

> How safe is it to use Remote Desktop and Terminal Services? I have a
> router using NAT and I have forwarded the 2 ports needed for Terminal
> Services and Remote desktop to my test server.
>
> I would like to know how secure this is?
>
> What are best practices for using both?
>
> Thanks
>
>
> Ron
>
.



Relevant Pages

  • RE: Microsoft RDP Priv. Escalation
    ... this is neither a "vulnerability" in RDP nor have you ... illustrated any "privilege escalation." ... Make sure you secure the host. ...
    (Pen-Test)
  • Re: Remote Access and Outlook Web Access on SBS 2003
    ... 4125 will not respond until a user is authenticated and requests an RDP via ... RWW connection. ... This is secure. ... Telnet won't work to port 4125, as was mentioned in a previous newgroup ...
    (microsoft.public.windows.server.sbs)
  • Re: Created on Access 2003, but.......................
    ... But that's not secure under any scenario, as any port scanner ... Well, you still need a userid, password and database name. ... You're assuming the server remains in a secured configuration. ...
    (comp.databases.ms-access)
  • RE: Server VPN Setup Causes Internal Network to Stop - WIN2K Pro Serve
    ... Nr of workstations to be accessed using RDP ... You'd need to change the default RDP port to anything else but 3389 ports ... years and find myself thrown in to all things Server / System Admin related ...
    (microsoft.public.windows.terminal_services)
  • Re: RWW problem with SBS2003
    ... The only thing we're using RWW for is to connect to the server desktop from ... Generally RDP suits our needs, but we like having RWW for the ... the default RDP port from 3389. ... once port 3389 is in use for one connection from the internet - ...
    (microsoft.public.windows.server.sbs)