Re: TS Security Issue



Isn't hte ASP in control of the security to their servers? Why aren't they
telling you how they want it done instead of leaving it up to you? I guess
I'm confused on how your supposed to make it more secure when the servers
are on their end and in their control.

Jeff Pitsch
Microsoft MVP - Terminal Services
http://www.sbcgatekeeper.com
Your Terminal Services Security Website

"AndreZ" <shmoes@xxxxxxxxxxx> wrote in message
news:%23tUOciIPGHA.3144@xxxxxxxxxxxxxxxxxxxxxxx
Ok, so here's the deal .. we're going to be using a new application which
will be hosted by an ASP, we will have access to that ASP via a VPN
allowable from our location only. The problem the ASP has is because our
only security is username/password to log into the TS server they don't
feel
that's enough protection for thier exsisting clients.

I'm not sure really what else to do at this point to secure it.. One
thing
I can think of is being able to identify the difference between a user
that's on TS on-site and a user that's on TS remotely .. then we could
possibly restrict the VPN accordingly.. I'm just not sure how it would be
done..

Or if anyone else has other ideas, i'm open to listen to anything at this
point.

Thanks.




.



Relevant Pages

  • Controlling access to servers
    ... Consider a situation where IT Dept has full access and control over all servers ... One solution might be to give the admin passwords to the IT Security Section or the IT Audit, in this way, Admins will have to request them to log in the machine for all interventions ...
    (Security-Basics)
  • Re: Need urgent help regarding security
    ... There is plenty of security info out there ... email from even a dozen servers is small. ... an OS version upgrade should not be taken lightly. ... Given that your root password was apparently found on the servers, ...
    (freebsd-questions)
  • [Full-Disclosure] w32.frethem.k@mm and good reading
    ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
    (Full-Disclosure)
  • [Full-Disclosure] w32.frethem.k@mm and good reading
    ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
    (Full-Disclosure)
  • RE: IIS6 Security and other web servers
    ... IIS6 Security and other web servers ... I know of no Windows architecture that is exposed directly to ... I know of a number of LAMP-type servers that are ... exposed directly to the Internet with no intervening layers. ...
    (Security-Basics)

Loading