RDP Security - Preventing clients from mapping drives




I have a vendor who wants our users to connect to a Windows 2003 Terminal Server (outside of our corporate control) in order to run a medical database application.

A requirement of this process is that our users (and other users in other health care companies all over the country) have to connect their drives to this foreign system. This raised a red flag immediately. The vendor is willing to work out other ways of file transfer, but in the meantime this is such a severe security hole we would like to globally disable this "feature" of the RDP client.

Unless I'm missing something, there appears to be no way to restrict this on the client side (Windows XP). There is an AD (Computer) Group Policy for "Do not allow drive redirection" but this appears to be a server-side policy. Since the server is outside our control, this policy is not going to work.

Has anyone run across this and has anyone found a way to prevent users from opening up this HUGE, GAPING security hole?



.



Relevant Pages

  • NII Advisory - Path Disclosure in Cold Fusion MX Server
    ... Path Disclosure in Macromedia ColdFusion MX Server ... Vendor: Macromedia http://www.macromedia.com ... We also develop host-based security auditing software - AuditPro for Windows, Unix, SQL, and Oracle ... This advisory may be redistributed, provided that no fee is assigned and that the advisory is not modified in any way. ...
    (NT-Bugtraq)
  • RE: Services can not start
    ... work with the vendor for assistance with this. ... Microsoft Online Partner Support ... We have a couple of Windows Services that ran OK on Windows 2000 ... This was not needed on Windows 2000 server. ...
    (microsoft.public.windows.server.migration)
  • [NT] Lotus Domino Physical Path Revealed
    ... Due to problems handling Windows DOS devices, the Domino Server can be ... - Lotus Domino version 5.0.9a on Windows 2000 Server ... The vendor was contacted on 7 February, ...
    (Securiteam)
  • Error with hyperlink
    ... I have an outside vendor that just updated there web access to aspnet ... on a Windows 2003 server. ... Object reference not set to an instance of an object. ...
    (microsoft.public.dotnet.framework.aspnet)
  • RDP client secuirty - disabling mapped drives
    ... I have a vendor who wants our users to connect to a Windows 2003 Terminal Server (outside of our corporate control) in order to run a medical database application. ... There is an AD Group Policy for "Do not allow drive redirection" but this appears to be a server-side policy. ...
    (microsoft.public.windowsxp.security_admin)