Re: RDP Security - Preventing clients from mapping drives



There is no way of controlling it on the client.

Jeff Pitsch
Microsoft MVP - Terminal Services
http://www.sbcgatekeeper.com
Your Terminal Services Security Website

"The Gesus" <TheGesus@xxxxxxxxx> wrote in message
news:%23Ybg7VTPGHA.456@xxxxxxxxxxxxxxxxxxxxxxx

I have a vendor who wants our users to connect to a Windows 2003 Terminal
Server (outside of our corporate control) in order to run a medical
database application.

A requirement of this process is that our users (and other users in other
health care companies all over the country) have to connect their drives
to this foreign system. This raised a red flag immediately. The vendor
is willing to work out other ways of file transfer, but in the meantime
this is such a severe security hole we would like to globally disable this
"feature" of the RDP client.

Unless I'm missing something, there appears to be no way to restrict this
on the client side (Windows XP). There is an AD (Computer) Group Policy
for "Do not allow drive redirection" but this appears to be a server-side
policy. Since the server is outside our control, this policy is not going
to work.

Has anyone run across this and has anyone found a way to prevent users
from opening up this HUGE, GAPING security hole?





.



Relevant Pages

  • Re: why microsoft choose mfc rather than wtl?
    ... to lower security settings, etc. ... For a client to get ... the particular AX control is never accessed, shown, or downloaded. ... unethical to deliver an automobile to customers because it is possible ...
    (microsoft.public.vc.mfc)
  • RE: [fw-wiz] VPN concentrators
    ... Well, if it is remote pc---->network connections, then you can control the ... end user's security pretty securely. ... If your client can't check for these things, ... If> VPN traffic could be split inot different network pools then internal NIDS, and> ACLs could manage this > ...
    (Firewall-Wizards)
  • Xato Advisory: Win2k/XP Terminal Services IP Spoofing
    ... Subject: Xato Advisory: Win2k/XP Terminal Services IP Spoofing ... Client Address, referring to the IP address of the connected client. ... The most obvious method for logging Terminal Services connections is ... Common Security Knowledge Increases - When details of an exploit ...
    (NT-Bugtraq)
  • Xato Advisory: Win2k/XP Terminal Services IP Spoofing
    ... Subject: Xato Advisory: Win2k/XP Terminal Services IP Spoofing ... Client Address, referring to the IP address of the connected client. ... The most obvious method for logging Terminal Services connections is ... Common Security Knowledge Increases - When details of an exploit ...
    (Bugtraq)
  • Re: Programmatically upload file from client machine
    ... for security so that malicious sites don't attempt to read files from the ... client computer ... Since the file path on the client ... > control, postedfile, saveas ... ...
    (microsoft.public.dotnet.framework.aspnet)