Re: Security problem in Terminal Server Windows 2003

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



TP wrote:
The current way to avoid this behavior is to disable automatic reconnect. You can disable it for all TS users of the server via group policy, or on each client on a per connection basis.

On the client, uncheck "Reconnect if connection is dropped" on the Experience tab.

-TP

HAL wrote:
I've set password protect after 6 minutes in Display Properties/Screen
Saver. I use the Blank screen saver. The system is running Windows
2003 Server Standard SP1. I use the latest mstsc from Vista (Ive also
seen this problem on older mstsc).

I've found that if I go away from my client computer running mstsc and
the connection is lost to the server (unfortunately the server link is
not 100% stable), and I then come back, I can go straight back to the
session WITHOUT entering any password.

All I see is the reconnecting session... Try 1 of 20.. Try 2 of 20..
and then bang I'm back into the session without any password entered..
I've even done this the next day (at least 12h after), as it seem that
the reconnect is not triggered before one hoover the mouse over the
mstsc window.

This seem quite shocking to me, as I'm sure this could somehow be
abused.

Well. It's quite scary that this is NOT the default. Microsoft should really look into this issue.

--
IT/MsC/ITAdm
Engineering Services
.



Relevant Pages

  • Re: .Net Scalability problem
    ... LoadRunner will peak out a server with a few virtual users. ... To get an idea of load, ... Fire off the test client and watch the number of ... > So I think that the MTC generate concurrent connection and per ...
    (microsoft.public.dotnet.framework.adonet)
  • Re: Connection lost at same time every hour (sometimes)
    ... After making the two following alterations on the server the problem seems ... After analyze your ipconfig on SBS and client, ... Then, other connection is good, ...
    (microsoft.public.windows.server.sbs)
  • Re: server disconnection - very often
    ... Reason of permanent popups is VMware server aplication on clients. ... Run CEICW to configure the network of SBS: ... Two network adapters - manual router connection to broadband ... Uninstall VMware on client. ...
    (microsoft.public.windows.server.sbs)
  • Re: Lan setup 2 nic
    ... The external nic only has TCP/IP enabled. ... Ipconfig of the server is looking good, but the client is still missing the ... > connection so we have a 2 nic with router setup now. ...
    (microsoft.public.windows.server.sbs)
  • Re: Regular disconnections from remote web workplace
    ... I can connect to office server and all office clients from home at all times ... be physically working right up until the connection is lost. ... If I enter http://companyip from a client I receive the login screen for the ... Click Services tab and select Hide All Microsoft Services and Disable ...
    (microsoft.public.windows.server.sbs)