Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [lists] [Full-Disclosure] Terminal Server vulnerabilities |
|---|---|
| Date: | Fri, 28 Jan 2005 01:06:53 +0530 |
It's also only possible when you've got NetBIOS/CIFS open to the Internet,
Yes I know... That is why I said security thru obscurity
With this argumentation, you could sell your firewalls.
No I would not I would use an ids with properly tuned sigs for the terminal server abd then connect the terminal server via a proxy like vnc running something over freebsd or linux. I would never allow a windows terminal server to be directly be connected to the net... -aditya ________________________________________________________________________ Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] "Advances in Security" in the Linux Kernel and RedHat idiocy, Michal Zalewski |
|---|---|
| Next by Date: | [Full-Disclosure] xinetd issue.., Juan Pablo Abuyeres |
| Previous by Thread: | Re: [lists] [Full-Disclosure] Terminal Server vulnerabilities, Jan Muenther |
| Next by Thread: | Re: [lists] [Full-Disclosure] Terminal Server vulnerabilities, Jan Muenther |
| Indexes: | [Date] [Thread] [Top] [All Lists] |