Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RES: Taking control of user's desktops

Subject: RES: Taking control of user's desktops
Date: Wed, 16 Feb 2005 08:47:32 -0300

        Does any one know if there's any VNC server that authenticate users
on kerberos? 

        That could solve the problem, only autorized users could access the
VNC on the machine.

 

-----Mensagem original-----
De: Steve Bostedor [mailto:Steveb@tshore.com] 
Enviada em: terça-feira, 15 de fevereiro de 2005 10:44
Para: Faleh Daoud Abdel Monem; Marty
Cc: security-basics@securityfocus.com
Assunto: RE: Taking control of user's desktops

Take a look at http://www.vncscan.com too.  That's the front end for VNC
that makes it work better. 

-----Original Message-----
From: Faleh Daoud Abdel Monem [mailto:abdelmonem@webone-tunisie.com]
Sent: Thursday, February 10, 2005 1:54 PM
To: Marty
Cc: security-basics@securityfocus.com
Subject: Re: Taking control of user's desktops

Marty wrote:
Hi,

My client's help desk requests for support is growing, with more than 
1,000 users its understandable.

We need to find a software (not an outsourced
service) that will permit the technicians to take control of the 
user's desktop for support purposes.  The user MUST agree to the 
technician taking control or even «peeking» at his desktop.

We've looked at a few but my concern is with overall security.

We used to have VNC installed on a few machines a couple of years ago 
but we removed it.

Is the latest version of VNC sufficient (security wise)?

Can you share your experience with us please?
Suggestions or comments welcomed.

Thanks!

Marty

__________________________________________________________
Lèche-vitrine ou lèche-écran ?
magasinage.yahoo.ca



Hi list,

Thought the RealVnc Enterprise Edition
(http://www.realvnc.com/products/enterprise/) has some good security
features regarding Authentication (Platform authentication integration,
2048 bits RSA keys...) and 128 bits traffic encryption more on
http://www.realvnc.com/products/features.html, also for a large intranet the
VNC Deployment
Tool(http://www.realvnc.com/products/vnctool/vnctool.pdf) is really useful
and can help establishing an enterprise use policy for the VNC service.
Another product to watch for a secure RDP connection is
SecureRDP(http://69.196.236.103/terminal/securerdp.asp). Also a little
googeling lead me to this
http://www.isaserver.org/articles/Using_NetMeeting_and_the_H323_Gatekeeper_a
s_a_HelpDesk_tool.html
.
Hope this was helpful
Best Regards.


--
-----------------------------------------------------------------
Daoud AbdelMonem Faleh             WebOne S.A.R.L eBusiness solutions
System Admin.


Tel:    +216 71 784 726        21 Rue Ibn Badis
Fax:    +216 71 894 326        1002 Tunis / Tunisia
abdelmonem@webone-tunisie.com           http://www.webone.com.tn
-----------------------------------------------------------------



<Prev in Thread] Current Thread [Next in Thread>