Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: remote desktop question

Subject: RE: remote desktop question
Date: Sat, 22 Oct 2005 12:36:19 -0400
Some ideas...

VPN clients if there are licenses available on your gateway device. This is
the best option if the licenses are available. The system doesn't need to be
directly exposed to the WAN this way.

Create access rules on your firewall to restrict source IP addresses to
known clients. (If static)

Keep the system patched. 

Strong passwords!

Nathan Grandbois
Cerdant, Inc.
614.717.0123 ext. 26 

-----Original Message-----
From: cc [mailto:cc@belfordhk.com] 
Sent: Friday, October 21, 2005 2:28 AM
To: security-basics@securityfocus.com
Subject: remote desktop question


Dear All,

The company I work with recently required a remote desktop access and
to keep the budget down, I used a XP Pro system to receive only one
Remote Desktop user.

Since this requires the opening up of a port on the firewall,
I'm quite concerned.  I have limited the system to only one or
two users who can log on.   Since this is my initial foray
into the remote desktop client (in the past, we used PCAnywhere,
but it's getting more and more expensive(hard to justify
purchasing a license for each system).

In what ways can I protect the remote desktop system from
being broken into?  (Well, aside from shutting it down.)

Any pointers appreciated.

Edmund






<Prev in Thread] Current Thread [Next in Thread>