How safe is RDP?


Go Back   Computer Help Articles > Windows XP Work Remotely
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 07:12 AM
louisXXX
 
Posts: n/a
Default How safe is RDP?

i remotely connect to my work via an ipsec vpn and use rdp to connect to the
workplaces terminal server. its extremely fast and is impressive by anybodies
standards.
however as with all ipsec's, they need configuring at both endpoints. pptp
isn't the answer here either as it requires setting up at the client end. ssl
is a so;ution to the problem but requires extra hardware/software.
what i'm after is a zero cost & zero configuration on the client side ie a
raw rdp connection from any xp client. this obviously opens up the PC on the
firewall on 3389 to external connections.
my question? how safe is this? i've configured an account lockout policy and
enforced strong passwords.
any help would be appreciated.
Reply With Quote
  #2  
Old 01-05-2006, 07:12 AM
Sooner Al [MVP]
 
Posts: n/a
Default Re: How safe is RDP?

The native RDP data stream is encrypted. See this reference for details...

http://tinyurl.com/8bvj

Personally I run RDP through a SSH tunnel for added security (I also use a
private/public key pair w/strong pass phrase for authentication) and its
easy to access more than one RDP host through the tunnel.

I think I would stick with the IPSec VPN if you have it up and running and
RDP is working through it...

--

Al Jarvi (MS-MVP Windows Networking)

Please post *ALL* questions and replies to the news group for the mutual
benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no
rights...

"louisXXX" <louisXXX@discussions.microsoft.com> wrote in message
news:05147EB5-F1F8-4059-9CB4-3396FEA30605@microsoft.com...
>i remotely connect to my work via an ipsec vpn and use rdp to connect to
>the
> workplaces terminal server. its extremely fast and is impressive by
> anybodies
> standards.
> however as with all ipsec's, they need configuring at both endpoints. pptp
> isn't the answer here either as it requires setting up at the client end.
> ssl
> is a so;ution to the problem but requires extra hardware/software.
> what i'm after is a zero cost & zero configuration on the client side ie a
> raw rdp connection from any xp client. this obviously opens up the PC on
> the
> firewall on 3389 to external connections.
> my question? how safe is this? i've configured an account lockout policy
> and
> enforced strong passwords.
> any help would be appreciated.



Reply With Quote
  #3  
Old 01-05-2006, 07:12 AM
beb
 
Posts: n/a
Default Re: How safe is RDP?

When you keep the host updated then, the man in the middle security attack
is what you should be concerned about .If you follow Mr. Sooner's advice
about secure tunnelling then that will take care of that hole.

Other than that the man in the middle threat, RDP is pretty secure when
configured with some of things you alluded to, strong password, user policy,
lockout policy, logging etc. ect.

"louisXXX" <louisXXX@discussions.microsoft.com> wrote in message
news:05147EB5-F1F8-4059-9CB4-3396FEA30605@microsoft.com...
>i remotely connect to my work via an ipsec vpn and use rdp to connect to
>the
> workplaces terminal server. its extremely fast and is impressive by
> anybodies
> standards.
> however as with all ipsec's, they need configuring at both endpoints. pptp
> isn't the answer here either as it requires setting up at the client end.
> ssl
> is a so;ution to the problem but requires extra hardware/software.
> what i'm after is a zero cost & zero configuration on the client side ie a
> raw rdp connection from any xp client. this obviously opens up the PC on
> the
> firewall on 3389 to external connections.
> my question? how safe is this? i've configured an account lockout policy
> and
> enforced strong passwords.
> any help would be appreciated.



Reply With Quote
  #4  
Old 01-05-2006, 07:12 AM
louisXXX
 
Posts: n/a
Default Re: How safe is RDP?

thanks for the replies. the reason i ask is because i want to connect via any
xp pc eg i am at my friends house etc. and do not have the luxury of an ssh
tunnel, ipsec etc
regards
louis

"Sooner Al [MVP]" wrote:

> The native RDP data stream is encrypted. See this reference for details...
>
> http://tinyurl.com/8bvj
>
> Personally I run RDP through a SSH tunnel for added security (I also use a
> private/public key pair w/strong pass phrase for authentication) and its
> easy to access more than one RDP host through the tunnel.
>
> I think I would stick with the IPSec VPN if you have it up and running and
> RDP is working through it...
>
> --
>
> Al Jarvi (MS-MVP Windows Networking)
>
> Please post *ALL* questions and replies to the news group for the mutual
> benefit of all of us...
> The MS-MVP Program - http://mvp.support.microsoft.com
> This posting is provided "AS IS" with no warranties, and confers no
> rights...
>
> "louisXXX" <louisXXX@discussions.microsoft.com> wrote in message
> news:05147EB5-F1F8-4059-9CB4-3396FEA30605@microsoft.com...
> >i remotely connect to my work via an ipsec vpn and use rdp to connect to
> >the
> > workplaces terminal server. its extremely fast and is impressive by
> > anybodies
> > standards.
> > however as with all ipsec's, they need configuring at both endpoints. pptp
> > isn't the answer here either as it requires setting up at the client end.
> > ssl
> > is a so;ution to the problem but requires extra hardware/software.
> > what i'm after is a zero cost & zero configuration on the client side ie a
> > raw rdp connection from any xp client. this obviously opens up the PC on
> > the
> > firewall on 3389 to external connections.
> > my question? how safe is this? i've configured an account lockout policy
> > and
> > enforced strong passwords.
> > any help would be appreciated.

>
>
>

Reply With Quote
  #5  
Old 01-05-2006, 07:12 AM
Peter
 
Posts: n/a
Default Re: How safe is RDP?

> thanks for the replies. the reason i ask is because i want to connect via
any
> xp pc eg i am at my friends house etc. and do not have the luxury of an

ssh
> tunnel, ipsec etc
> regards
> louis


If you cannot trust security of their computer, then you are insecure.
They might have keylogger installed, without even being aware.

Travel with your own computer (laptop?).


Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Safe Mode alwaysneedhelp Windows XP Configuration Manage 1 01-05-2006 06:37 PM
Safe Mode alwaysneedhelp Windows XP Configuration Manage 0 01-05-2006 07:33 AM
safe mode alwaysneedhelp Windows XP Security Admin 8 01-05-2006 05:44 AM
Safe Mode alwaysneedhelp Windows XP Help and Support 2 01-05-2006 02:51 AM
Have results from Hijackthis. Don't understand them!!! 1st half StanStan Windows XP General 15 01-05-2006 02:36 AM


All times are GMT. The time now is 08:18 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

How safe is RDP?