RDP still susceptible to Man in middle attack?


Go Back   Computer Help Articles > Windows XP Work Remotely
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 07:14 AM
recon
 
Posts: n/a
Default RDP still susceptible to Man in middle attack?

Greetings,

After a quick nessus scan on one of my RDP - enabled machines I realized
that RDP is susceptible to man in middle attacks. Even after the XP SP2 .. a
rogue machine can decrypt the communication between the two machines in
question, revealing passwords and such sensitive information. Are there any
plans to fix the design flaw?

Best regards,
recon
Reply With Quote
  #2  
Old 01-05-2006, 07:14 AM
Peter
 
Posts: n/a
Default Re: RDP still susceptible to Man in middle attack?

> After a quick nessus scan on one of my RDP - enabled machines I realized
> that RDP is susceptible to man in middle attacks. Even after the XP SP2 ..

a
> rogue machine can decrypt the communication between the two machines in
> question, revealing passwords and such sensitive information. Are there

any
> plans to fix the design flaw?


What flaw? Post nessus scan procedure or other details how you discovered
that RDP defficiency; then we can talk.


Reply With Quote
  #3  
Old 01-05-2006, 07:14 AM
Sooner Al [MVP]
 
Posts: n/a
Default Re: RDP still susceptible to Man in middle attack?

I can't answer your question directly other than to say consider running RDP
through a VPN or SSH tunnel. Personally I use the SSH method with a
private/public key pair (encrypted with a strong pass phrase) for
authentication.

--

Al Jarvi (MS-MVP Windows Networking)

Please post *ALL* questions and replies to the news group for the mutual
benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no
rights...

"recon" <recon@discussions.microsoft.com> wrote in message
news:4A980EE2-821F-4865-9B2E-8CFD2D7A44B6@microsoft.com...
> Greetings,
>
> After a quick nessus scan on one of my RDP - enabled machines I realized
> that RDP is susceptible to man in middle attacks. Even after the XP SP2 ..
> a
> rogue machine can decrypt the communication between the two machines in
> question, revealing passwords and such sensitive information. Are there
> any
> plans to fix the design flaw?
>
> Best regards,
> recon



Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
web page squished to the middle crazy blonde Internet Explorer 6 6 01-05-2006 04:33 PM
Optical Mouse - middle mouse button not recognised by some games Mike Windows XP Games 7 01-05-2006 07:53 AM
Wait for Windows patch opens attack window Jim Windows XP Help and Support 10 01-05-2006 02:51 AM
Wait for Windows patch opens attack window Jim Windows XP General 2 01-05-2006 02:35 AM
Repairs after a virus attack G F O'Neill Windows XP General 2 01-05-2006 02:34 AM


All times are GMT. The time now is 09:33 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

RDP still susceptible to Man in middle attack?