Remote Desktop Security

N

Name

Hi,

My question is about the security of Remote Desktop. I have heard elswhere
that RDP communication is/maybe encrypted.

Can anybody elaborate on what kind of encryption this is, can it be turned
on/off. What is the default status?

Are there any flaws in this encryption so that we will need another VPN to
pass the RDP connection thru?

Thanks for any help,
Regards
 
B

Bill Sanderson

I think Al's links are authoritative.

There have been flaws in the RDP encryption system in the past, but they are
long since patched:

http://www.microsoft.com/technet/security/bulletin/MS02-051.mspx

RDP alone as a protocol is vulnerable to a man in the middle attack.

Such an attack is not easy to mount, but note this evidence:

http://bitstop.com.ph/archive/2004/11/16/609.aspx

Here's a description of the issue:

http://www.windowsitpro.com/WindowsSecurity/Articles/ArticleID/38589/pg/2/2.html

RDP hasn't been changed to eliminate this problem. Running RDP within a VPN
tunnel helps.

The other issue with RDP are brute force attacks on the password.

There are automated mechanisms out there and in use performing such attacks,
so use a strong password.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top