Remote Desktop Security

N

Neal Kaufman

I got Remote Desktop to work over the internet. Now I am concerned about
someone hacking into my computer. Is there a way to prevent someone from
connecting remotely as the administrator? Is there some way to allow only a
small number of attempts to log onto an account remotely (using an incorrect
password), before requiring a reset? In otherwords, how can I better
protect my computer.

Thanks,
Neal
 
P

Phil Waligora [MSFT]

Hello Neal,

There are a number of things that you can do to protect your computer.

First and foremost, you should use strong passwords. The definition of a
"strong" password may differ from company to company, but a good bet is that
your password should be at least 8 characters long. It should contain a
mixutre of lower case letters, upper case letters, numbers, and symbols. It
should also not include easily-thought of words or combinations. Passwords
such as Pa$$word or passwords substituting the '@' symbol for an 'a'
character are extremely common and easy to break.

Your password should seem random to anyone looking at it. This will make it
much more difficult for password hacking programs to guess your password.

Secondly, if you can help it, you should not normally run your box under the
Administrator account. Ideally, you should normally be running your
computer under a Normal User. The logic behind this is that if the password
for your Normal User is discovered, a malicious user will not have much
access to your computer. If a hacker has access to your Administrator
account, the attacker essentially owns your box and can do mostly anything
he or she wishes to do. Again, both the Administrator and Normal Users
should have strong passwords. You should also change your passwords on a
regular basis. Change your passwords at least once every three months.

Also, Don't use one password for all of your accounts. This includes
personal computer accounts, work computer accounts, web site access, online
shopping, voicemail PINs, ATM PINs, etc. Ideally, each account should have
its own password. This way, if an attacker guesses one password, he or she
will not be able to access all of your accounts.

Set up a policy on your computer to record invalid login requests. Windows
has the ability to do this built in. You can periodically check your system
logs and see if somone is trying to access your box.

There are still many more things you can do, but these should be a good
start. If you are still concerned I suggest picking up a Windows System
Administration book and look at tips given in that book.

Thanks,
Phil

This posting is provided "AS IS" with no warranties, and confers no rights.
 
J

Jeffrey Randow (MVP)

In addition, I would recommend visiting the Microsoft Security site at
http://www.microsoft.com/security . They have all sorts of tips and
tools that will help you maintain the security of your system...

Jeffrey Randow (Windows MVP - Networking & Smart Display)
(e-mail address removed)

Please post all responses to the newsgroups for the benefit
of all USENET users. Messages sent via email may or may not
be answered depending on time availability....

Remote Networking Technology Wiki -
http://www.remotenetworktechnology.com
Smart Display Support - http://www.smartdisplays.us
Windows XP Expert Zone - http://www.microsoft.com/windowsxp/expertzone
 
R

Russell DeMarco

Set up a policy on your computer to record invalid login requests.
Windows
has the ability to do this built in. You can periodically check your system
logs and see if somone is trying to access your box.
Hi Phil,

How do you setup a policy to record invalid login requests? Can u do this
with Windows 2000 as well? What about W2K server? And finally, where are
the logs kept?

Thanks.
 
J

Jeffrey Randow (MVP)

Via Group Policy (gpedit.msc). You will be setting audit Policies
(under Computer Configurations/Windows Settings/Security
Settings/Local Policy/Audit Policy).

These events are logged into the Security Event Log (accessible via
Computer Management - compmgmt.msc)

Jeffrey Randow (Windows MVP - Networking & Smart Display)
(e-mail address removed)

Please post all responses to the newsgroups for the benefit
of all USENET users. Messages sent via email may or may not
be answered depending on time availability....

Remote Networking Technology Wiki -
http://www.remotenetworktechnology.com
Smart Display Support - http://www.smartdisplays.us
Windows XP Expert Zone - http://www.microsoft.com/windowsxp/expertzone
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top