Click here to get back home

Security bug in terminal services?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security bug in terminal services? Stefan Cuypers 05-04-2006
Posted by Stefan Cuypers on May 4, 2006, 4:02 am
Please log in for more thread options
I'm currently configuring a terminal server running Windows Server 2003 R2
with two RDP connections (using 2 network cards). The first connection will
be used for internal connections and the second connection will be used to
allow some users to connect directly via the Internet.
I configured the permissions on the second connection to only allow a
limited number of users. When testing this at first it seems to work fine
(users not allowed get an error message that they do not have terminal
server user access permission).
If however a user currently has an active or disconnected session (set up
via the first connection), the second connection connects just fine to the
existing session although the user does not have permission to use that
connection!
To me this seems to be a security bug: connection security is not checked
any more if the session already exists!

regards,
Stefan Cuypers



Posted by Steven L Umbach on May 4, 2006, 3:32 pm
Please log in for more thread options
You might also want to post in one of the Terminal Services newsgroups for
feedback. What you might want to do is to configure RDP to end a
disconnected session and have your users connect via a VPN to the TS from
the internet. Then if you are using a Windows server for VPN you can
configure Remote Access Policies so that only authorized users can connect
to the TS using input/output filters to block others. Another advantage with
using a VPN is if L2TP can be used you will remove the risk of users not
using authorized computers from attempting to connect to the VPN because
L2TP requires that the VPN client and server authenticate with certificates
before a user is allowed to even attempt to authenticate. --- Steve


> I'm currently configuring a terminal server running Windows Server 2003 R2
> with two RDP connections (using 2 network cards). The first connection
> will be used for internal connections and the second connection will be
> used to allow some users to connect directly via the Internet.
> I configured the permissions on the second connection to only allow a
> limited number of users. When testing this at first it seems to work fine
> (users not allowed get an error message that they do not have terminal
> server user access permission).
> If however a user currently has an active or disconnected session (set up
> via the first connection), the second connection connects just fine to the
> existing session although the user does not have permission to use that
> connection!
> To me this seems to be a security bug: connection security is not checked
> any more if the session already exists!
>
> regards,
> Stefan Cuypers
>
>



Posted by Stefan Cuypers on May 4, 2006, 4:24 pm
Please log in for more thread options
We are currently using L2TP VPN's to this end, but the problem is that some
users need to have access from unauthorised PC's. To this end we set up the
RDP connection (with things like drive and printer mapping disabled).
I'll try to post in the terminal services groups also.

Stefan.

> You might also want to post in one of the Terminal Services newsgroups for
> feedback. What you might want to do is to configure RDP to end a
> disconnected session and have your users connect via a VPN to the TS from
> the internet. Then if you are using a Windows server for VPN you can
> configure Remote Access Policies so that only authorized users can connect
> to the TS using input/output filters to block others. Another advantage
> with using a VPN is if L2TP can be used you will remove the risk of users
> not using authorized computers from attempting to connect to the VPN
> because L2TP requires that the VPN client and server authenticate with
> certificates before a user is allowed to even attempt to
> thenticate. --- Steve
>
>



Similar ThreadsPosted
Terminal Services Security Issue with Cached Credentials October 29, 2007, 12:53 pm
Logon Using Terminal Services GPO August 16, 2007, 2:57 am
Terminal Services Profiles problems August 15, 2005, 5:08 pm
How do I configure Terminal Services for 443 access only February 12, 2006, 10:37 am
Deny Logon through Terminal Services Issue August 22, 2006, 12:49 pm
Digital signature, USB tokens and terminal services September 25, 2006, 9:16 am
Terminal services-give a program admin rights January 10, 2006, 4:14 pm
Prevent browsing with UNC paths for Terminal Services users April 5, 2006, 2:05 pm
Deny Right to Local Admin Group to Log On Via Terminal Services? May 24, 2007, 12:28 pm
Domain Controller Policy setting "Allow log on through Terminal Services" April 1, 2008, 12:01 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap