Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen

Onderwerp: Rdp

  1. #1
    Rdp
    Professional
    3.115 Berichten
    Ingeschreven
    05/02/05

    Locatie
    Alkmaar

    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    101 Berichten zijn liked


    Naam: Thomas
    Registrar SIDN: JA
    ISPConnect: Lid
    KvK nummer: 76706966

    Thread Starter

    Rdp

    Microsoft RDP DoS Information

    Last week Microsoft released a security alert that warned of a remote Denial of Service (DoS) condition in the Remote Desktop Protocol (RDP). RDP is disabled by default on most Windows versions, with the exception of Media Center. However, many organizations do enable it to aid in remote support.

    http://www.microsoft.com/technet/sec...ry/904797.mspx

    As of today, there is not a patch available for this vulnerability and complete details are not publicly known. Microsoft and other security experts have recommended that in order to mitigate this vulnerability, users should disable RDP and ensure that TCP Port 3389 is blocked at the firewall level. While this will definitely protect users from the vulnerability, it can significantly impact the business of those organizations that rely on RDP.

    About the Vulnerability
    eEye Digital Security researchers did not discover this vulnerability, but the researcher who did has consulted with eEye and has provided some additional details about this issue to help us confirm the analysis and assess the risk that it poses. Without going into complete details on this issue, we will explain the already public details and dispel some misconceptions reported by the media.

    The first misconception was reported last week. Some known security experts were quoted saying that there is a high likelihood that this vulnerability can be exploited to run arbitrary code on the target systems. This is completely false. The Microsoft analysis on this bug is, in this case, 100% correct and the potential result of a successful exploit is nothing more severe than a DoS. Once details are released, the eEye research team may explain the technical reasons behind why this flaw does not lead to an opportunity to execute arbitrary commands, and offer a look at the exact code behind the vulnerability.

    Because there is no opportunity to run arbitrary code, this also removes the possibility for this flaw to be used in a worm attack. As far as attack scenarios go, this vulnerability can be utilized in a Denial of Service (DoS) attack or a blended attack where the attacker requires the ability to force a remote system to reboot. Causing a DoS on a target system would force either an automatic or manual reboot to be required, depending on the target system's configuration.

    So what exactly is this vulnerability? This question is difficult to answer without discussing information that is not already public knowledge. A specific driver, RDPWD.SYS, is present on Windows 2000, Windows 2003, and Windows XP. All versions of Windows including Windows XP SP2 are vulnerable, but as mentioned above, only if the RDP service is enabled.

    ---

    Minder leuk nieuws.

  2. #2
    Rdp
    geregistreerd gebruiker
    5.163 Berichten
    Ingeschreven
    04/06/05

    Locatie
    Zeeland

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: nee
    KvK nummer: nvt
    Ondernemingsnummer: nvt

    Re: Rdp

    Origineel geplaatst door getUP
    Microsoft RDP DoS Information


    ---

    Minder leuk nieuws.
    Goh, wat gek. Een veiligheidsprobleem met windows.

    Gebruik dan geen RDP :-)

  3. #3
    Rdp
    geregistreerd gebruiker
    1.075 Berichten
    Ingeschreven
    25/04/04

    Locatie
    -

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked


    Registrar SIDN: -
    KvK nummer: -
    Ondernemingsnummer: -

    Goh, wat gek. Een idioot die niets te melden heeft.

    Post dan niet :-)

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics