<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Steve Riley on Security : Terminal Server</title><link>http://blogs.technet.com/steriley/archive/tags/Terminal+Server/default.aspx</link><description>Tags: Terminal Server</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Securing Terminal Services over the Internet</title><link>http://blogs.technet.com/steriley/archive/2005/06/28/Securing-Terminal-Services-over-the-Internet.aspx</link><pubDate>Tue, 28 Jun 2005 19:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:406961</guid><dc:creator>Steve Riley</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/steriley/comments/406961.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=406961</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=406961</wfw:comment><description>&lt;P&gt;In my presentation on remote access at TechEd, I gave three scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;web-based access to internal resources, published with ISA Server&lt;/LI&gt;
&lt;LI&gt;"desktop over the Internet" using Terminal Services and the remote desktop web connection&lt;/LI&gt;
&lt;LI&gt;full IP-based virtual private networks with L2TP+IPsec&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;In the discussion on TS over the Internet, I failed to mention a very important bit. There is no mechanism built into RDP to authenticate the server to the client. This creates an opportunity to conduct a man-in-the-middle attack. Tools now exist to do exactly this.&lt;/P&gt;
&lt;P&gt;In Windows Server 2003, you can configure TS to use TLS for server authentication and data encryption. This is extremely important for anyone running TS over the Internet. See&amp;nbsp;&lt;A class="" href="http://support.microsoft.com/?id=895433" target=_blank mce_href="http://support.microsoft.com/?id=895433"&gt;KB 895433&lt;/A&gt; for the step-by-step details.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=406961" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/access+technologies/default.aspx">access technologies</category><category domain="http://blogs.technet.com/steriley/archive/tags/protection/default.aspx">protection</category><category domain="http://blogs.technet.com/steriley/archive/tags/TechEd/default.aspx">TechEd</category><category domain="http://blogs.technet.com/steriley/archive/tags/configuration/default.aspx">configuration</category><category domain="http://blogs.technet.com/steriley/archive/tags/Terminal+Server/default.aspx">Terminal Server</category></item></channel></rss>