<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: The most secure way to use Windows Remote Desk in Wireless Security</title>
<link>http://www.dslreports.com/forum/r14690481</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 17:22:39 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 17:22:39 EDT</lastBuildDate>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14938235</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : An alternative to changing the port in the /etc/sshd_config file on the server, and one that I use, is to keep the server listening on TCP Port 22 but redirect a high number port through your firewall/NAT/router to TCP Port 22 on your server. When calling from a remote location use the new high number port. See the attached image for an example of that...<br><br>Glad its working for you...<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14938235?c=932714&ret=L2ZvcnVtL3IxNDY5MDQ4MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="97192 bytes" WIDTH=600 HEIGHT=445 SRC="/r0/download/932714.thumb600~1de0badb7fca4ca7e609e755397459a9/SSHPortRedirect.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14938235</guid>
<pubDate>Sat, 03 Dec 2005 12:20:22 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14937430</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by Sooner :</SMALL><BR><BR>AlWell, no I have <B>not</B> seen that error before...<br> </DIV>Really?!  Well, you haven't lived until you've scoured the databases looking for definitions to cryptic crap like this.  <br><br>10053 or WSAECONNABORTED and other error messages extremely similar to these were all the rage in the mid 90s.  ... before search engines were good.<br><br>App writers didn't want to take the time to translate the error, so they just popped it up to the user interface.  <br><br>And, naturally, Joe Public was confused by this.<br><SMALL>--<br>Robb Topolski -= <A HREF="http://funchords.com/">funchords.com</A> =- Hillsboro, Oregon USA<BR><I>~ Keeper of the <A HREF="/faq/dlink">D-Link FAQ</A> ~ Did you <A HREF="/nsearch">Search</A>? ~ More features, Free! <A HREF="/join/new">Join BBR</A>! ~<br>---</I><br>[Mod Note: Edited to fix broken quote.<I> --kc</I>]</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14937430</guid>
<pubDate>Sat, 03 Dec 2005 03:21:20 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14937047</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : [edit] It seems I actually do NOT know how to change the port. I did get my keys setup, and password authentication off.<br><br>I noticed that both ssh_config and sshd_config have the passwordauthentication line. Should it be NO in both?<br><br>I saw the line "port" in ssh_config, but changing it breaks it. How do I change the port?<br><br>[edit yet again]I did figure it out after all, change the port in sshd_config not ssh_config.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14937047</guid>
<pubDate>Sat, 03 Dec 2005 01:25:18 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14936645</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : Confusion over :) I uninstalled and reinstalled COPSSH, and now I can login just fine. Must've messed something up accidentally first time. Like being too lazy to actually logout and back into an admin account, and just using "runas" for the install, and then not bothering to reboot before messing with stuff.<br><br>I see the necessity and function of port forwarding now too. Have to do that even just to access the server machine over RDP I see. I'm able to access multiple machines on my network over the tunnel now. :)<br><br>I'm going to try making my RSA keys next.<br><br>Can you tell me how to change the port number that COPSSH uses?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14936645</guid>
<pubDate>Fri, 02 Dec 2005 23:54:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14934854</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : <div class="bquote"><SMALL>said by  SoonerAl <A HREF="/useremail/u/662411"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  Raphion <A HREF="/useremail/u/220044"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Every step stumps me. Now I made accounts without spaces, and tried again, and PuTTY says "Network error: Software caused connection abort". This is why I say VPN or any other tunneling system is way over my head. :hmm:<br> </DIV>I have never seen that error...<br><br>Can you post screen shots of how you have PuTTY setup?<br><br>Make sure you test locally before you try to do this over the public internet and test with a psssword before you try to setup and use a key pair.<br> </DIV>I followed the link you gave exactly, only skipping the port forwarding because I'll only want to connect to the one machine for now, and replacing the address with my own of course.<br><br>I looked at the exchange between the machines using a sniffer, and what I see is:<br>Client sends SYN from port 2145 to Server port 22,<br>Server sends SYN ACK from port 22 to Client port 2145,<br>Client sends ACK from port 2145 to Server port 22,<br>Server sends RST ACK from port 22 to Client port 2145.<br><br>And that's all that happens.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14934854</guid>
<pubDate>Fri, 02 Dec 2005 19:09:46 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14934223</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : <div class="bquote"><SMALL>said by  funchords <A HREF="/useremail/u/340409"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  SoonerAl <A HREF="/useremail/u/662411"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Raphion <A HREF="/useremail/u/220044"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL>and PuTTY says "Network error: Software caused connection abort". </DIV>I have never seen that error...<br></DIV>Oh, I'm sure you have seen it and don't recognize it because it's actually in text and not in the usual cryptic form. :) This is the WSAECONNABORTED error, and the 10053 error.<br> </DIV>Well, no I have <B>not</B> seen that error before...<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14934223</guid>
<pubDate>Fri, 02 Dec 2005 17:30:05 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14932977</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : <div class="bquote"><SMALL>said by  SoonerAl <A HREF="/useremail/u/662411"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Raphion <A HREF="/useremail/u/220044"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL>and PuTTY says "Network error: Software caused connection abort". </DIV>I have never seen that error...<br></DIV>Oh, I'm sure you have seen it and don't recognize it because it's actually in text and not in the usual cryptic form. :) This is the WSAECONNABORTED error, and the 10053 error.<br><br>In this case, most likely Winsock sent data over the connection that was not acknowledged before a timeout, so Winsock closed the connection.<br><br>Another reason would be because winsock couldn't open the connection due to some constraint, such as a socket's queue being full.<br><SMALL>--<br>Robb Topolski -= <A HREF="http://funchords.com/">funchords.com</A> =- Hillsboro, Oregon USA<BR><I>~ Keeper of the <A HREF="/faq/dlink">D-Link FAQ</A> ~ Did you <A HREF="/nsearch">Search</A>? ~ More features, Free! <A HREF="/join/new">Join BBR</A>! ~</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14932977</guid>
<pubDate>Fri, 02 Dec 2005 14:42:02 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14930490</link>
<description><![CDATA[<A HREF="/useremail/u/1000329"><b>YqE41k24</b></A> : That's a good point.<br><br>&raquo;<A HREF="http://projects.cerias.purdue.edu/secprog/class3/2.Phys_&_Link.ppt#295,40,ARP-Related" >projects.cerias.purdue.edu/secpr&middot;&middot;&middot;-Related</A> Vulnerabilities<br>&raquo;<A HREF="http://www-128.ibm.com/developerworks/wireless/library/wi-stack.html?open&l=803,t=r,p=arp" >www-128.ibm.com/developerworks/w&middot;&middot;&middot;=r,p=arp</A><br>&raquo;<A HREF="http://www-128.ibm.com/developerworks/security/library/s-sniff.html?article=wir" >www-128.ibm.com/developerworks/s&middot;&middot;&middot;icle=wir</A><br><br>I'm a little puzzled why you can't figure out how to run a VPN, though.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14930490</guid>
<pubDate>Fri, 02 Dec 2005 07:39:44 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14930429</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : <div class="bquote"><SMALL>said by  Raphion <A HREF="/useremail/u/220044"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Every step stumps me. Now I made accounts without spaces, and tried again, and PuTTY says "Network error: Software caused connection abort". This is why I say VPN or any other tunneling system is way over my head. :hmm:<br> </DIV>I have never seen that error...<br><br>Can you post screen shots of how you have PuTTY setup?<br><br>Make sure you test locally before you try to do this over the public internet and test with a psssword before you try to setup and use a key pair.<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14930429</guid>
<pubDate>Fri, 02 Dec 2005 07:20:40 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14930252</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : <div class="bquote"><SMALL>said by  YqE41k24 <A HREF="/useremail/u/1000329"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>That's why in the link above, they say that this exploit is more viable with DNS than without.  This isn't the kind of attack you'd run into at a coffee shop or public internet (unless you think the ISP is hosting the attack). <br> </DIV>Why wouldn't it be easy to run on a coffee shop network? MITM attacks are <B>extremely</B> easy on a  WiFi network. All  you have to do is ARP poison both the target and the gateway, and then you have every bit of the target's IP traffic running through your machine, and can do whatever you want with it. I've done that on my own network, and it's childsplay.<br><br>[edit] I suppose a well run network would have guards in place to make MITM less easy, like kicking a client that sends out excessive ARPs. But I wouldn't expect to see anything like that in a small network like a hotel or hotspot, where they dole out private IP's to everyone via a SOHO DSL router. Though it would be a nice idea.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14930252</guid>
<pubDate>Fri, 02 Dec 2005 05:48:15 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14927701</link>
<description><![CDATA[<A HREF="/useremail/u/1000329"><b>YqE41k24</b></A> : Thank you for the link.  I skimmed through the article and this discussion<br><br>&raquo;<A HREF="http://groups.google.com/group/microsoft.public.windows.server.security/browse_thread/thread/b93953eb853ea376/631a9419deddc08e?lnk=st&q=Montoro+remote+desktop&rnum=2#631a9419deddc08e" >groups.google.com/group/microsof&middot;&middot;&middot;deddc08e</A><br><br>I don't like the looks of the Cain&Able program. Anyways... you would have to work to use this RDP attack.  You need to position yourself and the environment such that the RDP client initiates a connection to you instead of the real RDP server.  That's why in the link above, they say that this exploit is more viable with DNS than without.  This isn't the kind of attack you'd run into at a coffee shop or public internet (unless you think the ISP is hosting the attack).  This attack is also not specific to the RDP protocol.  SSH would have the same vulnerability, for instance, were it not the fact that each server generates and publishes its own certificate.<br><br>Here are some "famous last words". :-)<br><div class="bquote">I wouldn't leave anything like in service all the time either.</DIV>This is how holes often appear in networks.  Somebody opens up a port for a special case, gets distracted, and the port remains open.  It would be better, IMHO, to set up a VPN which you can leave active and secure.  If you can understand the RDP attacks and open/close ports, you shouldn't have any trouble setting up a VPN these days.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14927701</guid>
<pubDate>Thu, 01 Dec 2005 20:37:42 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14926784</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : <div class="bquote"><SMALL>said by  YqE41k24 <A HREF="/useremail/u/1000329"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>This article describes one vulnerability to Windows Remote Desktop.  It sounds real, but an attacker would have to be pretty determined to get anywhere with it.<br><br>&raquo;<A HREF="http://www.xatrix.org/article.php?s=1943" >www.xatrix.org/article.php?s=1943</A><br><br>I don't think there's any practical problem with using RDP over a clear channel (unless you are worried about targeted corporate espionage...).  But taken from a system perspective, why would you want to?  A better system design is to use a VPN-capable firewall to protect you from snooping and your inner equipment from the internet.  You could use straight RDP, but it's better to have a secure entre into your lan through one path instead of opening one-off paths with firewall rules for protocol-specific ports.<br> </DIV>I read about a worse exploit that allows total decryption of the whole RDP session. &raquo;<A HREF="http://www.oxid.it/downloads/rdp-gbu.pdf" >www.oxid.it/downloads/rdp-gbu.pdf</A> (Sorry it's a PDF) And it's built right into a program called Cain&Able, so you don't even have to work much at all to use it.<br><br>As to why I would like to be able to use something simple like RDP; I really don't have the knowledge to setup or administer any of those VPN firewall things. I've looked at some, and all I get for it is a headache.<br><br>I wouldn't leave anything like in service all the time either. I would only open the ports for it at my gateway router when the rare occasion comes that I'll actually need it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926784</guid>
<pubDate>Thu, 01 Dec 2005 18:39:56 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14926550</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : Every step stumps me. Now I made accounts without spaces, and tried again, and PuTTY says "Network error: Software caused connection abort". This is why I say VPN or any other tunneling system is way over my head. :hmm:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926550</guid>
<pubDate>Thu, 01 Dec 2005 18:12:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14926458</link>
<description><![CDATA[<A HREF="/useremail/u/1000329"><b>YqE41k24</b></A> : This article describes one vulnerability to Windows Remote Desktop.  It sounds real, but an attacker would have to be pretty determined to get anywhere with it.<br><br>&raquo;<A HREF="http://www.xatrix.org/article.php?s=1943" >www.xatrix.org/article.php?s=1943</A><br><br>I don't think there's any practical problem with using RDP over a clear channel (unless you are worried about targeted corporate espionage...).  But taken from a system perspective, why would you want to?  A better system design is to use a VPN-capable firewall to protect you from snooping and your inner equipment from the internet.  You could use straight RDP, but it's better to have a secure entre into your lan through one path instead of opening one-off paths with firewall rules for protocol-specific ports.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926458</guid>
<pubDate>Thu, 01 Dec 2005 18:00:32 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14922313</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : <div class="bquote"><SMALL>said by  Raphion <A HREF="/useremail/u/220044"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Well I'm trying CopSSH, but I can't activate my user account. I was able to activate administrator, but not an account that I actually use. It tells me the account does not exist, even though it just listed it. :huh:<br><br>The account name in question has a space in it, does the space break this? :hmm:<br> </DIV>That is the problem...<br><br>&raquo;<A HREF="http://www.itefix.no/phpws/index.php?module=phpwsbb&PHPWSBB_MAN_OP=view&PHPWS_MAN_ITEMS[]=205" >www.itefix.no/phpws/index.php?mo&middot;&middot;&middot;MS[]=205</A><br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14922313</guid>
<pubDate>Thu, 01 Dec 2005 06:22:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14919650</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : Well I'm trying CopSSH, but I can't activate my user account. I was able to activate administrator, but not an account that I actually use. It tells me the account does not exist, even though it just listed it. :huh:<br><br>The account name in question has a space in it, does the space break this? :hmm:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14919650</guid>
<pubDate>Wed, 30 Nov 2005 20:56:55 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14919126</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : Yes, you can change the listening port for RDP. See the section near the end of this page that has information about that...<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/RemoteDesktop/RemoteDesktopSetupandTroubleshooting.html" >theillustratednetwork.mvps.org/R&middot;&middot;&middot;ing.html</A><br><br>Personally I think your better off running RDP through a VPN or Secure Shell (SSH) tunnel for added security. For a home user/SOHO user SSH is quite easy to setup and quite a bit safer than using the native RDP data link, IMHO...<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/Ssh/RemoteDesktopSSH.html" >theillustratednetwork.mvps.org/S&middot;&middot;&middot;SSH.html</A><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/Ssh/Private-publicKey.html" >theillustratednetwork.mvps.org/S&middot;&middot;&middot;Key.html</A><br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14919126</guid>
<pubDate>Wed, 30 Nov 2005 19:52:42 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14918807</link>
<description><![CDATA[<A HREF="/useremail/u/220044"><b>Raphion</b></A> : Is it possible to change the port used by RDP?<br><br>I'm going to want to try RDP from some insecure WiFi soon, as VPN seems way over my head. I plan to do all my online tasks from my home computer over RDP as a lazy man's workaround. I'd feel a bit more secure about it if I could change the port to something obscure so as to keep the hax0rz from trying the door as much.<br><br>Second question; how long would be long enough for a purely random mixed case password?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14918807</guid>
<pubDate>Wed, 30 Nov 2005 19:15:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14850929</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : Another reason I like using a SSH tunnel is that once the tunnel is connected I can grab files off of my PC without using Remote Desktop. Both Tunnelier or <B>WinSCP</B>, both free, offer that functionality...<br><br>&raquo;<A HREF="http://winscp.net/eng/index.php" >winscp.net/eng/index.php</A><br><br>Also, WebDrive allows mapping of drives through a SSH tunnel.<br><br>&raquo;<A HREF="http://www.webdrive.com/index.php?pg=./products/webdrive/index" >www.webdrive.com/index.php?pg=./&middot;&middot;&middot;ve/index</A><br><br>Unfortunately I have not been able to get it to work yet, but I will...:)<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14850929</guid>
<pubDate>Mon, 21 Nov 2005 06:33:26 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14850580</link>
<description><![CDATA[<A HREF="/useremail/u/340409"><b>funchords</b></A> : I often enable RDP without requiring a tunnel.  I have set the password policy (in gpedit.msc) to lock out an account after 3 failed password attempts.  <br><br>So far, I haven't seen _any_ abuses in the log, but I know that's just a matter of time.<br><br>Worst possible thing I expect to happen is a DDOS on my account.  But they're not getting in.  :)<br><SMALL>--<br>Robb Topolski -= <A HREF="http://www.funchords.com/">http://www.funchords.com/</A> =- Hillsboro, Oregon USA<BR><I>... Did you wake up grouchy this morning or did you let her sleep in? ...</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14850580</guid>
<pubDate>Mon, 21 Nov 2005 02:41:42 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14850490</link>
<description><![CDATA[<A HREF="/useremail/u/914343"><b>AMD Phreak</b></A> : I have a brother that uses port knocking to access his home network.  He had to write a script to perform the sequence as they are only milliseconds apart.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14850490</guid>
<pubDate>Mon, 21 Nov 2005 01:57:29 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14848926</link>
<description><![CDATA[<A HREF="/useremail/u/768499"><b>Shootist</b></A> : <div class="bquote"><SMALL>said by  Anav <A HREF="/useremail/u/431519"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Lets go back to the original question, no one here seems to use RD by itself. Is it not secure?  If that is all one has, what precautions/practices should one exercise?????<br> </DIV>I RDC to my home PC from work all the time and don't use any other tunnel. I do use the Z5 firewall rules to block all other IP's except a select few which I know I'll be using to connect with on port 3389.<br><SMALL>--<br>Shooter Ready--Stand By      BEEP    <B>********</B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14848926</guid>
<pubDate>Sun, 20 Nov 2005 21:03:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14847432</link>
<description><![CDATA[<A HREF="/useremail/u/356916"><b>Komputerguy</b></A> : I actually also do the ssh tunneling thing but I went even a step further and also implemented port knocking to turn on and off the SSH server.  I've run into one problem, though.  I had to resort to using nmap to do the knocking because I had finer control on how the tcp connections were made.  For instance all of the other utilities I used would make multiple connections for each attempt to contact a particular port which would mess up the knocking sequence.  This seemed to work fine for a while but recently for some reason I am now having a similar problem with nmap and it also seems like the order that the ports are being contacted on the receiving end is different than on the sending end.  I'm giving a pretty reasonable several second delay between knocks which I think would be more than enough to ensure there not to be a problem like this, so I'm kind of baffled.  I'm now looking for a different utility to do the knocking.  Does anyone have any suggestions?<br><SMALL>--<br><br>What can possibly go wrong?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14847432</guid>
<pubDate>Sun, 20 Nov 2005 17:03:45 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14846429</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : There have been some reports in the past of man-in-the-middle attacks against the native Remote Desktop protocol.<br><br>I simply think its safer to use a SSH tunnel (or VPN if that floats your boat) with a private/public key pair encrypted with a strong pass phrase to safe guard the link. Personally I have more confidence in the integrity of the link that way.<br><br>I think it comes down to what you feel comfortable with...<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14846429</guid>
<pubDate>Sun, 20 Nov 2005 13:43:23 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14846256</link>
<description><![CDATA[<A HREF="/useremail/u/914343"><b>AMD Phreak</b></A> : I frequently use RDP without external methods of tunneling.  I too am under the impression that it is plenty secure.  some things that I stress are picking passwords that are very secure, such as using pass-phrases rather than passwords.  I find its much easier for myself or a user to remember a phrase rather than a word.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14846256</guid>
<pubDate>Sun, 20 Nov 2005 13:12:32 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14846025</link>
<description><![CDATA[<A HREF="/useremail/u/431519"><b>Anav</b></A> : Lets go back to the original question, no one here seems to use RD by itself. Is it not secure?  If that is all one has, what precautions/practices should one exercise?????]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14846025</guid>
<pubDate>Sun, 20 Nov 2005 12:33:34 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14845827</link>
<description><![CDATA[<A HREF="/useremail/u/914343"><b>AMD Phreak</b></A> : Sorry to revive an old post and not to threadjack but what about using this method for VPN?  I am having issues with that. Any help?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845827</guid>
<pubDate>Sun, 20 Nov 2005 11:55:36 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14697266</link>
<description><![CDATA[<A HREF="/useremail/u/494741"><b>DavidJWood</b></A> : As  seezar <A HREF="/useremail/u/421841"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> says, use a passphrase on the private key, so even if found it's useless.<br><br>The only time I have private keys without passphrases is when one machine needs to connect to another automatically. In that case, I lock down the permissions on the public key end so as to make the key essentially useless to anyone who gets hold of it (at the moment, I'm only using rsync in this way, so I prohibit ptys and only allow the domains including the server that needs to rsync to authenticate using that key).<br><br>David]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14697266</guid>
<pubDate>Mon, 31 Oct 2005 06:59:03 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14695291</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : <div class="bquote"><SMALL>said by  jig <A HREF="/useremail/u/279131"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>i'm wary of limiting my connection to me having to carry a large key around in my pocket. i can't memorize it, but i can lose it in a way that gives access to another...<br> </DIV>Even if someone gets access to the private key, it still doesnt automatically mean someone has access, they still have to know the password as well.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14695291</guid>
<pubDate>Sun, 30 Oct 2005 21:23:51 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14695130</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : sorry to interject:<br><br>1) ssh provides a secure authentication (start up phase), and a simpler firewall configuration (one port from WAN). it might add some encryption to the stream itself once it's up and running, but it probably is a negligible increase in security at that point since the RDP stream is already encrypted. i would be surprised if the RDP authentication procedure is even AS secure as current ssh.<br><br>2) is the public/private key passing really more secure (against packet sniffing) for authentication than just a strong password?<br><br>i'm wary of limiting my connection to me having to carry a large key around in my pocket. i can't memorize it, but i can lose it in a way that gives access to another...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14695130</guid>
<pubDate>Sun, 30 Oct 2005 21:05:40 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14693071</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : <div class="bquote"><SMALL>said by  Flaubert <A HREF="/useremail/u/1120130"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I was just looking at the link posted above about Windows remote connections and it looks like there's a way of encrypting the traffic between the client.<br><br>What gives?<br> </DIV>Windows remote desktop in itself does encrypt the traffic on its own. SSH just provides an additional layer of security.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14693071</guid>
<pubDate>Sun, 30 Oct 2005 15:42:26 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14693066</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : Well, I got it setup with private/public key and its working fine. Once you understand how it works its really not that complicated to get it all setup. You'll just have to make sure you remove the private key from the server and keep a copy of it with you as your client machines will need that file in order to connect.<br><br>I have a USB thumb drive that I plan to keep the private key on in case I need it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14693066</guid>
<pubDate>Sun, 30 Oct 2005 15:41:16 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14692186</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : I was just looking at the link posted above about Windows remote connections and it looks like there's a way of encrypting the traffic between the client.<br><br>What gives?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14692186</guid>
<pubDate>Sun, 30 Oct 2005 13:04:11 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14691803</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : I think I'm all set I'll try all this this sunday and keep you posted.<br><br>I'm still a little bit worried about those private keys, it doesn't look too simple.<br><br>thanks anyway for all this help .....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14691803</guid>
<pubDate>Sun, 30 Oct 2005 11:58:47 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14691112</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : This thread has been a tremendous help, thank you SoonerAl for your contribution. The FAQ on this site talks about remote desktop, &raquo;<A HREF="/faq/vnc">Windows Based Remote Connections</A> but is a bit lacking in some of the specifics.<br><br>Flaubert, I'd do as SonnerAl suggested and just get it setup with password authentication first. Once you grasp that you can then try setting it up with a public key. That is my next step.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14691112</guid>
<pubDate>Sun, 30 Oct 2005 09:42:38 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14690481</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : <div class="bquote"><SMALL>said by  Flaubert <A HREF="/useremail/u/1120130"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>So you're saying:<br>a- Install CopSsh on the server.<br>b-Install Tunnelier on the client.<br>c -Forward only port 22 to my private IP ??<br><br>Sorry if I seem a little slow but there are a couple of things I need explained:<br><br>The parameters you've entered in Tunnelier<br> under "Host" and "Port"<br>On the "Login" tab:<br>I am not on a Domain, so should I just enter my Wan ip on there if I connect from outside my Llan?<br>On the Options tab:<br>Do I have to enter the same parameters as yours?<br><br>And also, could you be a little more specific on how to create those 2048 bit public/private keys?<br>I tried reading your openbsd link but I didn't understand it.<br><br>Thanks anyway for your help so far. I know a lot more than when I started this thread....<br> </DIV>This page has <B>general help with ssh-keygen</B>. Look at the page up to the part about changing permissions. The rest does <B>NOT pertain</B> to CopSSH/Tunnelier.<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/RemoteDesktop/SSH-RDP-VNC/OpenSSH/Private-publicKey.html" >theillustratednetwork.mvps.org/R&middot;&middot;&middot;Key.html</A><br><br>The page was created for <I>OpenSSH for Windows</I> and <I>PuTTY</I>, so the rest really does not pertain to CopSSH and Tunnelier. If you do use PuTTY, which is a very good option IMHO, as <I>seezar</I> did, then most still pertains, ie. the part about converting the key file to a format PuTTY understands. <B>Note the file paths are different than shown for CopSSH as are the location of the key files</B>. Also note the default key generated by ssh-keygen is now a 2048-bit RSA key.<br><br>If you do use CopSSH also note that the change I made in the <B>sshd_config</B> file for use with <I>OpenSSH for Windows</I>, ie. the <B>StrictModes</B> option, should be left as the default value <B>yes</B>.<br><br>I suggest you get the SSH link up using a password first. Once you have the basic tunnel setup and RDP working through the tunnel you can look at configuring and using a private/public key pair. Use a <B>strong password</B>.<br><br>As far as server host addressing is concerned, I use a free service from No-IP.com (&raquo;<A HREF="http://www.no-ip.com" >www.no-ip.com</A>) to map a fully qualified domain name to my ISP DHCP assigned IP address. That works very well for me.<br><br>Note the default initial authentication method is for a password versus the key as I have mine configured for.<br><br>The options page is the default except for the fact that I point to a customized .RDP file for the initial Remote Desktop connection to my PC Ashtabula, ie. the entry in the <I>Parameters</I> window.<br><br>I can't speak to how to configure NIS 2006 other than to say it must pass TCP Port 22 (or whatever port you have CopSSH listening on).<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14690481</guid>
<pubDate>Sun, 30 Oct 2005 06:07:53 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14689495</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : On the server I have software and hardware firewall.<br>The hardware part I can take care of by forwarding port 22 to my private ip<br>Now, will the connection get past Norton Internet Security 2006?<br>I guess if I enter CopSsh as a legitimate app in the list of trusted apps in NIS 2006 I should be Ok ?!!!<br>On the client side I will have only software firewall. I guess I will do the same thing for PuTTy.<br><br>Now How do I set up those public/private keys....?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14689495</guid>
<pubDate>Sun, 30 Oct 2005 00:44:08 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14688135</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : <div class="bquote"><SMALL>said by  Flaubert <A HREF="/useremail/u/1120130"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>    :</SMALL><BR><BR>So you're saying:<br>a- Install CopSsh on the server.<br>b-Install Tunnelier on the client.<br>c -Forward only port 22 to my private IP ??<br><br>Sorry if I seem a little slow but there are a couple of things I need explained:<br><br>The parameters you've entered in Tunnelier<br> under "Host" and "Port"<br>On the "Login" tab:<br>I am not on a Domain, so should I just enter my Wan ip on there if I connect from outside my Llan?<br>On the Options tab:<br>Do I have to enter the same parameters as yours?<br><br>And also, could you be a little more specific on how to create those 2048 bit public/private keys?<br>I tried reading your openbsd link but I didn't understand it.<br><br>Thanks anyway for your help so far. I know a lot more than when I started this thread....<br> </DIV>OK, I just set this up and it appears to work very well.<br><br>I installed CopSSH on my windows server. CopSSH is pretty cool, its basically OpenSSH with kind of a front end to make it easier to administer. After installing CopSSH I had to go in and 'activate' one of the accounts on the windows server. Once that account is activated I can now SSH to that windows server using that account.<br><br>I used PuTTY as a client. I put in the IP of the windows server to connect to. In the tunnel section of PuTTY I put i n a source port of 3390 and a destination of the IP address of the windows server and a destination port of 3389.<br><br>So now when I SSH to the windows server, I login with the account I activated. Then I run the remote desktop client. in the connect to box I put in localhost:3390 (3390 was the port I specific as the source). Then I am able to login to the windows server.<br><br>So basically, from the outside all you need to do is forward port 22 (or whatever port you are going to SSH to)to the IP of the windows server.<br><br>With it setup this way you can go into windows firewall on the server and remove access to remote desktop on port 3389 and make sure you allow access to port 22.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14688135</guid>
<pubDate>Sat, 29 Oct 2005 20:26:18 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14687589</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : So you're saying:<br>a- Install CopSsh on the server.<br>b-Install Tunnelier on the client.<br>c -Forward only port 22 to my private IP ??<br><br>Sorry if I seem a little slow but there are a couple of things I need explained:<br><br>The parameters you've entered in Tunnelier<br> under "Host" and "Port"<br>On the "Login" tab:<br>I am not on a Domain, so should I just enter my Wan ip on there if I connect from outside my Llan?<br>On the Options tab:<br>Do I have to enter the same parameters as yours?<br><br>And also, could you be a little more specific on how to create those 2048 bit public/private keys?<br>I tried reading your openbsd link but I didn't understand it.<br><br>Thanks anyway for your help so far. I know a lot more than when I started this thread....]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14687589</guid>
<pubDate>Sat, 29 Oct 2005 19:00:25 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14687448</link>
<description><![CDATA[<A HREF="/useremail/u/421841"><b>seezar</b></A> : Funny this topic is posted today. Earlier I was starting to research how to you SSH in conjunction with remote desktop.<br><br>If I understand correctly, in a configuration where the machine you want to use remote desktop on is behind a NAT router and you use SSH to tunnel in you only have to have port 22 on a SSH  server listening from the WAN. This makes it nice if you have multiple windows boxes on that network you want to have access to. Instead of having to open multiple ports on the WAN, 3389, 3390, etc.. you just have to have 22 open.<br><br>I've yet to try this out yet but thats how I understand it to work. If I'm incorrect someone please advise.<br><br>Here is a guide on the subject (there is also one posted on this site but the main search page is undergoing maintenance):<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/RemoteDesktop/SSH-RDP-VNC/RemoteDesktopVNCandSSH.html" >theillustratednetwork.mvps.org/R&middot;&middot;&middot;SSH.html</A><br><br>Edit: looks like SoonerAl already clarified what I said and posted the same link :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14687448</guid>
<pubDate>Sat, 29 Oct 2005 18:34:32 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14687267</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : I use <B>CopSSH</B> as my SSH server on an XP Pro SP2 box. I like CopSSH because it is being actively maintained as new releases of OpenSSH become available.<br><br>&raquo;<A HREF="http://www.itefix.no/phpws/index.php?module=pagemaster&PAGE_user_op=view_page&PAGE_id=12&MMN_position=22:22" >www.itefix.no/phpws/index.php?mo&middot;&middot;&middot;on=22:22</A><br><br>I also use <B>Tunnelier</B> as the client. Tunnelier can be configured to automatically launch a RDP session when the SSH tunnel is established if you want.<br><br>&raquo;<A HREF="http://www.bitvise.com/tunnelier.html" >www.bitvise.com/tunnelier.html</A><br><br>In my case I also use a 2048-bit private/public RSA key pair (with strong pass phrase) for authentication versus a password (strong or otherwise) and a listening port other than the default TCP Port 22. Now to be clear the latter measure is <B>NOT</B> a standalone deterrent/security measure, but it does not hurt either...<br><br>&raquo;<A HREF="http://www.openbsd.org/cgi-bin/man.cgi?query=ssh-keygen&sektion=1" >www.openbsd.org/cgi-bin/man.cgi?&middot;&middot;&middot;ektion=1</A><br><br>&raquo;<A HREF="http://forums.bitvise.com/index.php?showtopic=397&st=0&p=1581" >forums.bitvise.com/index.php?sho&middot;&middot;&middot;0&p=1581</A><br><br>The screen shots illustrate how I have Tunnelier configured to access my home LAN and my two XP Pro boxes...<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/LAN/LAN.jpg" >theillustratednetwork.mvps.org/LAN/LAN.jpg</A><br><br>...via the SSH tunnel. In my case the CopSSH server runs on the PC <I>Ashtabula</I>. The rest of the Tunnelier configurables are the defaults.<br><br>I also created and saved two .RDP files to customize the Remote Desktop experience for each PC. When I connect with the SSH tunnel the RDP link to my main desktop, ie. Ashtabula, automatically launches. I have to click on the NormanRDP desktop icon to initiate the RDP connection to the other PC...<br><br>For SSH all you need to do is to forward TCP Port 22 through any firewall/router at your home. All other traffic goes through the tunnel. No other ports need to be opened on the firewall/router...<br><br>&raquo;<A HREF="http://theillustratednetwork.mvps.org/RemoteDesktop/SSH-RDP-VNC/Diagrams/RDPThroughSSHTunnel.html" >theillustratednetwork.mvps.org/R&middot;&middot;&middot;nel.html</A><br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/speak/slideshow/14687267?c=915588&ret=L2ZvcnVtL3IxNDY5MDQ4MS54bWw%3D"><IMG TITLE="2898 bytes" BORDER=0 WIDTH=189 HEIGHT=123 SRC="/r0/download/915588~6f0205b9252e3ae4cad886996a9122ca/NormanRDP.JPG"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14687267?c=915593&ret=L2ZvcnVtL3IxNDY5MDQ4MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="70776 bytes" WIDTH=600 HEIGHT=573 SRC="/r0/download/915593.thumb600~19174736ca188c18c65f3c2a60d75570/Tunnelier1.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14687267?c=915594&ret=L2ZvcnVtL3IxNDY5MDQ4MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="73356 bytes" WIDTH=600 HEIGHT=573 SRC="/r0/download/915594.thumb600~f236c6250f546e0304ff2de9fc33433d/Tunnelier2.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14687267?c=915595&ret=L2ZvcnVtL3IxNDY5MDQ4MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="68606 bytes" WIDTH=600 HEIGHT=573 SRC="/r0/download/915595.thumb600~5690778b6a367ccf3f15b49b58c08714/Tunnelier3.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14687267</guid>
<pubDate>Sat, 29 Oct 2005 18:05:34 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14687108</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : What kind of ssh server (preferably free) should I install?<br>I didn't quite understand the port forwarding part of your answer. I know that I have to forward  Port 3389 to the server's IP address. What about port 22? Do I need to forward that one too if I install an ssh server on the RDC server?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14687108</guid>
<pubDate>Sat, 29 Oct 2005 17:39:00 EDT</pubDate>
</item>

<item>
<title>Re: The most secure way to use Windows Remote Desk</title>
<link>http://www.dslreports.com/forum/remark,14686662</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : I use RD over SSH tunnel. To do that you need an ssh server on the LAN to access RD using Putty. Install either on server or another computer.<br><br>Some argue that RD is secure enough, and if you want to do it that way then just configure your router to forward port 3389 to your WinXP Pro box. Otherwise you'll need to forward port 22 to your ssh server. If ssh server is on your XP Pro box, then no additional setup with Putty is required. If you have a separate ssh server, then you'll need to setup port forwarding in Putty.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14686662</guid>
<pubDate>Sat, 29 Oct 2005 16:21:44 EDT</pubDate>
</item>

<item>
<title>The most secure way to use Windows Remote Desktop</title>
<link>http://www.dslreports.com/forum/remark,14686628</link>
<description><![CDATA[<A HREF="/useremail/u/1120130"><b>Flaubert</b></A> : I've been reading up on how to secure a Remote desktop connection to a  XP Pro SP2 server.<br>I am already able to use that connection from inside my network with no problem.<br>If I want to use that connection from outside my network (Hotspots, Friends etc....) what is the best way to secure it.<br>I've read that ssh would do it because it would create an encrypted tunnel from the client to the server.<br>I've also heard that using Anonymizer would also encrypt all traffic.<br>I don't really care to hide my IP can anonymizer be used ONLY for encryption and not IP stealthing?<br><br>Can I use PuTTy to access RDC without installer a ssh server on the server?<br><br>I would greatly appreciate the help of someone who's solved the same problem successfully.<br><br>Thanks in advance]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14686628</guid>
<pubDate>Sat, 29 Oct 2005 16:15:36 EDT</pubDate>
</item>

</channel>
</rss>
