Security professionals allege RDP vulnerability

Wednesday, 30 May 2007, 12:06 AM EST

ccording to security professionals, it's possible for users of Microsoft's new RDP 6.0 client to bypass server-side security settings and successfully establish connections—even when their sessions haven't been authenticated.

"With Terminal server installed on Windows 2003 Server [sic] with current service packs and patches it is possible to bypass the server side setting that requires SSL with a self-signed cert," the Bugtraq contributor—an enterprise support specialist with a state government agency—wrote.

At ESJ.

[ Read more ]




Spotlight

Why vulnerability disclosure shouldn’t be a marketing tool

Brian Honan, CEO at BH Consulting, talks about a recent vulnerability disclosure trend – a trend that he believes may ultimately cause more harm than good: security vendors using vulnerability disclosure as a marketing tool with the goal of enhancing their company’s bottom line.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Wed, Jul 1st
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //