Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Windows Remote Desktop Protocol Private Key Disclosure

Posted on 2009-05-13
5
Medium Priority
?
1,189 Views
Last Modified: 2012-05-06
Hi Experts:

Our security scan shows us that we have a vunerbility called "Windows Remote Desktop Protocol Private Key Disclosure". I have searched all over the internet but can't seem to find a solution.
Could someone what I need to do to fix this?
We are running Windows server 2003 R2 with SP2.
Thanks
0
Comment
Question by:changjia
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 12

Expert Comment

by:nsx106052
ID: 24378095
This article is pretty good on the issue you are seeing:
http://www.vulnerabilityscanning.com/Microsoft-Windows-Remote-Desktop-Protocol-Server-P-Test_18405.htm

Another thing to consider may be to create local firewall policies to only allow RDP traffic from the local subnet.  Also check to make sure the computer is up to date with all the latest MS security patches.
0
 

Author Comment

by:changjia
ID: 24378264
Hi Nsx106052,

From reading the article, I have learn that the solution is to Force the use of SSL as a transport layer for this service.

Do you know how to do that?

Thanks
0
 
LVL 12

Expert Comment

by:nsx106052
ID: 24378379
You will need to configure it in Group policy:

computer configuration/administrative templates/windows components/terminal services/encryption and security



0
 

Author Comment

by:changjia
ID: 24378688
It has always been set to high and require secure connection, how come the scan still shows the vunerbility?
Thanks
0
 
LVL 27

Accepted Solution

by:
Tolomir earned 2000 total points
ID: 24603401
Well the problem still persists but you can circumvent it:

---
http://social.msdn.microsoft.com/forums/en-US/winserver2008appcompatabilityandcertification/thread/de9ad6db-f814-4f44-bd64-ddcf9173ab74/

This issue was "fixed" by adding SSL support to TS in W2K3 SP1 and CredSSP to Vista/W2K8.

In W2K3 this was:

BUG: 806509 - APPROVED DCR: ETA: 8/6 WS2003SP1: RDP is vulnerable to man-in-the-middle attack

It was a well-known TS security issue. The private key used to sign a proprietary certificate (which contains the generated TS public key) is hardcoded in the code (see MS-RDPBCGR section 5.3.3 for more details).

Take a look at (this discuss SSL in W2K3 SP1):

http://technet2.microsoft.com/WindowsServer/en/library/a92d8eb9-f53d-4e86-ac9b-29fd6146977b1033.mspx?mfr=true

---

So with SSL enabled this is no longer an issue. When you disable SSL it is an issue, so it is not repaired.

Tolomir
0

Featured Post

Tech or Treat!

Submit an article about your scariest tech experience—and the solution—and you’ll be automatically entered to win one of 4 fantastic tech gadgets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I don't pretend to be an expert at this, but I have found a few things that are useful. I hope that sharing them here will help others, so they will not have to face some rather hard choices. Since I felt this to be a topic of enough importance and…
An overview of cyber security, cyber crime, and personal protection against hackers. Includes a brief summary of the Equifax breach and why everyone should be aware of it. Other subjects include: how cyber security has failed to advance with technol…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question