Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
How to get to my home PC from the road
Message
From
20/07/2007 14:33:18
Al Doman (Online)
M3 Enterprises Inc.
North Vancouver, British Columbia, Canada
 
 
To
20/07/2007 11:36:52
Jay Johengen
Altamahaw-Ossipee, North Carolina, United States
General information
Forum:
Windows
Category:
Computing in general
Miscellaneous
Thread ID:
01242367
Message ID:
01242458
Views:
11
>I can connect very easily/quickly to a server at work via Remote Desktop. How can I setup my PC at home to accomplish the same thing? Thanks!

Being able to connect to a work server from home, or to your home computer from work directly via Remote Desktop implies that both computers are directly connected to the Internet without intervening hardware firewalls. This is NOT good practice. Although the Windows software firewalls on both sides is better than nothing, any directly-connected machine is basically zero-day exploit meat. Crackers these days use tools such as Metasploit to programmatically try 20 or 30 different exploits against un-firewalled computers. If you've missed even a single patch, you're history.

Also, crackers port-scanning computers are looking for machines open to Internet connections via Remote Desktop/RDP. If you do this you have to use a strong password.

For any machine connected to the Internet there should be a hardware firewall, even if it's just something as inexpensive as a Linksys WRT-54GL (~$60) upgraded with dd-WRT firmware (free).

Once you have a hardware firewall in place, to implement remote control capabilities you have 2 basic options:

1. Open port(s) in the firewall to allow incoming connections. If you're good at networking and the client software supports it you can use non-standard ports and port map within the firewall/router which will greatly slow down crackers. If you open standard ports your Remote Desktop security is no better than with no firewall at all (but the firewall prevents other attacks on other ports).

2. If you don't want to open firewall ports or bother with advanced router/firewall configuration you can use a proxy service such as GoToMyPC. GoToMyPC is very easy to install and requires no firewall/router mods and is therefore more secure than option 1.
Regards. Al

"Violence is the last refuge of the incompetent." -- Isaac Asimov
"Never let your sense of morals prevent you from doing what is right." -- Isaac Asimov

Neither a despot, nor a doormat, be

Every app wants to be a database app when it grows up
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform