Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Remote Desktop
Message
De
24/10/2013 13:22:18
 
 
À
24/10/2013 12:40:16
Information générale
Forum:
Windows
Catégorie:
Sécurité
Titre:
Versions des environnements
OS:
Windows Server 2012
Divers
Thread ID:
01586307
Message ID:
01586310
Vues:
45
>Hi All,
>
>I'm not a networks expert or anything so forgive the ignorance. We have a remote desktop server running which allows users to access our program remotely via TS or Citrix style access. Our program allows a user to open files, such as a DBF file or a text file. I have found a security issue in that a user can use the standard windows File->Open dialog to navigate around the C drive and even go so far as going into the Windows sub-folder, into the System32 sub-folder, and then run the management console to see user login names and details! They can navigate into the Users folder to see what other users have access to the server. How can one prevent this or is that not possible?
>
>I cannot restrict users from the Windows sub-folder because I think they need that access in order to log on with Remote Desktop surely? I cant deny access to the Users folder for the same reason (although windows does prevent the user from accessing any specific user folder other than his own).

If you have "frisky" users poking around, ultimately you're probably going to need to lock your TS down. Googling [terminal server lockdown] for your specific version should give you some ideas.
Regards. Al

"Violence is the last refuge of the incompetent." -- Isaac Asimov
"Never let your sense of morals prevent you from doing what is right." -- Isaac Asimov

Neither a despot, nor a doormat, be

Every app wants to be a database app when it grows up
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform