Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business How to secure your remote control access
MSP Business

How to secure your remote control access

By Ian Thornton-Trump
12 February, 2015

Remote Control software and VPN technologies have been around for a really long time. Norton PC Anywhere was one of the first widespread remote control utilities. In fact it still has an install base today, and was in one case recently brought to my attention in a security audit; it was the only way to reach an embedded Windows 2000 HVAC control system.

Unsurprisingly, Remote Control software has also been a favorite target of hackers. In fact it was reported in February 2012 that a group of hackers, known as Yamatough but operating under the umbrella of Anonymous, released the source code for Symantec's PCAnywhere product in a failed attempt to extort a $50,000 ransom. But I digress.

225887800System admins have utilized VPN for remote administration since Remote Access Service was first included on the Microsoft Windows Server Operating Systems, way back on Windows NT 3.51 (NT RAS). This technology largely supported “dial-up connectivity via modem”, but as Trumpet Winsock and a TCP/IP networking stack became available in later versions of Windows, admins everywhere jumped at the chance to work remotely.

Today, however, all is not well in Windows Remote Access Services utilizing Point-to-Point Tunneling Protocol (PPTP), unless specific measures are taken to safe guard it. It’s not that there is a glairing security hole here; it’s just that PPTP was developed in the late 90s. It was the very first VPN protocol that was supported by Microsoft’s servers and even though it is no longer recommended by Microsoft, it is still widely deployed.

PPTP is everywhere
Since that time, PPTP capability has been embedded in all sorts of devices – you find it in many routers, firewalls and embedded devices such as Network Attached Storage. Can it be broken? Yes; and it was successfully broken and never fixed in 1999, by Bruce Schneier and Mudge. Its vulnerability lies in the Microsoft Challenge Handshake Authentication Protocol (MS-CHAP v2): A challenge-response procedure that provides mutual authenticity – a brute force dictionary attack can figure out the password.

From a simplistic view, PPTP requires a “hole” (an open port) in your firewall. The Administrator account, in many versions of Windows Server cannot be locked out by bad password attempts, so this account is frequently used as a user ID to attack. As a result port 1723 comes under frequent attack – brute forcing “Administrator” as the user ID and many password attempts per second.

Just as PPTP is continually probed, Microsoft’s Remote Desktop Protocol (RDP) or terminal services come under frequent attack as well, and port 3389 is assaulted by many brute force password attempts just as PPTP is. Again, this remote admin feature requires a hole in the firewall. Hackers are taking a keen interest in the Remote Desktop Protocol and there are many patches and updates that address exploits that target this Windows Service. So, if you have RDP exposed to the Internet you better be up-to-date. If you’re running an older version of Windows Server, check to see if you’re set up to log failed login attempts – you may be surprised at how much activity you see in those logs.

VNC is another remote console-style application that again is targeted by hackers armed with brute force attacks against Port 5900. Finding exploits for this software is trivial and many exploits exist for the free and out-of-date versions; use this only at extreme peril.

Any port that lets traffic in is a liability
Unless you’re prepared to invest a lot of time constructing firewall Access Control Lists, in this day and age any open port on your network that lets traffic in is a vulnerability and a liability. If you have ports open to the Internet it’s frightening to think you’re not limiting traffic from certain IP address ranges to ports that should only be used by a limited number of users or administrators.

Enter the next generation of remote control utilities such as TeamViewer and Log-Me-In and any other “out bound, https-based” remote control utilities.  Why are they safer than RDP, PPTP or anything else – even IPSEC – running on Port 500?

In short these remote utilities don’t need an open port on your Firewall. Instead they reach out from the computer inside your network, through the Internet over https (encrypted with SSL), to a central server that in turn connects a client requesting that machine. Think of it as a “server” that sits in-between the two connections, brokering the connections.

I know for a fact that these companies spend a lot on security and are working to make both the encryption of the connection and the “brokering” of connections more robust, stable and secure.

The harsh reality is that any remote control connection is going to be vulnerable to some sort of attack. The analogy is that anything on the Internet can be attacked, the only (now arguable) way is to air-gap the secure system from the Internet. This pretty much stops the idea of remote administration dead in it’s tracks.

Although systems like RDP and PPTP are still popular, a solution that does not open a hole in your firewall, to the ravages of the Internet is surely a better choice in the increasingly hostile threat landscape of the Internet.

 

Ian Thornton-Trump, CSA+, CD, CEH, CNDA is CTO at Octopi Managed Services Inc. Ian is an ITIL certified Information Technology (IT) consultant with more than 20 years of experience in IT security and information technology. He enjoys and maintains a strong commitment to the security community. From 1989 to 1992, Ian served with the Canadian Forces (CF), Military Intelligence Branch; in 2002, he joined the CF Military Police Reserves and retired as a Public Affairs Officer in 2013.

You can follow Ian on Twitter® at @phat_hobbit.

You might also like...
MSP Business

What you need to know to get into Linux administration

MSP Business

3 key benefits to proactively monitoring your IT networks

MSP Business

How to keep your IT skills up to date

MSP Business

Remote access: 5 questions you need to ask - and get answered

MSP Business

The 5 biggest challenges for today's IT admins

MSP Business

Background Remote Management: A powerful tool for MSPs

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
  • TAP Blog Series: Maximizing Your Service Delivery Opportunity
  • Why Do MSPs Choose SolarWinds Backup? IT Central Station Finds Out
  • Seven Features Remote Assistance Software Should Have
  • TAP Blog Series: Creating Your Automation Strategy—Three Key Components You Must Have in Place
Categories:
  • Security (229)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (82)
  • Business Growth (75)
  • The Head Nerds (74)
  • IT Support (41)
  • Business (39)
  • Cybersecurity (37)
  • Automation (36)
  • Operations (33)
  • Mail (33)
  • Remote Management (27)
  • ITSM (25)
  • Data (21)
  • Cloud Computing (21)
  • Networking (21)
  • Marketing (14)
  • Product (11)
  • PSA (10)
  • Service Desk (4)
  • Services & Support (4)
  • Mobile (4)
  • Risk Intelligence (4)
  • Customer Service (3)
  • Internet of Things (3)
  • GDPR (2)
  • Research & Trends (2)
  • Training (2)
  • LOGICcards (1)
  • Business Risk (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.