security - Installing Terminal Server (Remote Desktop Services) on a Domain Controller (Active Directory)
From my research, I've come to understand that "Installing Terminal Server (Remote Desktop Services) on a Domain Controller (Active Directory)" is a cardinal sin - apparently there are some serious security risks.
Could someone please elaborate and explain the risks?
More specifically:
How would someone go about compromising the server?
What is the worst that could happen?
Understand these aspects of my particular configuration:
No files are being stored on the server.
The directory is only being used to authorize users to use Remote Desktop Services.
The server will be accessed by less than 50 users.
Thank you.
Answer
The simplest things I can think of right off the bat: Start a process that fills the hard drives or RAM and crashes the server.
More insidious tactics would use everything from cache and side band attacks to malware and hacking toolkits to derive any and all information from AD, including potentially reversible passwords, security and other sensitive information.
Comments
Post a Comment