security - Installing Terminal Server (Remote Desktop Services) on a Domain Controller (Active Directory)
From my research, I've come to
understand that "Installing Terminal Server (Remote Desktop Services) on a Domain
Controller (Active Directory)" is a cardinal sin - apparently there are some serious
security risks.
Could someone please
elaborate and explain the risks?
More
specifically:
How would someone go about
compromising the server?
What is the worst that could
happen?
Understand these aspects of my
particular configuration:
No files
are being stored on the server.
The directory is only being used to authorize
users to use Remote Desktop Services.
The server will be accessed by less than
50 users.
Thank you.
Answer
The simplest things I can think of right off the bat: Start a process that
fills the hard drives or RAM and crashes the
server.
More insidious tactics would use
everything from cache and side band attacks to malware and hacking toolkits to derive
any and all information from AD, including potentially reversible passwords, security
and other sensitive information.
Comments
Post a Comment