G
Guest
Hi,
i think the remote desktop for windows xp have an concept error and don't
verify correctly if another user it's connected and can bypass restrictions
allowing see the actions of the remote user (permit spy) .
The escenario it's:
PC1 - PC with remote desktop enabled
PC2 - PC for connect to PC1
PC3 - PC to spy the actions of PC2 in PC1
One worker have in office PC1 with remote desktop enabled, in home connect
from PC2 to PC1 typing the user&password correctly, other user (PC3) connect
to PC1 with a remote administration tool (dameware for ex.) , when the user
of PC3 connect to PC1, the correct it's view "this computer it's locked" but
only can view a blank screen if don't have activity PC1, but if PC2 it's
connected by remote desktop to PC1, the PC3 can view all in PC1, can view how
works PC2, and move the mouse, use the keyboard, etc.
I think if anyone it's connected remotely by remote desktop, if other user
connect to this machine with an RAT must view the "computer locked" and no
the remote desktop too, it's possible the user that are connecting with RAT
are not the same are connected by remote desktop.
Best regards.
i think the remote desktop for windows xp have an concept error and don't
verify correctly if another user it's connected and can bypass restrictions
allowing see the actions of the remote user (permit spy) .
The escenario it's:
PC1 - PC with remote desktop enabled
PC2 - PC for connect to PC1
PC3 - PC to spy the actions of PC2 in PC1
One worker have in office PC1 with remote desktop enabled, in home connect
from PC2 to PC1 typing the user&password correctly, other user (PC3) connect
to PC1 with a remote administration tool (dameware for ex.) , when the user
of PC3 connect to PC1, the correct it's view "this computer it's locked" but
only can view a blank screen if don't have activity PC1, but if PC2 it's
connected by remote desktop to PC1, the PC3 can view all in PC1, can view how
works PC2, and move the mouse, use the keyboard, etc.
I think if anyone it's connected remotely by remote desktop, if other user
connect to this machine with an RAT must view the "computer locked" and no
the remote desktop too, it's possible the user that are connecting with RAT
are not the same are connected by remote desktop.
Best regards.