Terminal server security issue with screen cache?

Terminal server security issue with screen cache?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Terminal server security issue with screen cache? Gary 12-19-2005
Posted by Gary on December 19, 2005, 12:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
I've never seen this mentioned anywhere, but at the hospital I work for, we
use a lot of thin clients with Terminal Servers. We also have PC's that
connect to them. When the client PC screen locks with the default logon.scr
screen saver while the session is idle in the background, if you switch back
to the Terminal Server session screen, there is about a 1/2 second where the
previously viewed screen is visible, then it updates to show the new screen,
which is the login screen. The problem is, it's pretty trivial to just click
on the taskbar icon of the session, bring it to the foreground, and hit
print screen in that half second, then paste it into paint, or something
like that. I've done it many times just to demonstrate the method. If there
is patient information in that screen (or any other sensitive info) it's
easy to snap a shot of it, and walk away with the data. I have tried
DE-selecting using bitmap caching in the TS client, but that doesn't affect
it.
Has anyone ever heard of alleviating this gap using settings on the client?
Thanks,



Posted by Steven L Umbach on December 19, 2005, 9:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If you feel that is a security risk then you may want to enable a logoff
screen saver in your environment being sure to train users because a logoff
screen saver will need to shut down open applications. Winexeit.scr is
available in the RK and there are many third party logoff screen
avers. --- Steve


"Gary" <phoneticallyitsgeemoonatsaratogacaredotorg> wrote in message
> Hi,
> I've never seen this mentioned anywhere, but at the hospital I work for,
> we use a lot of thin clients with Terminal Servers. We also have PC's that
> connect to them. When the client PC screen locks with the default
> logon.scr screen saver while the session is idle in the background, if you
> switch back to the Terminal Server session screen, there is about a 1/2
> second where the previously viewed screen is visible, then it updates to
> show the new screen, which is the login screen. The problem is, it's
> pretty trivial to just click on the taskbar icon of the session, bring it
> to the foreground, and hit print screen in that half second, then paste it
> into paint, or something like that. I've done it many times just to
> demonstrate the method. If there is patient information in that screen (or
> any other sensitive info) it's easy to snap a shot of it, and walk away
> with the data. I have tried DE-selecting using bitmap caching in the TS
> client, but that doesn't affect it.
> Has anyone ever heard of alleviating this gap using settings on the
> client?
> Thanks,
>
>



Similar ThreadsPosted
Terminal Server Security December 6, 2006, 5:10 pm
Security settings on the Terminal Server prevent automatic logon September 12, 2005, 3:18 am
Terminal Server on the DMZ December 26, 2005, 12:59 am
Terminal server log March 24, 2008, 10:48 am
Group Policy with Terminal Server July 23, 2005, 5:24 am
secure lockdown of terminal server liscencing? July 5, 2007, 6:58 pm
Using SSL Certificate for TSAC on NLB Windows 2003 Terminal Server March 28, 2006, 11:42 am
Terminal Server with Roaming Profile Locks Accounts January 3, 2007, 1:29 pm
Terminal server rdp, tls certificates & subject alternative names? June 30, 2008, 11:03 am
Possible Windows server 2003 SP1 bug - Script can blue screen serv October 13, 2005, 12:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy