Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Windows: Prevent a worm by updating Remote Desktop Services (Critical! Patch Now!)
Microsoft Technet ^ | May 14, 2019 | Microsoft Security Response Center Team

Posted on 05/20/2019 5:30:49 PM PDT by dayglored

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-55 next last
To: thescourged1
> Since 2000, I’ve disabled Remote Desktop Connections after every new installation of Windows. Call me paranoid, lol.

I won't call you paranoid. I'll call you cautious.

Unless there's good reason to enable an external access service (RDP or any other), leave 'em off!

21 posted on 05/20/2019 6:23:54 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 19 | View Replies]

To: dayglored

Well, thanks for the heads up.


22 posted on 05/20/2019 6:34:05 PM PDT by Jim W N (MAGA by restoring the Gospel of the Grace of Christ and our Free Constitutional Republic!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: dayglored

bkmk


23 posted on 05/20/2019 6:38:37 PM PDT by sauropod (Yield to sin, and experience chastening and sorrow; yield to God, and experience joy and blessing.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Which one do I download for Windows 7, Monthly Rollup or Security only?


24 posted on 05/20/2019 6:57:17 PM PDT by Inyo-Mono
[ Post Reply | Private Reply | To 1 | View Replies]

To: Innovative

I just had a WIN 10 update an hour ago. It was the Win 10 1809 update.


25 posted on 05/20/2019 7:02:43 PM PDT by hsmomx3
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

That box that has Win98 has a video card that I cannot use in any later version of Windows. It does a single frame capture.
I cannot recall launching a browser there in a decade.
It does run Visual Basic 5 to automate the capture function.
It is using Windows drive share with the other machines in the house. Those being WinXP, Win7 and linux. I hope the shares are secure.


26 posted on 05/20/2019 7:04:07 PM PDT by George from New England (escaped CT in 2006, now living north of Tampa)
[ Post Reply | Private Reply | To 20 | View Replies]

To: dayglored

Great. MS “patched” my Win7 the other day. I turned it on the next morning to find it had bluescreened.


27 posted on 05/20/2019 7:05:05 PM PDT by VeniVidiVici
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks...I think. In the middle of installing 170 updates (!) I didn’t think I was that out of the loop. Last I went through this was APR 2019. What’s that in dog years?


28 posted on 05/20/2019 7:05:19 PM PDT by Attention Surplus Disorder (Apoplectic is where we want them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Inyo-Mono
> Which one do I download for Windows 7, Monthly Rollup or Security only?

AFAIK the "Security Only" differs from the "Monthly Rollup" in that it only addresses actual security vulnerabilities. The Monthly Rollup has those, but also includes non-security related bug fixes and occasional feature fixes.

Personally I keep my Win7 machines fully patched, so I get the rollups. But if you only want security fixes, then use the other.

29 posted on 05/20/2019 7:09:21 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 24 | View Replies]

To: dayglored

Thank you for taking the time to answer my question!


30 posted on 05/20/2019 7:18:31 PM PDT by Inyo-Mono
[ Post Reply | Private Reply | To 29 | View Replies]

To: Paladin2

31 posted on 05/20/2019 7:29:54 PM PDT by Pollard (If you don't understand what I typed, you haven't read the classics.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored
done... and THANK YOU!!! man it must be worse than AIDS for them to patch XP
32 posted on 05/20/2019 7:41:14 PM PDT by Chode ( WeÂ’re America, Bitch!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Chode
> man it must be worse than AIDS for them to patch XP

No kidding! I imagine that a lot of the remote/embedded XP based systems like ATMs probably are accessed by RDP. Yikes!

33 posted on 05/20/2019 7:50:44 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 32 | View Replies]

To: dayglored

So, I went to the security choice for my Win 7 64 bit laptop and it asked me if I wanted to save 4491755 to file ?? Didn’t seem to do anything. How do you just turn off remote desktop to be sure you aren’t open to attack?


34 posted on 05/20/2019 8:12:12 PM PDT by Hartlyboy
[ Post Reply | Private Reply | To 21 | View Replies]

To: dayglored

If you did the monthly rollup system update for May, you are A-OK.


35 posted on 05/20/2019 8:16:56 PM PDT by Zhang Fei (My dad had a Delta 88. That was a car. It was like driving your living room.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Hartlyboy
> ...Win 7 64 bit... How do you just turn off remote desktop...

Control Panel -> System -> Remote Settings -> Remote

Under "Remote Assistance", UN-CHECK "Allow Remote Assistance..."

Under "Remote Desktop", CHECK "Don't allow connections to this computer"

Click OK, close Control Panel.

36 posted on 05/20/2019 8:45:55 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 34 | View Replies]

To: dayglored
Thanks to the original poster! I applied the downloadable Microsoft fix to my ancient Windows XP SP3 box and also double-checked that Remote Desktop Services functionality was still disabled.

While we're on the topic of security, I'll mention in passing the Steve Gibson service and utility for reducing general vulnerability by making your Windows box less visible to the Internet.

GRC UnPlug n' Pray

GRC Shields UP!!

I also found the following article, which popped up in a quick Google search for UPnP vulnerabilities, to be reasonably interesting:

UPnP: Vulnerability As a Feature That Just Won’t Die

BTW, Mr. Gibson's website also has a number of other freeware downloads. I kind of like the one for assigning a unique beep, boop, or bong to each key from A through Z. It's not my cup of tea, but the idea of driving nearby lurkers crazy with a random melody has its points. ^^;

37 posted on 05/20/2019 9:22:37 PM PDT by Sarcasm Factory
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thanks dayglored...


38 posted on 05/20/2019 10:03:36 PM PDT by GOPJ
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored
" Under "Remote Assistance", UN-CHECK "Allow Remote Assistance..." Under "Remote Desktop", CHECK "Don't allow connections to this computer" "

Those were the settings on my Win7 laptop. Is it still vulnerable?

Right now the Microsoft page won't load for me, maybe because of my slow connection, thus I'm a bit in the dark as to what to do.

39 posted on 05/20/2019 10:25:37 PM PDT by 1_Rain_Drop
[ Post Reply | Private Reply | To 36 | View Replies]

To: dayglored

And shame on those people using default 3389 with a port open on their router.


40 posted on 05/20/2019 10:35:23 PM PDT by miliantnutcase
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-55 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson