SageTV Community  

Go Back   SageTV Community > General Discussion > The SageTV Community
Forum Rules FAQs Community Downloads Today's Posts Search

Notices

The SageTV Community Here's the place to discuss what's worth recording, HTPC deals at retail stores, events happening outside of your home theater, and pretty much anything else you'd like. (No For-Sale posts)

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 05-22-2010, 08:28 AM
CanadianEh CanadianEh is offline
Sage Aficionado
 
Join Date: Apr 2004
Location: Colchester, VT
Posts: 434
Suggestions on ways to Secure RDP?

Good morning,

For years, I've always used port mapping and opened up TCP Port 3389 in my firewall for RDP access to my Sage box, to fix things remotely when needed.

Unfortunately, I'm getting a ton of traffic an errors int he event log indicating someone/something is trying to hack me through RDP. I do use secure passwords, but just because of all of the attempts I see, I've had to close down the port from the outside world.

Does anyone have a better solution for this that uses freeware or some cheap software? I figured I must not be the only one to attempt this, so one of you guys must have suggestions


Thanks!
-Jay
__________________
My systems:
Server: AMD Phenom Quad-Core 2.3Ghz, 4GB RAM, ECS A780GM-A MB, 2x HD-PVRs (connected to DirecTV HD STBs using ethernet channel changing), 1x AverMedia A180, OS RAID-1 mirror - 2x250GB 7200rpm SATA, Media RAID-1 mirror - 2x1TB 7200rpm SATA, USB-UIRT (remote control)
Main Client: Sage STX-HD100 Media extender
Second Client: Athlon XP 4000+, 2GB MB PC3200 DDR, Asus A8N5X MB, 512MB PCI-E ATI HD Radeon 3650, 160 GB SATA - hardware mirrored
Reply With Quote
  #2  
Old 05-22-2010, 08:57 AM
sic0048 sic0048 is offline
Sage Icon
 
Join Date: Nov 2007
Posts: 1,400
Use a different port to start with. With some routers you can simple map an external port to a different internal port on a specific computer on the network. This feature is generally called "Port Forwarding"

So intead of using port 3389 externally, perhaps you use port 25432. Forward external port 25432 to the internal port 3389 on the computer you wish to access via RDP.

This also allows you to access more than one internal computer via RDP. Simply forward another external port - perhaps 25433 to internal port 3389 of a different internal computer.

Hopefully that makes sense. If your router does not allow you to map ports like this, then you can always change the default RDP port that each computer uses. But that generally requires a registry hack, so the mapping of ports on the router is easier to do.

Hope that helps!
__________________
i7-6700 server with about 10tb of space currently
SageTV v9 (64bit)
Ceton InfiniTV ETH 6 cable card tuner (Spectrum cable)
OpenDCT
HD-300 HD Extenders (hooked to my whole-house A/V system for synched playback on multiple TVs - great during a Superbowl party)
Amazon Firestick 4k and Nvidia Shield using the MiniClient
Using CQC to control it all
Reply With Quote
  #3  
Old 05-22-2010, 09:00 AM
brewston brewston is offline
Sage Expert
 
Join Date: Apr 2006
Location: Surrey
Posts: 719
Tunnel it through ssh. You either need to install and run Cygwin on your PC at both ends or have a linux box on your network somewhere (My NAS runs linux so I use that)

Then, remotely you run :

ssh -C -L 3389:x.x.x.x:3389 user@y.y.y.y

Where x.x.x.x is the LAN IP address of the Windows PC and y.y.y.y your WAN IP address.

For extra security change the ssh port from 22 to something else and also make sure ssh doesn't allow remote logins as root
__________________
Tecra M5, 2 x HD200, 2 x HD300
2 x PCTV 290e
Win 7, Sage 7.1.9, Phoenix 2 STV
Stephane's XMLTV Importer, Digiguide,
Reply With Quote
  #4  
Old 05-22-2010, 11:46 AM
zoundz zoundz is offline
Sage Advanced User
 
Join Date: Sep 2004
Location: Jericho, VT
Posts: 205
You can run SSH on Windows for free without the bother of cygwin. WinSSHD works just fine and you can then tunnel VNC or RDP using Putty as a client on the remote. If you use a port other than 22 for your SSH access and if you only allow SSH public/private key authorization (no password auth), you are pretty much going to be immune to outside attacks.

YMMV but it works for me.
Reply With Quote
  #5  
Old 05-25-2010, 09:53 AM
[JiF]Mike [JiF]Mike is offline
Sage Advanced User
 
Join Date: Jan 2008
Posts: 106
I use the free version of www.logmein.com on a few pc's in the house including my sage box. If you use sage in service mode this works really well. If you have sage running in full screen mode you will get a black screen as the program does not transmit the sage screen for whatever reason. Pressing "shift-ctrl-f" will put sage in window mode so you can get to the desktop. LogMeIn is secure and you don't have to forward any ports in your router/firewall.
__________________
SageTV: Athlon 64 X2 4200+ | 4 GB | 1 Tuner | DirecTV via HD-PVR | Windows Home Server 2011
Clients: PlaceShifter | (3) STP-HD200
Primary TV: Samsung 61" DLP 1080p
Bedrooms: Toshiba 32" LCD 1080p
Customizations: Pheonix | Web Server

www.jiff.net
Reply With Quote
  #6  
Old 05-25-2010, 12:01 PM
razrsharpe razrsharpe is offline
Sage Icon
 
Join Date: Sep 2008
Location: Boston, MA
Posts: 2,111
+1 for logmein... i use it on all my pcs and the pcs of family members so i can remote trouble shoot them
__________________
Server 2003 r2 32bit, SageTV9 (finally!)
2x Dual HDHR (OTA), 1x HD-PVR (Comcast), 1x HDHR-3CC via SageDCT (Comcast)
2x HD300, 1x SageClient (Win10 Test/Development)
Check out TVExplorer
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Any new ways to record HD streams? vorius Hardware Support 5 10-03-2009 06:37 AM
19 ways to make ffmpeg to work for you bcjenkins The SageTV Community 2 09-24-2008 11:29 AM
Web User Interface + Secure = Broken Streaming Function jmoney579 SageTV Customizations 1 05-28-2008 01:51 AM
Most secure way to remote to PC korben_dallas General Discussion 17 04-05-2005 08:15 AM
How best to secure client access from Internet? Dr Squish SageTV Software 3 04-26-2004 05:42 PM


All times are GMT -6. The time now is 07:57 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2023, vBulletin Solutions Inc.
Copyright 2003-2005 SageTV, LLC. All rights reserved.