ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Consider security when using Remote Assistance

Brien M Posey

Published: 24 Apr 2002 12:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Remote Assistance allows you to share control of an end user's computer via your organisation's network or the Internet. You can view the user's screen, control their keyboard and pointer, and even communicate with the user via a chat feature. Although several security concerns might make you think twice about using this feature.

It all begins with an invitation
The remote assistance process begins when the user who's having the problem generates a Remote Assistance invitation. The invitation is basically a code that authorises the person holding it to remotely control the PC that issued the invitation. After the user generates the invitation, they must send it to the help desk.

The invitation can be sent via e-mail or through an instant message. Invitations can also be dumped to a file, copied to a disk, and snail mailed to the help desk, or the file can be posted to a network directory or Exchange public folder. However, e-mail and instant messages are the customary methods for delivering such an invitation.

An invitation for trouble
Although the flexibility with which a user can transmit an invitation to the help desk makes the invitation a handy tool, there are some very serious security issues that this flexibility produces. For starters, users tend to be impatient. If the help desk takes too long to respond to the user's problem, there's nothing stopping the user from sending the invitation to someone else. For example, most large offices have an office "guru" who thinks he or she knows everything that there is to know about computers, and who manages to convince other employees that he or she can fix the problem. A frustrated employee who hasn't gotten immediate attention from the help desk could very well turn to such a person for help.

A user could also send a remote invitation to a friend who doesn't even work for your organisation. While this friend may be a bona fide computer expert, there's always the possibility that the invitation could be used as a chance to gather information about your organisation's network configuration. (However, you can prevent Remote Assistance from connecting to anyone outside your organisation by simply blocking port 3389 on your firewall.)

Any time a user issues an invitation to someone other than the help desk staff, there's a risk of that person deleting files, spreading viruses, uploading pirated software, or worse. You may now be wondering, "What exactly can someone gain access to through Remote Assistance invitations?"

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
134 out of 215 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Related Jobs

Manager of Business Infrastructure Projects

Technology Platforms designs, develops and operates Sky's Broadcast and IT infrastructure with the continued goal of improving flexibility and ...

Senior Active Directory Engineer

Experience This is a great opportunity to work for a Tier 1 bank with the flexibility of 1 day working from home, great rate and serious path to ...

Redhat Linux AdministratorWindowsXP,DR,Backup,Network Connectivity,FX

Project work includes drawing up, designing and implementing a DR Solution as well as developing the existing Linux Infrastructure. Furthermore, You ...

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Vista Upgrade Blog

XP survival, from one horses mouth, an...

Hi everyone....for those that need more information on XP survival, I have pasted this open letter from Bill Veghte, senior vice president of microsoft, found on microsoft .com. Hope... More

2 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment