Check: 5.048
Windows XP STIG:
5.048
(in versions v6 r1.32 through v1 r0)
Title
Terminal Services is not configured to allow only the original client to reconnect. (Cat II impact)
Discussion
This setting, which is located under the Sessions section of the Terminal Services configuration option, controls whether a different client may be used to resume a disconnected session. Only the original client should be able to resume a session to help prevent session hijacking.
Check Content
If the following registry value doesn’t exist or its value is not set to 1, then this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Subkey: \Software\Policies\Microsoft\Windows NT\Terminal Services\ Value Name: fReconnectSame Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Terminal Services -> Sessions “Allow Reconnection from Original Client Only” to “Enabled”.
Additional Identifiers
Rule ID: SV-3459r1_rule
Vulnerability ID: V-3459
Group Title: Terminal Services - Original Client Reconnection
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |