Hey Hey,

That sounds like the problem I had when I came in here... Terminal Services open to the world... I just went into routing and remote access and setup a VPN.

I think that the openSSH solution is too complex if you have non-IT people using it... It's too complex compared to the VPN solution in any case...

With things like TSGrinder (and subsequently other tools such as ProbeTS and TSEnum from the same site)... having TS open to the world is scary... I do it with my home system and sometimes that worries me.

Available From: http://www.hammerofgod.com/download.htm
TSGrinder is the first production Terminal Server brute force tool, and is now in release 2. The main idea here is that the Administrator account, since it cannot be locked out for local logons, can be brute forced. And having an encrypted channel to the TS logon process sure helps to keep IDS from catching the attempts.
TSGringer is a "dictionary" based attack tool, but it does have some interesting features like "l337" conversion, and supports multiple attack windows from a single dictionary file. It supports multiple password attempts in the same connection, and allows you to specify how many times to try a username/password combination within a particular connection.
Note that the tool requires the Microsoft Simulated Terminal Server Client tool, "roboclient," which may be found here:
ftp://ftp.microsoft.com/ResKit/win2000/roboclient.zip

There are still a couple of bugs we are working out- for instance, we've got a problem with using "l337" conversion with more than 2 threads open. There have also been requests to support standard brute-force-via-character-iteration attacks, and we will get to this when we can. In the meantime, enjoy the tool, and let me know how it works for you.
For those interested in the Blackhat presentation Ryan Russell and I made in Vegas, you can find that here:
ttp://www.blackhat.com/presentations/bh-usa-03/bh-us-03-mullen.pdf

Go nuts!

While it's not the end-all.. for a quick, low cost, easy to implement solution is to go into routing and remote access and quickly enable VPN... Takes less than 2 minutes.. but makes you feel much better.

Peace,
HT