By Keren Pollack, on February 12th, 2020

Short for line printer terminal, LPT is used by IBM compatible computers as an identification for the parallel port, such as LPT1, LPT2, or LPT3. The LPT port is commonly required when installing a printer on an IBM compatible computer. The majority of all computers utilize LPT1 and do not have an option for another LPT port unless additional ports are added to the computer.

 

POLICY DESCRIPTION:

This policy specifies whether to prevent the redirection of data to client LPT ports during a Remote Desktop Services session. You can use this setting to prevent users from mapping local LPT ports and redirecting data from the remote computer to local LPT port peripherals.

 

POTENTIAL VULNERABILITY:

If a value is configured to Disabled or Not Configured, the attacker can leverage it to map the client’s LPT ports. In addition, he can use the port to redirect data from the Terminal Server to the local LTP ports.

Windows RDP Server Hardening Guide

COUNTERMEASURES:

Enable this object wherever’s possible.

If the status is set to Disabled, Remote Desktop Services always allows LPT port redirection. If the status is set to Not Configured, LPT port redirection is not specified at the Group Policy level. However, an administrator can still disable LPT port redirection using the Remote Desktop Session Host Configuration tool.

 

POTENTIAL IMPACT:

RDS users won’t be able to access a client’s LPT port peripherals.

 

DEFAULT VALUE:

Disabled

 

CALCOM’S RECOMMENDED VALUE:

Enabled

RDS: Do Not Allow COM Port Redirection- The Policy Expert

HOW TO CONFIGURE:

 

  1. Press Windows Logo+R, type gpedit.msc, and press Enter.

 

  1. Click the arrow next to Computer Configuration under Local Computer Policy to expand it.

 

  1. Click the arrow next to Administrative Templates to expand it.

 

  1. Click All Settings to show all group policy settings.

 

  1. Scroll down to Do not allow LPT port redirection and double-click on it to view the setting.

6. Ensure the policy is Enabled and click OK.

 

 

AUTOMATE YOUR SERVER HARDENING:

Server hardening can be a painful procedure. If you’re reading this article, you probably already know it. Endless hours, labor and money are invested in this process, which can often result in production breakdown despite the effort to prevent it. CSH by CalCom is automating the entire server hardening process. CHS’s unique ability to ‘learn’ your network abolishes the need to perform lab testing while ensuring zero outages to your production environment. CHS will allow you to implement your policy directly on your production hassle-free. want to know more?

Click here and get the datasheet.