Microsoft Windows XP Remote Desktop transmits user account names in plain text over the network when a connection is initiated. The account name sent is not necessarily the user account name on the remote machine; it is the most recent user account used by the remote desktop client. A sniffer could potentially capture traffic on a network and discover user account names, especially when repeated connections are being made to a particular machine from Remote Desktop clients.
Microsoft Windows XP Remote Desktop transmits user account names in plain text over the network when a connection is initiated. The account name sent is not necessarily the user account name on the remote machine; it is the most recent user account used by the remote desktop client. A sniffer could potentially capture traffic on a network and discover user account names, especially when repeated connections are being made to a particular machine from Remote Desktop clients.