Community discussions

MikroTik App
 
gosha
Member Candidate
Member Candidate
Topic Author
Posts: 154
Joined: Mon Jul 19, 2004 3:14 pm
Location: Tallinn, Estonia

RDP password scan

Mon Mar 27, 2017 2:26 pm

Hi

Is there a way to block RDP password scanners ? Seems that RDP server do not drop the session and there is no new connection every new password, so there not possible to do same way as ssh, limit 3-5 new tcp sesstions per 2-3 minutes and all. RDP server do not logs the source IP on audit failures in case if strong security is used. Is there a way to protect the RDP servers from a password scans?
 
Netstumble
newbie
Posts: 26
Joined: Tue Aug 05, 2014 9:11 am

Re: RDP password scan

Mon Mar 27, 2017 3:34 pm

I don't know of any, but I'm not up-to-date with the latest versions of MS server versions.
An idea would be to blacklist source ip if a lot of connections are made @ rdp port in a small time frame,
and then drop the attempted connections on firewall.
That would limit the problem somewhat.
Even better, you could limit the incoming connections in the firewall to known IPs
if the clients connections from outside have static addresses.
Or, set up some sort of vpn access to the rdp server(s).
From a security perspective an open rdp server is a big no-no.
 
Netstumble
newbie
Posts: 26
Joined: Tue Aug 05, 2014 9:11 am

Re: RDP password scan

Mon Mar 27, 2017 3:56 pm

re-reading your post.. (i'm on the 1st coffee, sorry),
disregard my post on firewalling since there is no new connection.
 
IntrusDave
Forum Guru
Forum Guru
Posts: 1286
Joined: Fri May 09, 2014 4:36 am
Location: Rancho Cucamonga, CA

Re: RDP password scan

Tue Mar 28, 2017 1:54 am

You can use this free tool, it works well.

http://www.terminalserviceplus.com/rdp-defender.php
 
gosha
Member Candidate
Member Candidate
Topic Author
Posts: 154
Joined: Mon Jul 19, 2004 3:14 pm
Location: Tallinn, Estonia

Re: RDP password scan

Tue Mar 28, 2017 8:19 am

Rdp Tool is not works at all because the logs do not contains the src ip address in case if strong security is used
 
IntrusDave
Forum Guru
Forum Guru
Posts: 1286
Joined: Fri May 09, 2014 4:36 am
Location: Rancho Cucamonga, CA

Re: RDP password scan

Tue Mar 28, 2017 8:53 pm

Then you will not be able to block brute force attacks.
 
mleonidov
just joined
Posts: 4
Joined: Sun Oct 16, 2016 10:21 am

Re: RDP password scan

Wed Mar 29, 2017 7:25 am

Who is online

Users browsing this forum: Amazon [Bot], gigabyte091, hazem, qatar2022, raiser and 211 guests