Ò£Ô¶µÄ´ºÌì | RDP±©Á¦¹¥»÷ÊÂÎñ¹«¸æ

°ä²¼¹¦·ò 2020-05-01

0x00 RDP±©Á¦¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©ÊÇMicrosoft¿ª·¢µÄ×îÊ¢ÐеĺÍ̸֮һ£¬ËüʹÓû§Äܹ»Ô¶³ÌÏνӹ¤×÷Õ¾»ò·þÎñÆ÷¡£Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©ÊÇĿǰԶ³Ì½Ó¼û·þÎñÆ÷µÄÒ»ÖÖ¼«¶ÈÊ¢ÐеĽâ¾ö¹æ»®£¬ËüʹԶ³Ì¹¤×÷ÈËÔ±Äܹ»ÔÚ¼ÒÖнӼûÆäWindows¹¤×÷Õ¾»ò·þÎñÆ÷¡£


×ÔCOVID-19·¢×÷ÒÔÀ´£¬¿¨°Í˹»ù³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ£¬RDP±©Á¦¹¥»÷µÄÊýÁ¿ÒÑ´ó·ùÔö³¤¡£±¾Ô³õ£¬ShodanµÄ×êÑÐÈËÔ±»ã±¨Ëµ£¬ÔÚÏß¶³öµÄRDPÖÕ¶ËÊýÁ¿Ôö³¤ÁË41£¥¡£


×Ô3Ô³õÒÔÀ´£¬Bruteforce.Generic.RDP¹¥»÷µÄÊýÁ¿ÏÕЩ±é¼°Õû¸öÍøÂ磺


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

RDP¹¥»÷£¨¿¨°Í˹»ù£©


¶ÔÓÚRDP±©Á¦¹¥»÷£¬ºÚ¿ÍʹÓø÷À๤¾ßÀ´É¨ÃèÍøÂ磬ÒÔ¼ø±ðRDP·þÎñÆ÷ʹÓõÄIPµØÖ·ºÍ¶Ë¿ÚÁìÓò¡£


Ò»µ©·¢ÏÖRDP·þÎñÆ÷£¬¹¥»÷Õß±ã»áʹÓø÷ÀàÓû§ÃûºÍÃÜÂëµÄ×éºÏÀ´±©Á¦ÆÆ½âRDP·þÎñÆ÷µÄÃÜÂë¡£


ÈôÊǹ¥»÷ÕßÄܹ»½Ó¼ûRDP·þÎñÆ÷£¬ÔòÄܹ»ÔÚ°µÍøÉÏÏúÊÛRDPÍ´´¦¡¢½ûÓÃɱ¶¾Èí¼þ¡¢×°ÖöñÒâÈí¼þ¡¢ÇÔÈ¡¹«Ë¾Êý¾Ý¡¢¼ÓÃÜÎļþµÈ¡£


ƾ¾ÝBinaryEdgeºÍShodanµÄͳ¼Æ£¬Ä¿Ç°³¬¹ý450Íǫ̀É豸½«RDP¹«¿ªµ½Internet¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

RDP ÊýÁ¿


0x01 ÀÕË÷Èí¼þ³Áµã¹¥»÷Ö¸±ê


×Ô2016ÄêÄêÖÐÒÔÀ´£¬Õë¶ÔRDP·þÎñµÄ¹¥»÷Ò»ÏòÔÚÔö³¤£¬Ê×ÏÈÊÇÆ¾¾Ý2018ÄêµÄÒ»·ÝIC3»ã±¨£¬ÔÚ°µÍøÏúÊÛRDP·þÎñÆ÷ÃÜÂëµÄÊÂÎñÓÐËùÔö³¤¡£


ÀýÈ磬2017Äêͨ¹ýxDedicÏúÊÛ»ò³ö×âÁ˳¬¹ý85000̨RDP·þÎñÆ÷£¬±»ºÚ¿ÍÈëÇֵķþÎñÆ÷¾ùÔÈÊÛ¼ÛΪ6ÃÀÔª¡£


¶ÔÓµÓÐÊ¢¿ªRDP¶Ë¿ÚµÄ·þÎñÆ÷µÄ±©Á¦¹¥»÷Ò²±»ÓÃ×÷ÀÕË÷Èí¼þ¹¥»÷µÄ³õʼ¹¥»÷ý½é£¬×î½üµÄÀý×ÓÊÇDharmaºÍDoppelPaymer¡£


0x02 VNCÒ²ÈÝÒ×Ôâµ½¹¥»÷


¿¨°Í˹»ùµÄICS CERT×êÑÐÍŶÓʹÓÃShodanËÑË÷ÒýÇæ·¢ÏÖÁË600,000¶à¸öVNC·þÎñÆ÷£¬ÕâЩ·þÎñÆ÷¿É½øÐÐÔ¶³Ì½Ó¼û¡£

¿¨°Í˹»ù°²È«×êÑÐÔ±Pavel Cheremushkin°µÊ¾£º¡°ÎªÔ¤·À¹¥»÷£¬¿Í»§¶Ë²»Ó¦Ïνӵ½Î´ÖªµÄVNC·þÎñÆ÷£¬ÖÎÀíԱӦʹÓÃΨһµÄÇ¿ÃÜÂëÔÚ·þÎñÆ÷ÉÏÅäÖÃÉí·ÝÑéÖ¤¡£¡±


0x03·À»¤Õ½Êõ


¡ñ ÖÁÉÙҪʹÓÃÇ¿ÃÜÂë

¡ñ ½öͨ¹ý¹«Ë¾VPNʹÓÃRDP

¡ñ Ê¹ÓÃÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©

¡ñ ÈôÊÇ¿ÉÄÜ£¬ÇëÆôÓÃË«³É·ÖÈÏÖ¤£¨2FA£©

¡ñ  ÈôÊDz»Ê¹ÓÃRDP£¬Çë½ûÓÃËü²¢¹Ø¹Ø¶Ë¿Ú3389

¡ñ Ê¹Óÿ¿µÃסµÄ°²È«½â¾ö¹æ»®


0x04²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102495/hacking/covid-19rdp-bruteforce-attacks.html

https://securelist.com/remote-spring-the-rise-of-rdp-bruteforce-attacks/96820/

https://www.bleepingcomputer.com/news/security/rdp-brute-force-attacks-are-skyrocketing-due-to-remote-working/

https://gbhackers.com/rdp-brute-force-attacks/


0x05¹¦·òÏß


2020-05-01  VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾