Ò£Ô¶µÄ´ºÌì | RDP±©Á¦¹¥»÷ÊÂÎñ¹«¸æ
°ä²¼¹¦·ò 2020-05-010x00 RDP±©Á¦¹¥»÷

Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©ÊÇMicrosoft¿ª·¢µÄ×îÊ¢ÐеĺÍ̸֮һ£¬ËüʹÓû§Äܹ»Ô¶³ÌÏνӹ¤×÷Õ¾»ò·þÎñÆ÷¡£Ô¶³Ì×ÀÃæºÍ̸£¨RDP£©ÊÇĿǰԶ³Ì½Ó¼û·þÎñÆ÷µÄÒ»ÖÖ¼«¶ÈÊ¢ÐеĽâ¾ö¹æ»®£¬ËüʹԶ³Ì¹¤×÷ÈËÔ±Äܹ»ÔÚ¼ÒÖнӼûÆäWindows¹¤×÷Õ¾»ò·þÎñÆ÷¡£
×ÔCOVID-19·¢×÷ÒÔÀ´£¬¿¨°Í˹»ù³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖ£¬RDP±©Á¦¹¥»÷µÄÊýÁ¿ÒÑ´ó·ùÔö³¤¡£±¾Ô³õ£¬ShodanµÄ×êÑÐÈËÔ±»ã±¨Ëµ£¬ÔÚÏß¶³öµÄRDPÖÕ¶ËÊýÁ¿Ôö³¤ÁË41£¥¡£
×Ô3Ô³õÒÔÀ´£¬Bruteforce.Generic.RDP¹¥»÷µÄÊýÁ¿ÏÕЩ±é¼°Õû¸öÍøÂ磺
RDP¹¥»÷£¨¿¨°Í˹»ù£©
¶ÔÓÚRDP±©Á¦¹¥»÷£¬ºÚ¿ÍʹÓø÷À๤¾ßÀ´É¨ÃèÍøÂ磬ÒÔ¼ø±ðRDP·þÎñÆ÷ʹÓõÄIPµØÖ·ºÍ¶Ë¿ÚÁìÓò¡£
Ò»µ©·¢ÏÖRDP·þÎñÆ÷£¬¹¥»÷Õß±ã»áʹÓø÷ÀàÓû§ÃûºÍÃÜÂëµÄ×éºÏÀ´±©Á¦ÆÆ½âRDP·þÎñÆ÷µÄÃÜÂë¡£
ÈôÊǹ¥»÷ÕßÄܹ»½Ó¼ûRDP·þÎñÆ÷£¬ÔòÄܹ»ÔÚ°µÍøÉÏÏúÊÛRDPÍ´´¦¡¢½ûÓÃɱ¶¾Èí¼þ¡¢×°ÖöñÒâÈí¼þ¡¢ÇÔÈ¡¹«Ë¾Êý¾Ý¡¢¼ÓÃÜÎļþµÈ¡£
ƾ¾ÝBinaryEdgeºÍShodanµÄͳ¼Æ£¬Ä¿Ç°³¬¹ý450Íǫ̀É豸½«RDP¹«¿ªµ½Internet¡£

RDP ÊýÁ¿
0x01 ÀÕË÷Èí¼þ³Áµã¹¥»÷Ö¸±ê
×Ô2016ÄêÄêÖÐÒÔÀ´£¬Õë¶ÔRDP·þÎñµÄ¹¥»÷Ò»ÏòÔÚÔö³¤£¬Ê×ÏÈÊÇÆ¾¾Ý2018ÄêµÄÒ»·ÝIC3»ã±¨£¬ÔÚ°µÍøÏúÊÛRDP·þÎñÆ÷ÃÜÂëµÄÊÂÎñÓÐËùÔö³¤¡£
ÀýÈ磬2017Äêͨ¹ýxDedicÏúÊÛ»ò³ö×âÁ˳¬¹ý85000̨RDP·þÎñÆ÷£¬±»ºÚ¿ÍÈëÇֵķþÎñÆ÷¾ùÔÈÊÛ¼ÛΪ6ÃÀÔª¡£
¶ÔÓµÓÐÊ¢¿ªRDP¶Ë¿ÚµÄ·þÎñÆ÷µÄ±©Á¦¹¥»÷Ò²±»ÓÃ×÷ÀÕË÷Èí¼þ¹¥»÷µÄ³õʼ¹¥»÷ý½é£¬×î½üµÄÀý×ÓÊÇDharmaºÍDoppelPaymer¡£
0x02 VNCÒ²ÈÝÒ×Ôâµ½¹¥»÷
¿¨°Í˹»ùµÄICS CERT×êÑÐÍŶÓʹÓÃShodanËÑË÷ÒýÇæ·¢ÏÖÁË600,000¶à¸öVNC·þÎñÆ÷£¬ÕâЩ·þÎñÆ÷¿É½øÐÐÔ¶³Ì½Ó¼û¡£
¿¨°Í˹»ù°²È«×êÑÐÔ±Pavel Cheremushkin°µÊ¾£º¡°ÎªÔ¤·À¹¥»÷£¬¿Í»§¶Ë²»Ó¦Ïνӵ½Î´ÖªµÄVNC·þÎñÆ÷£¬ÖÎÀíԱӦʹÓÃΨһµÄÇ¿ÃÜÂëÔÚ·þÎñÆ÷ÉÏÅäÖÃÉí·ÝÑéÖ¤¡£¡±
0x03·À»¤Õ½Êõ
¡ñ ÖÁÉÙҪʹÓÃÇ¿ÃÜÂë
¡ñ ½öͨ¹ý¹«Ë¾VPNʹÓÃRDP
¡ñ ʹÓÃÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©
¡ñ ÈôÊÇ¿ÉÄÜ£¬ÇëÆôÓÃË«³É·ÖÈÏÖ¤£¨2FA£©
¡ñ ÈôÊDz»Ê¹ÓÃRDP£¬Çë½ûÓÃËü²¢¹Ø¹Ø¶Ë¿Ú3389
¡ñ ʹÓÿ¿µÃסµÄ°²È«½â¾ö¹æ»®
0x04²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102495/hacking/covid-19rdp-bruteforce-attacks.html
https://securelist.com/remote-spring-the-rise-of-rdp-bruteforce-attacks/96820/
https://www.bleepingcomputer.com/news/security/rdp-brute-force-attacks-are-skyrocketing-due-to-remote-working/
https://gbhackers.com/rdp-brute-force-attacks/
0x05¹¦·òÏß
2020-05-01 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ