Ò£Ô¶µÄ´ºÌì | RDP±©Á¦¹¥»÷ÊÂÎñͨ¸æ
Ðû²¼Ê±¼ä 2020-05-010x00 RDP±©Á¦¹¥»÷
Ô¶³Ì×ÀÃæÐÒ飨RDP£©ÊÇMicrosoft¿ª·¢µÄ×îÊ¢ÐеÄÐÒéÖ®Ò»£¬£¬£¬£¬£¬£¬ËüʹÓû§¿ÉÒÔÔ¶³ÌÅþÁ¬ÊÂÇéÕ¾»òЧÀÍÆ÷¡£¡£¡£Ô¶³Ì×ÀÃæÐÒ飨RDP£©ÊÇÏÖÔÚÔ¶³Ì»á¼ûЧÀÍÆ÷µÄÒ»ÖÖºÜÊÇÊ¢ÐеĽâ¾ö¼Æ»®£¬£¬£¬£¬£¬£¬ËüʹԶ³ÌÊÂÇéÖ°Ô±¿ÉÒÔÔÚ¼ÒÖлá¼ûÆäWindowsÊÂÇéÕ¾»òЧÀÍÆ÷¡£¡£¡£
×ÔCOVID-19±¬·¢ÒÔÀ´£¬£¬£¬£¬£¬£¬¿¨°Í˹»ùʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬RDP±©Á¦¹¥»÷µÄÊýÄ¿ÒÑ´ó·ùÔöÌí¡£¡£¡£±¾Ô³õ£¬£¬£¬£¬£¬£¬ShodanµÄÑо¿Ö°Ô±±¨¸æËµ£¬£¬£¬£¬£¬£¬ÔÚÏß̻¶µÄRDPÖÕ¶ËÊýÄ¿ÔöÌíÁË41£¥¡£¡£¡£
×Ô3Ô³õÒÔÀ´£¬£¬£¬£¬£¬£¬Bruteforce.Generic.RDP¹¥»÷µÄÊýÄ¿ÏÕЩÆÕ±éÕû¸öÍøÂ磺
RDP¹¥»÷£¨¿¨°Í˹»ù£©
¹ØÓÚRDP±©Á¦¹¥»÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÖÖÖÖ¹¤¾ßÀ´É¨ÃèÍøÂ磬£¬£¬£¬£¬£¬ÒÔʶ±ðRDPЧÀÍÆ÷ʹÓõÄIPµØµãºÍ¶Ë¿Ú¹æÄ£¡£¡£¡£
Ò»µ©·¢Ã÷RDPЧÀÍÆ÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ã»áʹÓÃÖÖÖÖÓû§ÃûºÍÃÜÂëµÄ×éºÏÀ´±©Á¦ÆÆ½âRDPЧÀÍÆ÷µÄÃÜÂë¡£¡£¡£
ÈôÊǹ¥»÷Õß¿ÉÒÔ»á¼ûRDPЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔÔÚ°µÍøÉϳöÊÛRDPƾ֤¡¢½ûÓÃɱ¶¾Èí¼þ¡¢×°ÖöñÒâÈí¼þ¡¢ÇÔÈ¡¹«Ë¾Êý¾Ý¡¢¼ÓÃÜÎļþµÈ¡£¡£¡£
ƾ֤BinaryEdgeºÍShodanµÄͳ¼Æ£¬£¬£¬£¬£¬£¬ÏÖÔÚÁè¼Ý450Íǫ̀װ±¸½«RDP¹ûÕæµ½Internet¡£¡£¡£
RDP ÊýÄ¿
0x01 ÀÕË÷Èí¼þÖØµã¹¥»÷Ä¿µÄ
×Ô2016ÄêÄêÖÐÒÔÀ´£¬£¬£¬£¬£¬£¬Õë¶ÔRDPЧÀ͵Ĺ¥»÷Ò»Ö±ÔÚÔöÌí£¬£¬£¬£¬£¬£¬Ê×ÏÈÊÇÆ¾Ö¤2018ÄêµÄÒ»·ÝIC3±¨¸æ£¬£¬£¬£¬£¬£¬ÔÚ°µÍø³öÊÛRDPЧÀÍÆ÷ÃÜÂëµÄÊÂÎñÓÐËùÔöÌí¡£¡£¡£
ÀýÈ磬£¬£¬£¬£¬£¬2017Äêͨ¹ýxDedic³öÊÛ»ò³ö×âÁËÁè¼Ý85000̨RDPЧÀÍÆ÷£¬£¬£¬£¬£¬£¬±»ºÚ¿ÍÈëÇÖµÄЧÀÍÆ÷ƽ¾ùÊÛ¼ÛΪ6ÃÀÔª¡£¡£¡£
¶Ô¾ßÓпª·ÅRDP¶Ë¿ÚµÄЧÀÍÆ÷µÄ±©Á¦¹¥»÷Ò²±»ÓÃ×÷ÀÕË÷Èí¼þ¹¥»÷µÄ³õʼ¹¥»÷ǰÑÔ£¬£¬£¬£¬£¬£¬×î½üµÄÀý×ÓÊÇDharmaºÍDoppelPaymer¡£¡£¡£
0x02 VNCÒ²ÈÝÒ×Ôâµ½¹¥»÷
¿¨°Í˹»ùµÄICS CERTÑо¿ÍŶÓʹÓÃShodanËÑË÷ÒýÇæ·¢Ã÷ÁË600,000¶à¸öVNCЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÕâЩЧÀÍÆ÷¿É¾ÙÐÐÔ¶³Ì»á¼û¡£¡£¡£
¿¨°Í˹»ùÇå¾²Ñо¿Ô±Pavel CheremushkinÌåÏÖ£º¡°Îª±ÜÃâ¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§¶Ë²»Ó¦ÅþÁ¬µ½Î´ÖªµÄVNCЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÖÎÀíԱӦʹÓÃΨһµÄÇ¿ÃÜÂëÔÚЧÀÍÆ÷ÉÏÉèÖÃÉí·ÝÑéÖ¤¡£¡£¡£¡±
0x03·À»¤Õ½ÂÔ
¡ñ ÖÁÉÙҪʹÓÃÇ¿ÃÜÂë
¡ñ ½öͨ¹ý¹«Ë¾VPNʹÓÃRDP
¡ñ ʹÓÃÍøÂç¼¶±ðÉí·ÝÑéÖ¤£¨NLA£©
¡ñ ÈôÊÇ¿ÉÄÜ£¬£¬£¬£¬£¬£¬ÇëÆôÓÃË«ÒòËØÈÏÖ¤£¨2FA£©
¡ñ ÈôÊDz»Ê¹ÓÃRDP£¬£¬£¬£¬£¬£¬Çë½ûÓÃËü²¢¹Ø±Õ¶Ë¿Ú3389
¡ñ ʹÓÿɿ¿µÄÇå¾²½â¾ö¼Æ»®
0x04²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102495/hacking/covid-19rdp-bruteforce-attacks.html
https://securelist.com/remote-spring-the-rise-of-rdp-bruteforce-attacks/96820/
https://www.bleepingcomputer.com/news/security/rdp-brute-force-attacks-are-skyrocketing-due-to-remote-working/
https://gbhackers.com/rdp-brute-force-attacks/
0x05ʱ¼äÏß
2020-05-01 VSRCÐû²¼Îó²îͨ¸æ