WINDOWS 7 - RDP - DoS - BLUE SCREEN
- Layout for this exercise:
data:image/s3,"s3://crabby-images/8c5a1/8c5a13539b19f69ad8bc77bbc4ea433499cb615c" alt=""
- Remote
Desktop Protocol (RDP) is a Microsoft protocol which provides a
graphical interface for connecting to a computer through a network
connection. RDP accepts connections at port TCP 3389
- Operating
systems like Windows 7 offer three options for RDP, regarding
security: Control
Panel -> System and Security -> System -> Remote settings ->
System Properties -> Remote:
data:image/s3,"s3://crabby-images/33eb4/33eb4441820583536e784713b97b35d4a5d34442" alt=""
- An
attacker can detect that the RDP 3389/tcp port is open at the
victim's computer:
data:image/s3,"s3://crabby-images/421ff/421ffb842305dd844cac312b9c245555a692f265" alt=""
- The less secure option allows any type of RDP connections, which is a vulnerability that can be taken advantage by exploiting it with the appropriate Metasploit module:
data:image/s3,"s3://crabby-images/5c7df/5c7df18546f8e782d786bcc406b6f4803a568e92" alt=""
- Required
options for this module are simple, just the victim's IP and the RDP
port (3389):
data:image/s3,"s3://crabby-images/a82f7/a82f7ddc6a12224f311a26ccea81310f2892e55e" alt=""
data:image/s3,"s3://crabby-images/e388a/e388ad71c86131d1030574fc34e86fe2adb1d90d" alt=""
- Running
this module some crafted packets are sent to the victim:
data:image/s3,"s3://crabby-images/d7283/d7283a803734e8f3233deff3d9171354da4f136d" alt=""
- As a
consequence a Denial Of Service attack results in a Blue Screen at
the target machine:
data:image/s3,"s3://crabby-images/65b30/65b308f3d06562bb217c2a98beb68ad5feca9ad3" alt=""
- To avoid this DoS attack, the RDP service should be disabled by default:
data:image/s3,"s3://crabby-images/a28c4/a28c43c907754f21f3a54bafc52d427be8477c14" alt=""
- Also,
the secure option with Network Level Authentication could be
considered:
data:image/s3,"s3://crabby-images/1badf/1badfccf9ead90c4806fc860e22725141cabbafa" alt=""