RDP Auth Server Scan Surge: Security Threat Explained
- A surge in reconnaissance activity targeting microsoft Remote Desktop Web Access and RDP Web Client suggests attackers are preparing for credential-based attacks, according to internet intelligence firm GreyNoise.
- Internet intelligence firm GreyNoise detected a substantial increase in scanning activity on February 28, 2024, involving 1,971 IP addresses simultaneously probing Microsoft Remote Desktop web Access (RD Web)...
- The scans are designed to identify timing flaws in the RDP authentication process.
Coordinated Scanning Campaign targets Microsoft RDP, Signaling Potential Attacks
Table of Contents
A surge in reconnaissance activity targeting microsoft Remote Desktop Web Access and RDP Web Client suggests attackers are preparing for credential-based attacks, according to internet intelligence firm GreyNoise.
What Happened?
Internet intelligence firm GreyNoise detected a substantial increase in scanning activity on February 28, 2024, involving 1,971 IP addresses simultaneously probing Microsoft Remote Desktop web Access (RD Web) and RDP Web Client authentication portals. greynoise blog This represents a notable anomaly, as the company typically observes only 3-5 such addresses daily.
The scans are designed to identify timing flaws in the RDP authentication process. These flaws could allow attackers to confirm the validity of usernames, paving the way for subsequent credential-based attacks like brute-force or password-spray attempts.
How Timing Flaws Work
timing flaws exploit subtle differences in system response times. When an RDP server receives a login attempt, it responds differently depending on whether the username is valid or invalid. An attacker can measure these response times; a faster response to a valid username indicates a correct guess. OWASP Top Ten
This technique,while subtle,can be automated to rapidly test numerous usernames,effectively bypassing conventional security measures.
Key Findings from GreyNoise
GreyNoise’s analysis revealed several key details:
- Massive Spike: 1,971 IP addresses engaged in coordinated scanning.
- Client Signature: 1,851 of the scanning ips shared the same client signature.
- Malicious Reputation: Approximately 92% of the IPs with the shared signature were already flagged as malicious.
- Geographic Origin: The majority of the scanning IPs originated from Brazil.
- Target Location: The primary targets of the scans were IP addresses located in the united States.
These findings suggest a single botnet or a coordinated group utilizing a common toolset is responsible for the scans. GreyNoise Blog
Potential Impact and Mitigation
Triumphant exploitation of timing flaws in RDP could led to:
- Account takeover: Attackers gaining unauthorized access to systems.
- Data Breaches: Sensitive details being stolen.
- Ransomware attacks: Systems being encrypted and held for ransom.
Organizations can mitigate this threat by:
- Enabling Multi-Factor Authentication (MFA): Adding an extra layer of security beyond passwords.
- Monitoring RDP Logs: Detecting suspicious login attempts.
- Patching RDP Systems: Ensuring systems are up-to-date with the latest security patches.
- Network Segmentation: Limiting access to RDP services to only authorized users and networks.
- Implementing Account Lockout Policies: Preventing brute-force attacks.
