Badlock: Patch Releases April 12, 2016
We won’t have to hold our breaths for any longer. For this upcoming Patch Tuesday, April 12, 2016, Microsoft and Samba will be releasing a patch to...
2 min read
Valeo Networks : Sep 11, 2019 12:00:00 AM
They say familiarity breeds contempt, but in the realm of cybersecurity, it also opens the door to vulnerability. Few things inflame a CISO’s contempt more quickly than exposing their enterprise’s sensitive data to hackers, but that is just what many sys admins are doing by relying on Microsoft’s all-too-familiar Remote Desktop Protocol (RDP).
RDP is a Microsoft-developed tool that uses a graphical interface to connect one computer to another over a network. While providing a handy way for sys admins to make quick changes and updates to a user’s computer, it also can also grant the same easy access to cyber-criminals.
“Let’s face it, it’s familiar,” CSO Online reported in discussing the latest RDP vulnerability. “It uses tools and techniques that we’ve used for years. It provides us with a resulting desktop that we’re familiar with. That familiarity means that attackers are familiar with it, too.”
According to British security company Sophos, cybercriminals are exploiting RDP to launch an increasing number of ransomware attacks. Many are leveraging a “wormable” vulnerability called Bluekeep that has the ability to spread self-replicating malware quickly across the internet in targeted RDP attacks.
Hackers are able to trigger mass ransomware outbreaks and take down RDP services, forcing their way into networks that often comprise thousands of other RDP services like a hungry fox in the data henhouse. These vulnerabilities also allow hackers to leverage password guessing software in brute-force attacks on RDP-connected computers.
If you are still using RDP to connect computers across your enterprise, Saalex recommends avoiding opening a direct RDP connection to the internet. Instead, employ a Remote Desktop web client. This option runs over the more secure HTTPS protocol, which encrypts communication to avoid man-in-the-middle attacks and other threats. This option allows you to publish apps and run a desktop environment using your internet browser of choice.
You can achieve additional peace of mind by deploying a Multi-factor Authentication (MFA) solution, such as those provided by DUO or Microsoft. Installed in front of the portal, such a solution acts as an application proxy, enforcing both MFA and single sign-on (SSO) access control. Azure AD allows you to determine password complexity and temporarily disable login after a set number of failed attempts.
Once implemented the above solutions provide the following safeguards:
Another step an enterprise can take to reduce exposure to brute-force password attacks is to use the native Windows firewall to set a rule limiting a machine’s access to specific IP addresses.
RDP also poses a threat to cloud computing vendors. Security experts recommend these enterprises modify the default configurations in their standard machine images. This includes updating remote administration configurations for cloud instances running Windows, which can help reduce the number of potential RDP attack targets.
The only drawback to these solutions is that they are a bit more complicated to set up than a standard RDP server. The good news is that Valeo Networks has the expertise to assist you in securing or refreshing your current RDP solution before hackers can take advantage of any “familiar” vulnerabilities. Contact us today for a complete assessment of your current cybersecurity posture, including any unaddressed RDP-related issues.
We won’t have to hold our breaths for any longer. For this upcoming Patch Tuesday, April 12, 2016, Microsoft and Samba will be releasing a patch to...
The advantages that notebook computers, smartphones and other wireless devices bring work and business are beyond dispute. The benefits of these...
1 min read
Managed Detection and Response (MDR) Secures Enterprises Inside and Out Today’s advanced security technologies have done an adequate job of...
With cutting-edge technology and quality customer service,
you’ll find everything you need to help your company soar
with Valeo Networks.
1006 Pathfinder Way
Rockledge, FL 32955
Business Hours:
M-F: 8AM-9PM
© 2024 Copyright Valeo Networks. All Rights Reserved.