Shadow companies been operating a large RDP shop online, under covers for time now. its a market selling remote desktop protocol accesses to hacked machines. The online under-ground market have gathered and selling access to about 70,000 machines already hacked.
- Do not allow RDP connections over the open Internet
- Use Complex Passwords
- Use Multi-Factor Authentication
- Use an RDP Gateway
- Lock out users and block or timeout IPs that have too many failed logon attempts
- Use a Firewall to restrict access
- Enable Restricted Admin Mode
- Encryption
- Enable Network Level Authentication (NLA)
- Restrict users who can logon using RDP
- Minimize the Number of Local Administrator Accounts
- Ensure that Local Administrator Accounts are Unique
- Limit Domain Administrator Account Access
- Consider using an account-naming convention that does not reveal organizational information



Comments