RDP Security Best Practices Every Admin Ignores Until It's Too Late
RDP security best practices come down to one rule most admins break on day one: that protocol has no business facing the internet. Dr. Mike Saylor and Prasanna Malaiyandi join me to break down why RDP earned the nickname Ransomware Deployment Protocol, who's out there scanning for your open port right now, and what to actually do about it.
Here's the part that gets me. Every Windows box ships with this thing turned on. You didn't ask for it. Nobody handed you a manual. It's just there, running, waiting. Mike calls it a dollar store hammer — still a tool, still gets the job done, just not the one you'd pick if anybody gave you a budget. I call it a hack-me sign taped to your back.
We get into how initial access brokers work, and it's less sophisticated than you'd hope. Somebody runs a Shodan query, gets a list of every exposed RDP service on the planet with IP addresses and device types, cross-references it against leaked credentials, packages the whole thing up, and sells it. Mike says the recon that used to take days now takes about 30 seconds with the AI tools floating around the dark net.
Then there's the credentials-don't-even-matter problem. Default RDP traffic isn't encrypted internally. Mike walks through a routing table poisoning job where his team captured an admin's keystrokes going to a server. No login required. Just be in the middle.
The back half is all fixes. Block the protocol and the port, not one or the other, because attackers will happily move to a different port. Check 3389 before you kill it — your database might be sitting on it. Enforce network level authentication. Put a VPN or a zero trust product in front, and Mike points out enterprise-grade stuff runs about six bucks a user now, so the "no budget" excuse is thinner than it used to be. Bastion hosts. Group policy. Monitoring at the endpoint, network, and firewall layers, with a governance layer on top so you know what's allowed before something breaks at 2am.
Prasanna plays devil's advocate the whole way through and swears he isn't pro-RDP. Mike wears three hats and can't pick one. I have exactly one opinion and I'm not moving off it.
CHAPTERS:
00:00 Windows ships with a back door
01:26 Welcome and my Facebook Marketplace weekend
03:18 Why RDP means Ransomware Deployment Protocol
04:46 What RDP actually does
05:51 Blue hat, red hat: Mike's split opinion
06:11 Does RDP deserve its bad reputation?
08:10 On by default, and you can't fully kill it
09:30 The back door nobody locks
11:52 Does the cloud secure RDP for you?
14:12 Who scans for exposed RDP, and how Shodan works
17:10 Initial access brokers explained
18:36 Vulnerabilities that skip credentials entirely
19:08 Unencrypted traffic and stolen keystrokes
20:38 The never-on-the-internet rule
20:59 The network survival stack: VPN and zero trust
23:22 Block the port and the service
24:17 Stopping lateral movement once they're inside
25:25 Network level authentication
27:50 Port 3389: check before you block it
29:44 Bastion hosts
30:26 Monitoring, auditing, and governance
31:19 Blue, red, and purple hats
Windows ships with a giant backdoor, and Microsoft turns it on by default.
Speaker:I'm talking about RDP, which I say stands for the Ransomware Deployment Protocol.
Speaker:This week, Dr. Mike Saylor and Prasanna join me to talk about RDP
Speaker:and its security best practices.
Speaker:Why does port 3389 keep showing up in breach reports?
Speaker:Why do initial access brokers love RDP?
Speaker:We talk about blocking the port and the service, network-level authentication,
Speaker:bastion hosts, and the one rule that I'll go to the mattresses for, RDP
Speaker:does not belong on the internet.
Speaker:If this is your first time watching or listening to me,
Speaker:I'm W. Curtis Preston, AKA Mr.
Speaker:Backup.
Speaker:I've been obsessing over backup recovery and now cyber recovery for over 30 years.
Speaker:If that's your bag, I'm your guy.
Speaker:You're not gonna find anybody that cares about this topic more than me.
Speaker:Ever since 1993 when I had to tell my boss that there were no backups
Speaker:of the database that we just lost.
Speaker:Now I've written five O'Reilly books, a blog, and now a podcast.
Speaker:Here we turn unappreciated admins into cyber recovery heroes.
Speaker:This is the Backup Wrap-Up
Speaker:hi, and welcome to the Backup Wrap Up.
Speaker:I'm your host, W. Curtis Preston, AKA Mr. Backup, and once again, I
Speaker:have a guy with me that followed me vicariously this weekend as I
Speaker:visited roughly a dozen random strange people's houses, Prasanna Malaiyandi.
Speaker:How's it going, Prasanna?
Speaker:I'm good, Curtis, and I'm glad that you were not kidnapped or missing a kidney
Speaker:or anything else like that because I know that you had to go around and pick up
Speaker:things from people you found on Facebook Marketplace, but those things worry me,
Speaker:I will say there was at least one house where we're like, "Okay, I'm
Speaker:not entering this fen-," if I was in Texas, it would be zero houses, right?
Speaker:but I'm like, "I'm not cracking this fence, but I'm not going into the
Speaker:yard to knock on a door," right?
Speaker:I'm like, I'm calling, I'm texting, I'm, But then there was one guy that
Speaker:came out in his, he was barefoot in his pajamas, and I'm like, "My God." have
Speaker:some decency, sir," plus his crib was d- But Mike, we, for the, daycare that
Speaker:I work with, I was, purchasing, 10, infant cribs, two rocking chairs, and
Speaker:table
Speaker:Yeah.
Speaker:that was my weekend.
Speaker:anyway, speaking of Mike, here we have my co-author of the lovely book right
Speaker:over my, left shoulder, Dr. Mike Saylor.
Speaker:How's it going, Mike?
Speaker:Oh, thank you.
Speaker:I didn't have any excitement over the weekend, but, hopefully this
Speaker:coming weekend I'll get to do something that spikes my adrenaline.
Speaker:Who knows?
Speaker:Yeah.
Speaker:just try walking up to 12 random strangers' houses.
Speaker:That is guaranteed, especially in Texas, to
Speaker:That's, that's old hat for me.
Speaker:I d- I used to do that all the time.
Speaker:Oh, no thank you.
Speaker:No thank you
Speaker:I'm gonna, I think I'm gonna, I'm gonna get in the middle of, a fight
Speaker:between, Black Vulture and my rooster.
Speaker:See if that'll, that maybe that'll get me charged
Speaker:up
Speaker:that I, is a story I wanna hear, but not today.
Speaker:today we are, we ha- we have been hinting at this episode many weeks.
Speaker:This is w- a favorite topic that I bring up.
Speaker:I allude to it quite a bit.
Speaker:It is my favorite protocol, of all because it is used to deploy ransomware, which is
Speaker:why it is called the ransomware deployment protocol, otherwise known as RDP.
Speaker:so
Speaker:I know you love this topic, so what I'm gonna do is I'm just
Speaker:gonna mute myself right now.
Speaker:And for all of the listeners out there, this is just gonna be the Curtis time.
Speaker:Mike, maybe you might get a word or two in here or there, but, I'm
Speaker:just gonna mute myself at this point
Speaker:You're killing me.
Speaker:This- it's just it's like, don't do this, right?
Speaker:But so many people do this, right?
Speaker:it's just there, there's so many initial breaches that are done via RDP, especially
Speaker:RDP that is accessible via the internet.
Speaker:I, I joke that it's like, that it's like having a, a kick
Speaker:me sign on your back, right?
Speaker:except it's a hack me, it's a hack me
Speaker:So, before you keep going on, maybe for some people who hopefully everyone's
Speaker:familiar with RDP, but maybe you should spend 30 seconds talking about what is R-
Speaker:my intro.
Speaker:I know, b-
Speaker:My
Speaker:you were getting like so intense and you're just about
Speaker:to go like jumping right in
Speaker:Like an old married couple
Speaker:I tell you, yeah, this is why.
Speaker:I don't know, I don't know why I put up
Speaker:This is why you keep me around
Speaker:Yeah, okay.
Speaker:So the actual name of this product is the Remote Desktop Protocol.
Speaker:And for those of you that don't know, this is the way that you can
Speaker:administer, especially, specifically a, a Windows-based… And by that,
Speaker:I actually don't mean the Windows with a capital W. like a, either a…
Speaker:what's the… What's… Is it Motif?
Speaker:Is that the, the Unix version?
Speaker:Isn't that what it's called?
Speaker:It's been a while since I've used that term.
Speaker:But basically a windowing type platform, which very commonly
Speaker:is, of course, Windows, right?
Speaker:if it is on, if it is enabled, you can basically run that other system as if
Speaker:you were sitting there with your mouse.
Speaker:And, which means that also, so can a hacker.
Speaker:And over the years, there have been all kinds of vulnerabilities
Speaker:that have resulted in all kinds of, hacks and, and therefore incidents
Speaker:and therefore ransoms, et cetera.
Speaker:And, Mike, do you also have a similar relationship with RDP?
Speaker:It depends on which, which hat I'm wearing.
Speaker:so if I'm
Speaker:Okay
Speaker:the blue hat, I hate RDP.
Speaker:If I'm wearing the red hat, love RDP
Speaker:yeah.
Speaker:That makes sense.
Speaker:That makes sense.
Speaker:Yeah.
Speaker:I can, I can ma- it makes sense a lot.
Speaker:But, is
Speaker:You're al- you're always, you always have a big but, Prasanna.
Speaker:Go
Speaker:No, okay.
Speaker:But, is RDP getting a lot of flack though because ad- administrators, users are
Speaker:misconfiguring it or not securing it in the proper way, or just taking, the easy
Speaker:route, and therefore it gets a bad name?
Speaker:Or does it truly deserve the, nickname ransomware deployment protocol?
Speaker:I think it's, I think it's a little bit of both, right?
Speaker:I think it, it got the name because it was so often used as, d- to deploy ransomware.
Speaker:But, it is, I would say it's a combination, and Mike, I, I am
Speaker:curious of your opinion here.
Speaker:it's both like just a protocol and the software underneath it that
Speaker:runs that protocol have had so many
Speaker:and therefore, breaches it, it's just a really dangerous protocol.
Speaker:And then, and people don't know, I don't think they realize
Speaker:just how dangerous this is.
Speaker:They leave it unprotected.
Speaker:They leave it connected to the internet, as a result, they get, they get hacked.
Speaker:what, w- would you agree with any of that, Mike?
Speaker:something you… I agree with a lot of that.
Speaker:and it, RDP has its purpose.
Speaker:It's a tool.
Speaker:it's a dollar store hammer instead of, the Home Depot, you know,
Speaker:professional roofing hammer, right?
Speaker:so it's still a tool, and you use what you have to use when, sometimes you
Speaker:don't have budget for more robust tool.
Speaker:But to your point about, it's not protected, it's connected to the internet,
Speaker:no one's monitoring when it's being used, all those other things that are
Speaker:also free and come with your Microsoft environment could help protect the use
Speaker:of RDP and just traditionally it's not.
Speaker:And so we're just leaving that dollar store hammer out there on
Speaker:the table for anybody to pick up.
Speaker:yeah, there, there's
Speaker:ways of making it better,
Speaker:and
Speaker:traditionally it doesn't
Speaker:isn't it on by default, Mike?
Speaker:The serv- yes,
Speaker:Yeah.
Speaker:This,
Speaker:it is.
Speaker:yeah,
Speaker:even on the work, even on the
Speaker:endpoints it's
Speaker:Just on by default
Speaker:and but
Speaker:the endpoint you can't turn, you can't turn all the RDP services off.
Speaker:You can only turn the, the primary, RDP call service off
Speaker:But, and everything you said, Mike, makes a lot of sense.
Speaker:A, there are certain things you can't do, and by the way comes by default,
Speaker:it's very insecure or could be very insecure if you aren't securing your
Speaker:firewall to prevent access, right?
Speaker:This could be externally facing.
Speaker:But it's, in my mind, that's like similar to being like, I have an
Speaker:amazing home alarm system, and I'm gonna leave the front door unlocked, right?
Speaker:Or, like there's certain things that are a little bit like user error, if you will,
Speaker:or users not using it in the way it was intended to be used or not understanding.
Speaker:And so I wonder if it's like, yes, there is this tool, yes, they could
Speaker:have done a better job of securing it or setting the right defaults,
Speaker:but maybe it's just getting a bad…
Speaker:And I sound like I'm pro-RDP.
Speaker:I am not pro-RDP, but I'm just taking the fl- I'm just taking the flip side
Speaker:and just trying to say, because I think it's useful in some environments, right?
Speaker:If you can secure it internally, right?
Speaker:Well, that, that's basically, that's what… It's not that RDP is evil,
Speaker:it's that it just ha- it, it can really be used for evil, right?
Speaker:but to take your analogy and maybe just tweak it a little bit, it's as if
Speaker:every new house comes with a back door that's wide open, and nobody thinks
Speaker:to maybe lock the back door, right?
Speaker:like every single builder puts in this door, and then
Speaker:advertises the door is open.
Speaker:It's got a big flashing, "I'm not locked," thing above it, and then nobody's like,
Speaker:"Hey, maybe we should do something." Did you wanna say something, Mike?
Speaker:It, it's a known protocol, so to your point, if that protocol was available
Speaker:at, in your house, bad guys just query the whole neighborhood, and
Speaker:I'll… Very quickly I can find out who's got RDP exposed to the internet.
Speaker:but Prasanna, made a comment about it, being a, a bad tool.
Speaker:It's not a bad tool.
Speaker:and there's a lot of tools out there that are used for evil.
Speaker:In fact, most tools that guys use to help do their job better are now used for evil.
Speaker:all the CIS internal tools are, have been cannibalized and turned to the dark side.
Speaker:it's all about risk mitigation and understanding what the risks are.
Speaker:So if you're using RDP in your environment, great.
Speaker:Have you thought about how to protect your environment from the
Speaker:RDP tool that you think you have to use in- instead of some other tool?
Speaker:And then cleaning up after yourself, too.
Speaker:to Curtis's point, it comes dis- installed or turned on by default.
Speaker:what if your default approach was not to use RDP?
Speaker:You're using some other remote management tool, but you forgot to turn RDP off.
Speaker:So there's just, there's just diligence, common sense, and the
Speaker:analysis of your environment, the risks, and all those things.
Speaker:So it's no different than taking something out of the box and plugging
Speaker:it in and thinking everything's fine, knowing that out of the box it's not
Speaker:fine and doing other things without consideration for reading the manual
Speaker:and knowing what you've turned on
Speaker:This manual thing of which you speak
Speaker:Do, you know, Mike?
Speaker:about this documentation
Speaker:Mike, so I totally get for an on-premises environment where you're deploying
Speaker:Microsoft servers and other things like that, it's on you to secure it.
Speaker:Do you know if cloud providers, when you are deploying Microsoft Windows
Speaker:in, say, Amazon AWS EC2 Compute, do they do a better job of helping
Speaker:secure things by default rather than what you would have on premises,
Speaker:or they're also in the same boat?
Speaker:it… You're also in the same… Depending on who your vendor is, you just by default
Speaker:spin up an Azure environment and put servers out there, absolutely Microsoft
Speaker:is gonna feed you their Kool-Aid.
Speaker:they're gonna be using RDP.
Speaker:It's gonna be configured the way they want it done, unless you tell them differently.
Speaker:So absolutely, yeah, Microsoft is a Microsoft shop, and they're gonna use all
Speaker:their stuff, and they think it's great.
Speaker:it's up to you to mitigate all that or to, to change whatever that might be.
Speaker:AWS is different.
Speaker:a lot of AWS, it's either you or a, a, a vendor that you've hired
Speaker:to help you build your virtualized environment, your cloud environment.
Speaker:that's kinda on you.
Speaker:so other environments that aren't Azure are a little different, but in most
Speaker:cases, unless you dictate how your servers are built, that, especially w-
Speaker:and it's only Windows, how your Windows servers are built, if you don't, if you
Speaker:don't spec- if you don't specify, then RDP is gonna be turned on by default.
Speaker:It's gonna be there whether you use it or not, and if you do use it, it's really
Speaker:no different than making sure you're using it appropriately and it's secured
Speaker:appropriately on-premise or in the cloud.
Speaker:The biggest problem, though, is if you've got it turned on in the
Speaker:cloud, it's already in the internet,
Speaker:Yeah
Speaker:So you've gotta be more cautious about, how am I using RDP?
Speaker:am I VPN-ing into a cloud environment and then using RDP, or am I using RDP
Speaker:from my desk through the firewall, out to the internet, through another firewall?
Speaker:That's even worse almost, 'cause just really,
Speaker:it, it all depends.
Speaker:it depends on your environment, depends on your budget, depends
Speaker:on your skill set, depends on your partners, depends on the environment.
Speaker:I'm just…
Speaker:We should, I think we should do a poll on how long
Speaker:To be a shirt
Speaker:Mike to say the phrase, "It depends," in each episode.
Speaker:but, Mike, let's move forward with, so the, e- earlier you were talking
Speaker:about wandering around the neighborhood and looking for the, in my analogy,
Speaker:the, the red flashing light, on.
Speaker:who would do that?
Speaker:Let's talk about, this, this really important group, the, the IABs
Speaker:it's, it ranges.
Speaker:security companies will search for those exposed services in order to identify
Speaker:opportunities for business development.
Speaker:there, it's not a… I frown upon that approach, but there are security
Speaker:companies out there that are the ambulance chasers, if you will.
Speaker:they're looking for known security flaws, and then they call you and go,
Speaker:"Hey, just to let you know, you've got this problem. We can help you fix it."
Speaker:I don't appreciate that, or condone it.
Speaker:Then there are people, people learning about cyber and this thing.
Speaker:"Hey, I heard that RDP's bad.
Speaker:I listened to this, Backup Wrap-Up podcast.
Speaker:I wanna go check that out." so they're gonna search for
Speaker:RDP. "All right, I found it.
Speaker:What do I do with it?" And so there's that.
Speaker:We call those script kiddies or newbies.
Speaker:and then you've got the people that really understand what it, the value
Speaker:of that exposed service, and they're gonna use tools like Shodan, which is a
Speaker:Nefarious.
Speaker:it's not, it's a legitimate search engine, but it's 100%
Speaker:used for bad stuff of the time.
Speaker:So in Shodan it's so in Google you would say, "What is RDP?" In Shodan you would
Speaker:say, "Show me every network that has RDP service exposed to the internet around
Speaker:the entire globe." And it will tell you.
Speaker:It, so it looks for those types of things.
Speaker:It doesn't look for articles, it looks for technical stuff,
Speaker:Right
Speaker:So Shodan is probably the, the number one if… It's probably the number
Speaker:one from a volume perspective for searching for stuff like that, and
Speaker:it gives you pretty verbose results.
Speaker:It'll tell you the IP address, the type of device that's promoting RDP.
Speaker:Is it a firewall?
Speaker:Is it a, a server out on the edge?
Speaker:Is it, what is it?
Speaker:country of origin, how long it's been there.
Speaker:there's any… And that's all on the normal internet.
Speaker:Then you can take that information into the dark net and see if,
Speaker:who, who else has attacked this.
Speaker:are there credentials that I can buy or find?
Speaker:So it's a process on the recon.
Speaker:So all that would be considered reconnaissance, and today all that can be
Speaker:done very quickly, especially with some of the dark net AI tools that are out there.
Speaker:you can put an attack list and a strategy together in 30 seconds
Speaker:But Mike,
Speaker:that… Hang on.
Speaker:Hang on, Prasanna.
Speaker:Mike, that was a great answer.
Speaker:It was not
Speaker:Now what you
Speaker:question I asked.
Speaker:the question I asked was who are initial access brokers?
Speaker:I thought I'd t- oh, no, I apologize.
Speaker:thought you were asking if IABs were the ones
Speaker:okay.
Speaker:Okay.
Speaker:Yeah, so
Speaker:and so my
Speaker:who, is this en- who is this entity,
Speaker:much
Speaker:and how do they figure into this?
Speaker:Yeah, initial access brokers are the guys that have, or, I'm gonna say guys,
Speaker:they are the, the group that has…
Speaker:They've already done the, the, the validation.
Speaker:so they searched for, and we'll just stick on the RDP theme for now.
Speaker:they've already identified all the assets with RDP accessible to the internet.
Speaker:They've already done their homework on are there known or published credentials
Speaker:for that device, for that RDP service.
Speaker:and they've packaged that together and they're, they've got that for
Speaker:sale for someone that wants to utilize it for an attack or whatever reason
Speaker:But is it safe to say though that without those credentials, just
Speaker:having RDP exposed out is bad?
Speaker:It is.
Speaker:it depends.
Speaker:No, it is because is it RDP… I- is it truly outbound RDP?
Speaker:so RDP from your environment to the cloud?
Speaker:or is it exposed to the internet so you can RDP in home or wherever if there's
Speaker:a problem or hopefully that's not your remote access mechanism for normal users.
Speaker:and then the other question is, did you change the password?
Speaker:Is it default?
Speaker:Is it easy?
Speaker:Is it, is it, 1234 and admin?
Speaker:so yeah, there's any number of ways that we can abuse,
Speaker:published RDP service
Speaker:But it also, in addition to, either guessing or obtaining the credentials
Speaker:to do this, my understanding is that there's also times where there are
Speaker:vulnerabilities of RDP that where you don't need said credentials.
Speaker:Is that correct?
Speaker:Yes, because of the vulnerabilities with RDP aren't specific to authenticating
Speaker:to RDP versus just capturing RDP traffic
Speaker:So internal to the network, default, RDP traffic is not encrypted
Speaker:So I can capture keystrokes.
Speaker:In fact, I've got a video from years ago where we did a DNS poisoning.
Speaker:it wasn't DNS, it was a
Speaker:At least DNS
Speaker:it was a routing table poisoning.
Speaker:and so we were able to get a router to sh- to, to send us the keystrokes
Speaker:that an admin was sending to a server, and we captured all of it, because
Speaker:our, at the, at, in that case, RDP, the RDP traffic was not encrypted.
Speaker:so I don't need access to be able to use RDP.
Speaker:I just need to be on the network.
Speaker:I just need to be in the middle
Speaker:to,
Speaker:to capture-
Speaker:to take your, that concept, and you said normally on an internal
Speaker:network it's not encrypted.
Speaker:If the server is directly on the internet, it's considering the internet the
Speaker:internal network at that point, right?
Speaker:So meaning, meaning that the, that your traffic would also not be encrypted
Speaker:It depends.
Speaker:So that point-to-point part, so if
Speaker:Right
Speaker:talking to the cloud firewall, is that a VPN?
Speaker:okay.
Speaker:assume, assuming there's no VPN.
Speaker:I'm just, I g- I got, a stupid server just sitting flat on the internet, is
Speaker:what I'm saying, not behind a firewall.
Speaker:the dumbest server ever, and no firewall, th- it, then it would be unencrypted.
Speaker:Right
Speaker:Okay.
Speaker:Which w- which I think we can all agree would be it, which is the point
Speaker:of this whole discussion, right?
Speaker:so I think we can agree, I think all three of us can agree is the never
Speaker:t- on the internet rule for RDP,
Speaker:I don't think it's just RDP.
Speaker:I think it's everything should not be on the internet unless
Speaker:it needs to be on the internet.
Speaker:That is true.
Speaker:I think there are some other services that are perhaps a little more secure
Speaker:that are s- safer to have on the internet, but, that is a much longer discussion.
Speaker:Mike, in the book, you talked about something called the survival stack.
Speaker:if people are gonna… If they need RDP, and by the way, I
Speaker:still think they don't need it.
Speaker:They need remote access, right?
Speaker:If you need remote access and you cannot afford a third-party remote
Speaker:access solution, then you need, is that, am I on the right track here?
Speaker:Then we start talking about the network survival stack.
Speaker:you wanna talk about that?
Speaker:Sure, and I wanna clear up a misconception about
Speaker:there are so many enterprise class tools out there now for VPN and
Speaker:zero trust that, I can think of offhand is, Zscaler, and it's $6 a month.
Speaker:and that… So that's enterprise.
Speaker:I'm not talking about the, the people at home that wanna be able to surf the
Speaker:internet and not, through a VPN and not have, traceability or whatever.
Speaker:You wanna… If you wanna use some of those other consumer
Speaker:level that's up to you.
Speaker:But enterprise stuff, Zscaler is very affordable, and it's very good,
Speaker:Six, that's $6 a month
Speaker:So
Speaker:per, box or per?
Speaker:per user.
Speaker:user, okay.
Speaker:Okay
Speaker:And that's mid-size.
Speaker:obviously a lot of companies will scale with you.
Speaker:if you wanna put 1,000 users on it, maybe it's not $6, maybe it's $4 or
Speaker:Gotcha.
Speaker:Okay
Speaker:it's affordable is what I'm getting at.
Speaker:And it's, and they're a lot easier to use than, back in the day you
Speaker:had to have a client installed.
Speaker:The client had to have a code or a cert or a token that tied it to the server,
Speaker:and then you had to put credentials in.
Speaker:Hopefully you had to put credentials in, and that they
Speaker:were different than your domain.
Speaker:So then you connect it, and then you have your domain.
Speaker:or you had to have a, a token with a, a key, a code on it.
Speaker:Two hours later
Speaker:things.
Speaker:Yes.
Speaker:so long story short, RDP on its own, if you have to use it, you
Speaker:need to have more controls in place to mitigate the risk of using it.
Speaker:So you don't wanna RDP directly into your environment.
Speaker:You want some other method, whether that's VPN or some zero
Speaker:trust solution, and then use RDP.
Speaker:So don't let RDP be exposed to the internet.
Speaker:Just have it running internally, and then u- use some other, more robust,
Speaker:trusted, configurable, remote access
Speaker:into the environment,
Speaker:and Mike, when we say don't let, it be exposed to the internet, the, is
Speaker:the easiest way to do that is just block that port on the firewall?
Speaker:Block it at the
Speaker:Yeah.
Speaker:Okay.
Speaker:Both the service and the port, or the protocol and the port
Speaker:so you talk… Yeah, go ahead
Speaker:that's important you could block the port and then you're compromised
Speaker:some other way, because you're not blocking the service, bad guys will
Speaker:just put it out a different port
Speaker:Yeah, that makes sense.
Speaker:But
Speaker:go ahead
Speaker:in this case though, Mike, that prevents external access to RDP, correct?
Speaker:In the sense of your RDP server is no longer visible on the internet.
Speaker:Is there things you could do in case a, an attacker comes in through some
Speaker:other, exploit or compromise, gets onto your network to prevent the
Speaker:lateral movement and exploiting RDP after they're inside your network?
Speaker:So that, I'm trying not to say depends.
Speaker:That, that is, it's based on how your architecture's built.
Speaker:So if you've got a simple flat architecture, you could still
Speaker:potentially define that rule on your firewall or your core switch.
Speaker:if you've got a complex environment, then you've gotta, you've gotta replicate
Speaker:that rule a- across your environment.
Speaker:You could also have group policy if you're a Windows environment
Speaker:that prevents it at the endpoint.
Speaker:You could also have an endpoint anti-malware solution like Huntress,
Speaker:as an example, that will trigger on the use of those protocols.
Speaker:You can… This is back to living on the land.
Speaker:Don't let it be available on that endpoint, right?
Speaker:Uninstall it, turn it off.
Speaker:bad guys, if a bad guy's made it to the endpoint and they wanna
Speaker:pivot, they're not gonna use RDP.
Speaker:They're gonna… They're probably gonna bring their own remote
Speaker:management tool like, ServiceNow or Splashtop or something like that
Speaker:So how does, NLA, network level authentication,
Speaker:figure into this discussion?
Speaker:Oh, what… Your architecture will,
Speaker:It depends.
Speaker:your architecture will dictate that as well.
Speaker:So if, again, if you've got a flat environment, you've
Speaker:got a domain controller.
Speaker:What, there's a lot of environments don't even have domain controllers.
Speaker:if you don't have a domain controller, your users are not authenticated to
Speaker:the network, they're just users that have access to other assets and the
Speaker:internet, that's probably actually not as risky because the endpoints don't
Speaker:have access to other stuff, unless you've created shares and things.
Speaker:But an environment where you've got a domain controller and you're
Speaker:authenticating to it, domain controller now has to be configured well so that
Speaker:the authentication of one device can't be cloned or duplicated or stolen.
Speaker:those Kerberos tickets or, sessions, from one asset to the other.
Speaker:And you can define in your architecture those routing restrictions that
Speaker:says, Mike's identity, can only persist on one device at a time.
Speaker:So group policy, architecture, good architecture design, good domain
Speaker:controller configuration, firewall rules.
Speaker:A-again, depends on, architecture.
Speaker:but all of that is, it's not new.
Speaker:It just takes time to work through, and if it's done right to begin
Speaker:with, it's a lot easier to manage
Speaker:The, yeah, let's move to the sort of the, the things that they should do, right?
Speaker:We talked about things not to do.
Speaker:you talked
Speaker:Don't use Windows.
Speaker:Oh, I remember, B- by the way, I did… while you two were talking at some
Speaker:point, I did look, and by the way, I was correct on Motif, but I do date myself.
Speaker:Apparently, it's not used very much anymore.
Speaker:That is the Windows manager for
Speaker:The gnome?
Speaker:old school Unix and Linux.
Speaker:and, it's still used… It's very lightweight, and it's still used
Speaker:in some distributions, but mainly for those that want a retro '90s
Speaker:aesthetic, according to that.
Speaker:I've got Openbox, Fluxbox, IceWM, there's a bunch of other ones.
Speaker:Anyway, just wanna make sure I wasn't crazy.
Speaker:So one, one of the things that we talked earlier about blocking the, the port
Speaker:and the service, the port's 3389, but, is something apparently that could
Speaker:result in a problem if you do that.
Speaker:but so you wanna talk about that, Mike?
Speaker:3389 could be used by something else.
Speaker:And so similar to, other recommendations we've given, you need to do some
Speaker:analysis in your environment to make sure that there's not some preexisting
Speaker:rule or service or connection, going out this or any other suspicious port.
Speaker:you wanna… you don't wanna impact business.
Speaker:we recommend 3389 'cause that's common for RDP or default RDP, but
Speaker:your environment could very well be using 3389 for a database connection
Speaker:or a, a session call or something
Speaker:It's sad, but, you have that problem, sad on you.
Speaker:So the next thing I've got on our to-do list here is to, if
Speaker:possible, I think everything, everything we're saying, right?
Speaker:No… Everything we're saying is investigate this
Speaker:in your environment, right?
Speaker:And that is, if possible, enforce network-level authentication, right?
Speaker:Because that's gonna support, or that's gonna, require users to prove who they
Speaker:are before they, start a- an RDP session.
Speaker:and then prasanna, what's our final recommendation?
Speaker:Final recommendation is if you are coming from external into an RDP environment
Speaker:or connecting from one to an RDP environment, use something to secure
Speaker:that external connection like a VPN such that you have-- you are not exposing
Speaker:RDP directly to the internet, but you do have that sort of proxy or secure
Speaker:connection into your network to then pass off into the VP, into the RDP session.
Speaker:Related to that, I w- I, we didn't have it on our list, but
Speaker:we discussed it in the book.
Speaker:that of course would be learning ransomware response and recovery.
Speaker:I can't believe I didn't mention the name earlier.
Speaker:We d- we discussed the concept of a bastion host, where you configure it
Speaker:so that if you're going to use RDP, and anything else that's dangerous,
Speaker:a- as I make quotes in the air, right?
Speaker:that you consider a bastion host, where all RDP has to go
Speaker:via this connection, right?
Speaker:And I think VPN is one of those ways.
Speaker:A bastion host would be another way.
Speaker:And, we seem to have lost Mike.
Speaker:I don't know
Speaker:No, he's back
Speaker:over there?
Speaker:You're glitching
Speaker:My all fuzzy.
Speaker:I'm not sure what's going on
Speaker:maybe you've been day drinking.
Speaker:All right,
Speaker:Wait, I have one more thing to ask or see.
Speaker:Mike, is there anything from an auditing perspective that you would recommend
Speaker:for remote desktop connections?
Speaker:or monitoring
Speaker:Oh, monitoring for sure.
Speaker:and there's, there are different ways of doing that too.
Speaker:There's layers.
Speaker:There's the endpoint layer, the network layer, the firewall perimeter
Speaker:layer for all those protocols.
Speaker:The important part is the governance layer, which is what we, establishing the
Speaker:policy of what we allow, what we prohibit, and then what are the exceptions.
Speaker:And then documenting that so when things do come up, we can very quickly
Speaker:determine if it's allowed or not.
Speaker:And then your incident response policy would, or procedure would say,
Speaker:"When these do, when these things happen, here are the people we need
Speaker:to involve in the conversation so we can determine how to address it."
Speaker:you heard it here, folks.
Speaker:Prasanna is pro RDP.
Speaker:I'm against it, and, Mike is with me.
Speaker:Well, no, Mike purple hat is with you.
Speaker:Mike red hat is against you
Speaker:so
Speaker:blue says, "No RDP." Red says, "I love RDP." Purple says, "Let's,
Speaker:let's educate each other on the, the appropriate use of RDP or not."
Speaker:The Backup Wrap-Up is written, recorded, and produced by me, W. Curtis Preston.
Speaker:If you need backup or DR consulting, content generation, or expert witness
Speaker:work, check out backupcentral.com.
Speaker:You can also find links for my O'Reilly books on the same website.
Speaker:Remember, this is an independent podcast, and any opinions that
Speaker:you hear are those of the speaker and not necessarily an employer.
Speaker:Thanks for listening