RDP security best practices come down to one rule most admins break on day one: that protocol has no business facing the internet. Dr. Mike Saylor and Prasanna Malaiyandi join me to break down why RDP earned the nickname Ransomware Deployment Protocol, who's out there scanning for your open port right now, and what to actually do about it.
Here's the part that gets me. Every Windows box ships with this thing turned on. You didn't ask for it. Nobody handed you a manual. It's just there, running, waiting. Mike calls it a dollar store hammer — still a tool, still gets the job done, just not the one you'd pick if anybody gave you a budget. I call it a hack-me sign taped to your back.
We get into how initial access brokers work, and it's less sophisticated than you'd hope. Somebody runs a Shodan query, gets a list of every exposed RDP service on the planet with IP addresses and device types, cross-references it against leaked credentials, packages the whole thing up, and sells it. Mike says the recon that used to take days now takes about 30 seconds with the AI tools floating around the dark net.
Then there's the credentials-don't-even-matter problem. Default RDP traffic isn't encrypted internally. Mike walks through a routing table poisoning job where his team captured an admin's keystrokes going to a server. No login required. Just be in the middle.
The back half is all fixes. Block the protocol and the port, not one or the other, because attackers will happily move to a different port. Check 3389 before you kill it — your database might be sitting on it. Enforce network level authentication. Put a VPN or a zero trust product in front, and Mike points out enterprise-grade stuff runs about six bucks a user now, so the "no budget" excuse is thinner than it used to be. Bastion hosts. Group policy. Monitoring at the endpoint, network, and firewall layers, with a governance layer on top so you know what's allowed before something breaks at 2am.
Prasanna plays devil's advocate the whole way through and swears he isn't pro-RDP. Mike wears three hats and can't pick one. I have exactly one opinion and I'm not moving off it.
CHAPTERS:
00:00 Windows ships with a back door
01:26 Welcome and my Facebook Marketplace weekend
03:18 Why RDP means Ransomware Deployment Protocol
04:46 What RDP actually does
05:51 Blue hat, red hat: Mike's split opinion
06:11 Does RDP deserve its bad reputation?
08:10 On by default, and you can't fully kill it
09:30 The back door nobody locks
11:52 Does the cloud secure RDP for you?
14:12 Who scans for exposed RDP, and how Shodan works
17:10 Initial access brokers explained
18:36 Vulnerabilities that skip credentials entirely
19:08 Unencrypted traffic and stolen keystrokes
20:38 The never-on-the-internet rule
20:59 The network survival stack: VPN and zero trust
23:22 Block the port and the service
24:17 Stopping lateral movement once they're inside
25:25 Network level authentication
27:50 Port 3389: check before you block it
29:44 Bastion hosts
30:26 Monitoring, auditing, and governance
31:19 Blue, red, and purple hats