RDP (Remote Desktop Protocol) is Windows's graphical remote-administration service, listening on TCP 3389, and it is among the most heavily attacked services on the internet: exposed RDP is a primary initial-access vector for ransomware. Its surface spans enumeration (version, encryption and NLA settings, the TLS certificate), authentication (brute force, spraying, credential stuffing, and the role of Network Level Authentication), exposure (internet-facing endpoints and weak TLS), pre-authentication protocol vulnerabilities (the wormable RCE class), and session abuse, taking over, shadowing, or using the device-redirection channels of RDP sessions.
nmap -p3389 -sV --script rdp-ntlm-info,rdp-enum-encryption <target>
# NLA/security posture and NTLM-leaked host/domain info
Subtopics#
- Enumeration: version, security settings, and certificate.
- Authentication: brute force, spraying, stuffing, and NLA.
- Exposure: internet-facing RDP and weak TLS.
- Pre-authentication flaws: wormable protocol RCE.
- Session abuse: hijacking, shadowing, and device redirection.