Publishing RDP straight to the internet is one of the most consequential misconfigurations in practice: exposed 3389 endpoints are continuously discovered and attacked, and they are a dominant initial-access route for ransomware. Finding them is trivial, mass port scanning and search engines index them, and once found the host is fingerprinted and then attacked through credentials or pre-auth bugs. Moving RDP to a non-standard port or fronting it with RD Gateway (RDP over HTTPS/443) changes the discovery method but does not remove the underlying exposure.
# direct discovery
nmap -p3389 --open <range>
masscan -p3389 <range> --rate 1000
# search-engine discovery (external): Shodan/Censys "port:3389" or RDP product tags
# RD Gateway front-end (RDP tunnelled over 443)
nmap -p443 --script http-title <target> | grep -i 'RD Web\|Remote Desktop'
# fingerprint discovered hosts for posture
nmap -p3389 --script rdp-ntlm-info,rdp-enum-encryption <discovered>
Exploitation notes#
- Discovery is easy and continuous; the point of this step is to inventory exposed hosts and immediately fingerprint their NLA status, version, and domain so the follow-on (credentials vs pre-auth) is chosen per host.
- Non-standard ports only obscure: a full-range
-sVscan still identifies RDP, and search engines index it regardless of port. - RD Gateway and RD Web Access move RDP onto 443, which is a different surface (HTTPS, web auth, sometimes MFA) but still ultimately brokers RDP; enumerate those web front-ends separately.
- Internet-facing RDP combines every other RDP weakness: it is where credential stuffing, spraying, and pre-auth RCE are applied at scale.