RDP sessions are an attack surface in their own right, exploited once an attacker already has privileged access to a terminal server or multi-user host. Windows lets a sufficiently privileged account connect to another user's session: hijacking takes over a disconnected or even active session without the victim's password, and shadowing observes a live session. Separately, RDP's device-redirection virtual channels, clipboard and drive mapping, move data between the client and server and leak it to whoever controls either end. These techniques convert host access into capturing other users' sessions, credentials, and data.
# enumerate sessions on a host you have privileged access to
query user # or: qwinsta (session IDs, states: Active/Disc)
Subtopics#
- Session hijacking: taking over another user's session without their password.
- Session shadowing: observing a live session.
- Clipboard redirection: capturing data via the clipboard channel.
- Drive redirection: reaching mapped client drives.