Click here to get back home

RDP Dictionary Attack Logon Failures - Capture Internet IP Address?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
RDP Dictionary Attack Logon Failures - Capture Internet IP Address? heers_muhgoo 07-30-2007
Posted by heers_muhgoo on July 30, 2007, 8:03 am
Please log in for more thread options
I have RDP on a Server2K3 accessible from the Internet. Occasionally I
see dictionary attacks in the security logs, about 30 to 40 logon
attempts in a period of a couple of minutes, using some common logon
ID's (administrator, admin, etc.). Since the attacks are coming from
outside the firewall (hardware), the event log does not show the IP
address. Any way to capture this so that I can block these folks at
the firewall?

I've been able to successfully block some east Asian IP addresses from
getting through on FTP and suspect they are the same ones trying to
hack RDP.

FWIW, administrator account is renamed and not used for general
administrative access. The server, always kept up to date with service
packs, has never been hacked but these folks are mildly persistent (so
far).

TIA

Mike

Posted by S. Pidgorny on August 1, 2007, 5:11 pm
Please log in for more thread options
There is a way - reconfiguring connectivity through the firewall to avoid
NAT that you use - but wha is the point? Blocking IPs isn't effective way to
counter the threat.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

>I have RDP on a Server2K3 accessible from the Internet. Occasionally I
> see dictionary attacks in the security logs, about 30 to 40 logon
> attempts in a period of a couple of minutes, using some common logon
> ID's (administrator, admin, etc.). Since the attacks are coming from
> outside the firewall (hardware), the event log does not show the IP
> address. Any way to capture this so that I can block these folks at
> the firewall?
>
> I've been able to successfully block some east Asian IP addresses from
> getting through on FTP and suspect they are the same ones trying to
> hack RDP.
>
> FWIW, administrator account is renamed and not used for general
> administrative access. The server, always kept up to date with service
> packs, has never been hacked but these folks are mildly persistent (so
> far).
>
> TIA
>
> Mike



Similar ThreadsPosted
Workstations showing logon failures by users can still logon? November 27, 2007, 6:56 pm
Mysterious Logon Failures in Security Log July 25, 2005, 11:52 am
cifs and rpcss logon failures August 16, 2006, 2:31 pm
capture and record login times December 8, 2005, 10:50 am
FTP Attack July 20, 2006, 8:27 pm
Audit Failures from users searching folders!! October 5, 2007, 5:37 pm
Kerberos machine authentication - apparent authentication failures May 30, 2005, 10:35 am
for internet December 18, 2006, 7:21 am
internet restriction July 22, 2005, 2:33 am
Internet access December 8, 2007, 11:53 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap