These days, Windows Remote Desktop Protocol (RDP) servers are being exploited by DDoS-for-hire services to expand Distributed Denial of Service (DDoS) attacks. However, we all know that Microsoft is one of the latest major tech firms to check that all its resources are being ill-treated as part of a DDoS attack.
Cybersecurity researchers have recently reported that Windows Remote Desktop Protocol (RDP) servers are being misused to expand their attacks. According to the report, the Microsoft RDP service has a built-in Windows service that is specifically proceeding on TCP/3389 and UDP/3389.
All these services allow authenticated remote virtual desktop infrastructure (VDI) so that it can access Windows servers and workstations.
The security consequence of RDP reflection/amplification attacks is probably quite high for all those companies whose Windows RDP servers are damaged as reflectors/amplifiers.
Not only this, but it also includes partial or full obstruction of mission-critical remote-access services, as well as further service disruption due to transportation capacity consumption, state-table exhaustion of stateful firewalls, load balancers, etc.
The cybersecurity researchers affirmed that the security impact to abusable Windows RDP servers could inform the systems administrators to either disable UDP-based service or to expand Windows RDP servers behind VPN concentrators; so, the main point is to prevent them from being used in RDP reflection/amplification initiatives.
There are many actions that have been recommended by the cybersecurity researchers and here we have mentioned them below:
Moreover, the cybersecurity firm, Netscout asserted that attackers could transfer malformed UDP packets to all the UDP ports of RDP servers that will eventually be reflected as the target of a DDoS attack, expanded in size, appearing in junk traffic crashing the target’s system.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…