1. 程式人生 > >Morto Worm Spreading via Remote Desktop Protocol

Morto Worm Spreading via Remote Desktop Protocol

August 31, 2011

A new Internet worm has been reported that spreads via Microsoft's Remote Desk Protocol (RDP). This worm scans an infected host's subnet for other hosts running RDP and attempts access to them using a pre-configured set of user names (including "administrator") and passwords. According to Microsoft, this worm can be remotely controlled and updated, such that infected hosts may be ordered to perform denial-of-service attacks or other functions. Because of this, the behavior of the worm may change over time.

This threat can be mitigated by following some basic security best practices. First, ensure that you are enforcing strong password choice on your user accounts. Note that the unique 'Administrator' account password AWS automatically assigns to your instance upon launch complies with this recommendation and should be sufficiently strong to make brute force password guessing infeasible. If you use the EC2 Windows Configuration Service to override this automatically assigned password, please ensure that your selection is cryptographically strong. Microsoft guidance on creating strong passwords can be found here: 

http://technet.microsoft.com/en-us/library/cc736605%28WS.10%29.aspx and instructions on using the Windows Configuration Service can be found here: http://docs.amazonwebservices.com/AWSEC2/latest/UserGuide/index.html?appendix-windows-config.html

Second, ensure that you are restricting inbound RDP (TCP 3389) to only those source IP addresses from which legitimate RDP sessions should originate. These access restrictions can be applied by configuring your EC2 Security Groups accordingly. For information and examples on how to properly configure and apply Security Groups, please refer to the following documentation:

http://docs.amazonwebservices.com/AWSEC2/latest/UserGuide/index.html?adding-security-group-rules.html

相關推薦

Morto Worm Spreading via Remote Desktop Protocol

August 31, 2011 A new Internet worm has been reported that spreads via Microsoft's Remote Desk Protocol (RDP). This worm scans an in

RDP協議,remote desktop protocol,遠端桌面協議

一 前言二 概述三 同絡層次四 各連線模組說明五 各功能模組說明六 rdpwin結構、資料流說明七 總結一、前言RDP, Remote Desktop Protocol,遠端桌面協議,是一個多通道(multi-channel)的協議,讓使用者(客戶端或稱“本地電腦”)連上提供

Remote Desktop Connection for mac 報錯:證書或相關鏈無效。

top alt ext nts jsb 技術 fill 相關 watermark 報錯截圖:mac連接遠程桌面報證書或相關鏈無效錯誤 解決辦法: 1. 2. Remote Desktop Connection for mac 報錯:證書或相關鏈無效。

Remote desktop manager 如何導入.db配置文件

技術 src manage .com 導航 com gpo post data 在導航側欄選擇3點設置。 選擇添加新的連接,individual中選擇SQLite, 輸入名字,Database文件地址(例如Onedrive上team共享的.db文件),當然onedr

Remote Desktop

windows 2016 RemoteEnable Remote Desktop to connect to the Server from other Computers.This exmaple shows to enable single session function of Remote Desk

mac遠程桌面Microsoft Remote Desktop for Mac的安裝與使用

net ros tps tail detail mic 安裝 OS AC mac遠程桌面Microsoft Remote Desktop for Mac的安裝與使用 學習了:https://blog.csdn.net/ytangdigl/article/details/78

Free Remote Desktop Sharing Software

ast ins prev dual nis tween one for ike TeamViewer 請添加鏈接描述TeamViewer is a remote PC support/control and screen-sharing tool. You can rem

遠端桌面管理工具Remote Desktop Connection Manager

使用說明:RDCMan安裝好後雙擊開啟RDCMan.exe,首次使用需要新增配置副檔名為rdg  1.點選File新建配置檔案,這裡命名為MRU,存放在安裝的根路徑下  建好之後,MRU會顯示在左側選單樹,右鍵MRU選擇Add Server,開啟下圖視窗   Server

mac 遠端桌面連線工具 Microsoft Remote Desktop for Mac 的安裝與使用

mac遠端桌面工具Microsoft Remote Desktop for Mac  下載地址:https://pan.baidu.com/s/1idbmjBrJWToK3M8sSkQclA  開啟之後,如下 配置完之後,找不到儲存按鈕啥的,不需要,填完資

Microsoft Remote Desktop的安裝使用

原由 工作中要通過堡壘機去檢視正式服的資料庫資料,所以我的小mac要下載Microsoft Remote Desktop來遠端連線到Windows的堡壘機。 下載 找了半天的Microsoft Remote Desktop,後來才發現中國區根本下載不了,只有到

mac 使用microsoft Remote Desktop 遠端連線本地資料夾方法

mac使用microsoft remote desktop 連線遠端伺服器之後,有時候想傳輸遠端檔案到本地,輸命令比較麻煩,microsoft remote desktop本身提供了,能把mac本地資料夾顯示在遠端的功能: 下面是操作方法(這個主要適用於伺服器是windows 或者linux

Remote Desktop Manager for Mac(遠端桌面管理軟體)中文破解版

Remote Desktop Manager for Mac(遠端桌面管理軟體)附註冊碼 v6.1.0.0中文破解版下載地址 如果你正好需要一款能夠幫助您遠端控制電腦桌面的軟體,千萬不要錯過remote desktop manager Mac中文破解版。Remote Desktop Manage

Tab Key not working when using Xfce remote desktop

short ubuntu ice com switch class out .config running Xfce 遠程桌面Tab鍵設置 Use CTRL-tab instead of tab The XFCE Terminal has kidnapped the

mac遠端桌面Microsoft Remote Desktop for Mac的安裝與使用

1、很多時候我們需要使用到遠端桌面登入到一臺windows電腦或阿里雲的windows伺服器上,在windows中系統中附件裡有自帶的遠端桌面。mac怎麼辦呢? 2、給大家介紹一個mac遠端桌面工具M

mac遠端桌面Microsoft Remote Desktop for Mac

1:在mac電腦遠端桌面可以使用,Microsoft 遠端桌面   使用 Microsoft Remote Desktop 這個還是很老的版本; 可惡的微軟mac版本不更新,更新了中國區下載

解決Remote Desktop的 “CredSSP encryption” 問題

當你的Remote Desktop在連線時出現:An authentication error has occurred. The function requested is not supported. Remote Computer: This could be due

Windows Server 2012 Web方式修改域使用者密碼-通過Remote Desktop Web實現

1.在Windows Server 2003上,作業系統預設提供了一種修改域使用者密碼的方式 2.在Windows Server 2008上,可以提取Windows Server 2003上的程式碼來實現相同的功能 3.在Windows Server 2012上,提供了一種

Remote Desktop Gateway on AWS

AWS provides a comprehensive set of services and tools for deploying Microsoft Windows-based workloads on its highly reliable and secure cloud inf

通過外網遠端訪問Window Remote Desktop 遠端桌面 Win10

開啟遠端服務:設定為自動啟動修改遠端桌面的服務埠:1: Run - Regedit;2:找到 HKEY_LOCAL_MACHINE/ SYSTEM/ CurrentControlSet/ Control/ Terminal Server/ Wds/ rdpwd/ Tds/ t

Microsoft Remote Desktop for Mac APPSTORE商店下載

曾經使用微軟出的remote desktop 2.11版,很爽。 後來OS X 11升級後,再也無法使用它了,很不爽。 現在才發現原來微軟早就開發了為新版MAC使用的遠端登入。只是需要從APPSTORE裡下載,國內APPSTORE賬號還不行,所以我只好用以前在新加坡使用的賬