You are enumerating a target and find a service on port 3389. What is the most effective way to identify if this service is open to remote login attacks during the reconnaissance phase?
Trap 1: Attempt a brute-force login with a large password list.
Brute-forcing RDP is extremely noisy and likely to be detected by account lockout policies. This is a poor reconnaissance step and should only be performed after careful consideration of the risks, as it does not provide information about the service version or configuration, which are the real objectives.
Trap 2: Connect using the telnet command.
Telnet is not compatible with the RDP protocol. Attempting to connect to port 3389 using Telnet will fail to establish a session and provides no meaningful information about the service. This is a waste of time and does not contribute to the enumeration of the target host's services.
Trap 3: Send an HTTP GET request to the port.
Port 3389 is for RDP, not HTTP. Sending an HTTP request to this port will not result in a valid response or provide information about the RDP service configuration. This is an incorrect application of protocols and demonstrates a lack of understanding regarding the port's function.
- A
Attempt a brute-force login with a large password list.
Why it fails: Brute-forcing RDP is extremely noisy and likely to be detected by account lockout policies. This is a poor reconnaissance step and should only be performed after careful consideration of the risks, as it does not provide information about the service version or configuration, which are the real objectives.
- B
Perform version fingerprinting using Nmap.
Nmap's version detection capabilities can identify the specific version and configuration of the RDP service. Knowing this allows the tester to check against publicly available CVEs, like BlueKeep, which are critical for determining the target's patch level and potential susceptibility to remote execution attacks without needing to perform risky logins.
- C
Connect using the telnet command.
Why it fails: Telnet is not compatible with the RDP protocol. Attempting to connect to port 3389 using Telnet will fail to establish a session and provides no meaningful information about the service. This is a waste of time and does not contribute to the enumeration of the target host's services.
- D
Send an HTTP GET request to the port.
Why it fails: Port 3389 is for RDP, not HTTP. Sending an HTTP request to this port will not result in a valid response or provide information about the RDP service configuration. This is an incorrect application of protocols and demonstrates a lack of understanding regarding the port's function.