How long does an attack on RDP-enabled computers take? In some cases, a few minutes. In most, less than 24 hours.
The problem with RDP (Remote Desktop Protocol)
“In recent years, criminals developing targeted ransomware such as BitPaymer, Ryuk, Matrix and SamSam have almost completely abandoned other hacking methods in favor of using RDP,” say Sophos researchers Matt Boddy, Ben Jones and Mark Stockley.

Hackers have the option of cracking passwords using tools like NLBrute or purchasing cracked passwords from others or accounts on compromised RDP servers.
To get an idea of how many attacks RDP servers face every day, 10 geographically dispersed Amazon EC2 instances running Windows Server 2019 have been created, with RDP enabled and secured with a “prohibitively strong password.”
One of them was subjected to an RDP brute-forcing attack for one minute and 24 seconds. In total, 4,298,513 failed login attempts were recorded during the month.

Some attackers attempted to attack administrator accounts while others settled for low-privilege accounts, hoping that passwords would be easier to reveal. In an effort to keep their activities low-profile, they slowly escalated their attacks, scaling down or amplifying them as the situation warranted.
Another interesting thing this research showed: attackers don't rely on Shodan – the search engine that lists devices connected to the Internet – to identify potential targets.
Μείωση του DP password brute-forcing κινδύνου
RDP-based Remote Desktop services are a useful technology that allows business administrators to access and interact with computers on remote networks or in the cloud.
Two months ago, Microsoft warned about CVE-2019-0708 (also known as BlueKeep), a wormable unauthorized remote code execution flaw in RDS, which was expected to be widely exploited.

Although cyber experts believe that state-sponsored hacking groups are already using BlueKeep for quiet intrusions, we have yet to see a mass exploitation.
However, poorly secured RDP servers represent an easy target for hungry cybercriminals, who often use them to spread malware (usually ransomware) throughout the target network.

Although the solution to RDP password brute-forcing is as easy as choosing a strong and long password, researchers are skeptical about this fact.
- Microsoft could make two-factor authentication mandatory or switch to another form of authentication (e.g., public key authentication).
- Cloud computing providers could offer servers with an alternative form of remote management or authentication.
- But until that happens, administrators can mitigate the risk by enabling multi-factor authentication.
- Finally, if RDP is not necessary, it should be disabled. When required, you should only access it via a virtual private network (VPN).
