Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



1339 posts

Uber Geek
+1 received by user: 161


Topic # 101843 10-May-2012 08:32 Send private message

The last couple of days I noticed some weird data usage overnight. 

This morning, checked netlimiter and I'd uploaded 50mb while asleep. 

Tracked this to process 1448, which is Remote desktop. 

Found the connection was still active, and there was remote desktop uploading data to 61.186.90.102. 

You can actually RDP to that IP address and it is a windows server 2003 machine in China.

I have no idea of what this person was uploading, nor can I figure out if they were actually signed on or not.   Could failed connection attempts cause this amount of data up loading?   IS there any logging of RDP anywhere?

I have a strong windows password, but now I'm wondering if RDP has a security exploit which was used to gain access to my machine .

Anyway, I've removed the port forwarding and will run some full system malware scans just to be sure. 

Create new topic
BDFL
47924 posts

Uber Geek
+1 received by user: 3540

Administrator
Trusted
Geekzone
Subscriber

  Reply # 622650 10-May-2012 08:36 Send private message

"I have a secure password"...

Worthless if there's a vulnerability. Have you applied all Windows Updates your system lately? Do you really need remote desktop? Why not use something like LogMeIn that doesn't need port forwarding?








1339 posts

Uber Geek
+1 received by user: 161


  Reply # 622678 10-May-2012 09:09 Send private message

freitasm: "I have a secure password"...

Worthless if there's a vulnerability. Have you applied all Windows Updates your system lately? Do you really need remote desktop? Why not use something like LogMeIn that doesn't need port forwarding?




Windows 7 is 100% up to date on patches (lesson learnt, thanks msblaster, cost me $3000 in 2003).

Secure password. 

Can 50mb of data could be generated by failed RDP log-on attempts. Windows RDP event logging is poor. 

I'll look at LogMeIn.

RDP is permanently banned from my house.

Even if someone accessed my machine, all my passwords are secured by Truecrypt.  But I'll change my banking passwords just to be sure. 

Thanks.




2858 posts

Uber Geek
+1 received by user: 131

Trusted
Subscriber

  Reply # 622694 10-May-2012 09:36 Send private message

Also make sure you require secure connections only for RDP





628 posts

Ultimate Geek
+1 received by user: 178


  Reply # 622718 10-May-2012 10:00 Send private message

Are you saying the RDP traffic is inbound or outbound?



1339 posts

Uber Geek
+1 received by user: 161


  Reply # 622719 10-May-2012 10:02 Send private message

wasabi2k: Are you saying the RDP traffic is inbound or outbound?


Approx 50MB Outbound traffic, to this china IP address. 

7528 posts

Uber Geek
+1 received by user: 235

Trusted
Subscriber

  Reply # 622740 10-May-2012 10:38 Send private message

Exposing RDP directly is like painting a big target on your back.

Setup a VPN server at home and only use RDP over the VPN would be my recommendation.

2034 posts

Uber Geek
+1 received by user: 29


  Reply # 622750 10-May-2012 10:55 Send private message

Have you run a rootkit scanner?

I had a client come to us with the same issue but that was on SBS2003 and there is a fix for that but MS say Win7 isn't affected.
Telecom usage meter showed that their monthly uploads went from about 1-2GB to over 10GB and they only noticed as they started hitting their data cap and getting slowed down to dial-up.

I found that their last IT provider had the SBS2003 in the DMZ in the router so didn't help and I installed the fix.

As others have said I wouldn't have port 3389 open to the internet.
If you really must have RDP open use another port like 33389.
Then when you want to connect with RDP just make sure you use ???.???.???.???:33389.






1339 posts

Uber Geek
+1 received by user: 161


  Reply # 622775 10-May-2012 11:24 Send private message

Windows RDP is disabled...lesson learnt :)

However, from what I understand any system can be hacked regardless. You can just try to make it harder.

Have run all necessary scans, inc the kaspersky rootkit scanner.

LogMeIn is my RDP tool from now.

655 posts

Ultimate Geek
+1 received by user: 5

Subscriber

  Reply # 622800 10-May-2012 11:58 Send private message

CYaBro: Have you run a rootkit scanner?

I had a client come to us with the same issue but that was on SBS2003 and there is a fix for that but MS say Win7 isn't affected.
Telecom usage meter showed that their monthly uploads went from about 1-2GB to over 10GB and they only noticed as they started hitting their data cap and getting slowed down to dial-up.

I found that their last IT provider had the SBS2003 in the DMZ in the router so didn't help and I installed the fix.

As others have said I wouldn't have port 3389 open to the internet.
If you really must have RDP open use another port like 33389.
Then when you want to connect with RDP just make sure you use ???.???.???.???:33389.

No you don't need 3389 open on SBS. Windows Web Workplace over https takes care of handling the RDP traffic without having to port forward 3389.

628 posts

Ultimate Geek
+1 received by user: 178


  Reply # 622818 10-May-2012 12:21 Send private message

If it is outbound your PC is initiating the traffic - you don't have RDP open inbound?

Then what is initiating RDP connections outbound to that IP? That's the question. Rootkit/malware/etc.

628 posts

Ultimate Geek
+1 received by user: 178


  Reply # 622819 10-May-2012 12:22 Send private message

allan:
CYaBro: Have you run a rootkit scanner?

I had a client come to us with the same issue but that was on SBS2003 and there is a fix for that but MS say Win7 isn't affected.
Telecom usage meter showed that their monthly uploads went from about 1-2GB to over 10GB and they only noticed as they started hitting their data cap and getting slowed down to dial-up.

I found that their last IT provider had the SBS2003 in the DMZ in the router so didn't help and I installed the fix.

As others have said I wouldn't have port 3389 open to the internet.
If you really must have RDP open use another port like 33389.
Then when you want to connect with RDP just make sure you use ???.???.???.???:33389.

No you don't need 3389 open on SBS. Windows Web Workplace over https takes care of handling the RDP traffic without having to port forward 3389.


Yeah - which requires forwarding another port instead - the RDP isn't tunnelled over 443 with SBS2003.

189 posts

Master Geek
+1 received by user: 1

Trusted

  Reply # 622883 10-May-2012 14:23 Send private message

surfisup1000:... Is there any logging of RDP anywhere? ...


(Terminology: note the client end is referred to as "Remote Desktop Connection"; the server end is referred to as "Remote Desktop").

Turn logging on for Remote Desktop and set account lockout policies for repeated (may be a bit late for this!) logon attempts (Windows 7): How-to Remote Desktop Security Windows 7

Can turn general IP logging on in Windows Firewall > Advanced | Security Logging | Settings

Check System Event Log for events with Source "TermService".

Create new topic








Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Forms of government for New Zealand
Created by charsleysa, last reply by Kyanar on 18-Apr-2014 20:55 (98 replies)
Pages... 5 6 7


MH370 - Call for Search & Rescue Help
Created by DS248, last reply by Sideface on 17-Apr-2014 17:28 (735 replies)
Pages... 47 48 49


galaxy s4 now on 4.4.2
Created by nzrock, last reply by Cameron1991 on 19-Apr-2014 01:35 (51 replies)
Pages... 2 3 4


why does the tax payer have to pay for the prince and princess' 6 star holiday?
Created by joker97, last reply by Geektastic on 17-Apr-2014 15:49 (67 replies)
Pages... 3 4 5


Snap suffering Trans-Tasman congestion 18/04?
Created by Lias, last reply by NonprayingMantis on 19-Apr-2014 00:05 (26 replies)
Pages... 2


Help ! Home business connection and VDSL dead. yikes.
Created by Scotsman, last reply by Scotsman on 17-Apr-2014 21:10 (26 replies)
Pages... 2


Free connection to Ultra Fibre not true
Created by kapitikarl, last reply by cbrpilot on 15-Apr-2014 13:24 (27 replies)
Pages... 2


TVNZ on Demand Jailbreak Detection
Created by TranceManNZ, last reply by hio77 on 18-Apr-2014 20:25 (12 replies)


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.