Showing posts with label TSGrinder. Show all posts
Showing posts with label TSGrinder. Show all posts

Friday, 30 April 2010

What a TSGrinder Grind Against an SBS Looks Like

On some of our older SBS 2003 installs where we have no out-of-band remote management setup in place, we open up port 3389 on the router to the server to run our updates.

Once we are finished, we normally close the port back up. Now, this particular evening we had run a series of updates across more than half of the servers that we manage one Saturday.

It seems that one of the firewall ports did not get closed and someone took an interest in that particular server:

image

  • Logon attempts: 3,282
  • IP: 64.46.44.76

Now, the IP may not be relevant since the machine behind it may be a zombie.

Things were relatively quite until a few days later:

image

  • Logon attempts: 5
  • IP: 113.53.231.2

Then this one kept at it for a number of days:

image

  • Logon attempts: 1,906
  • IP: 84.53.64.91

The above IP kept after the server until this day:

image

  • Logon attempts: 2,414
  • IP: 84.53.64.91

And another shot of a report that was taken manually in the SBS Console not long after the above:

image

  • Logon attempts: 4,545
  • IP: 84.53.64.91

Note the different numbers between the automatically generated report and the one manually created by us. The disparity may be due to the fact that the TS service was being hammered so frequently.

While the grind was happening we could not log on to the server via a direct TS connection. We were almost instantly bumped out as soon as we saw the logon screen.

Fortunately, we could log onto RWW and TS via the RWW RDP connection that uses a proxy port of 4125. If that had failed, then we would have connected to a workstation and ran:

  • mstsc /v:servername /admin

From there we would have had console access and could do what needed to be done which was to close the 3389 publishing rule in ISA.

TS Client help screenshot:

image

As a rule, we do not allow port 3389 to be opened to the Internet by default.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Saturday, 14 March 2009

AuthAnvil – Want to See a Neat Security Demo Video?

With the advent of the TS Gateway service on SBS 2008, the only thing protecting our production SBS 2008 networks is a password.

Even  with a passphrase in place, there are some pretty sophisticated password dictionaries out there.

We will be looking to providing another layer of protection to our SBS 2008 networks.

That protection will be provided by Dana Epp’s (Security MVP blog link) AuthAnvil security product.

Check out the video that demonstrates AuthAnvil in action:

09-03-14 AuthAnvil

Scorpion Software: AuthAnvil Demonstration Video

Something to keep in mind is that TSGrinder (Live Search) has been reworked to now be able to attack the new TS setup on Windows Server 2008.

The video link: Scorpion Software: AuthAnvil Demonstration Video

Scorpion Software also offers a partner program: Scorpion Software Partner Program.

Much like Vlad’s OwnWebNow, Scropion Software is another reputable product vendor that delivers on a great business relationship and a great product set that is well supported.

Do check out Dana’s blog. It is a good read!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Wednesday, 8 October 2008

The one and ONLY reason to never have TS port 3389 open!

Ever hear of this: TSGrinder? If not, look into it because it could spell the end of the world as you know it if you have 3389 exposed ... or even RDP via an alternate port.

A TSGrinder like tool put the kybosh on a huge project we were working on years back due to the risk factor and the number of sniffs and subsequent attempts against the TS box.

If Terminal Services is needed, then the Remote Web Workplace is the cat's meow. A direct link in RWW to the "Application Server" means users will pick up quickly where they need to click.

SSL security, with the ability to provide another tier of security in AuthAnvil tokens means that Terminal Services will be that much more secure.

And, with the advent of SBS 2008 and TSApps, the RWW integration scenarios just keep growing!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.

Tuesday, 12 June 2007

SBS 2K3 - RWW & Terminal Server Publishing

Once a Terminal Server is installed and configured on the SBS network, external access to the TS desktop is served via Remote Web Workplace:

Once the user clicks on "Connect to my company's application-sharing server" the user will be redirected to the TS desktop's logon screen via a TSWeb session.

Proxy for the session is handled in the same way as a Remote Desktop session to Windows XP Pro or Vista Business via port 4125.

A few years back with the advent of TSHammer TSGrinder, one should never expose a Terminal Server listener to the Internet. It does not matter what port either, whether 3389, or somewhere in the 10K+ range. TSHammer TSGrinder was adept at snooping TS listeners and subsequently hitting them with dictionary attacks.

With the advent of RDP version 6 and the restructuring of TS authentication, we may see a change in our ability to expose Terminal Services to the Internet.

These changes might explain why TSHammer TSGrinder is harder to find in Internet searches.

UPDATE 2008-10-07: TSHammer could not be found because the old gray matter had clouded over the name! It is TSGrinder.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists