<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Unfettered access to port 3389</title><link>http://msmvps.com/blogs/bradley/archive/2008/06/23/unfettered-access-to-port-3389.aspx</link><description>I&amp;#39;m reading this post and it&amp;#39;s talking about how to run the wizard for VPN but at the end, is it just me or does it suddenly change over to using straight RDP to the server? Configure Windows Small Business Server 2003 R2 Remote Access | Tech</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Unfettered access to port 3389</title><link>http://msmvps.com/blogs/bradley/archive/2008/06/23/unfettered-access-to-port-3389.aspx#1637207</link><pubDate>Tue, 24 Jun 2008 11:11:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637207</guid><dc:creator>petieg</dc:creator><description>&lt;p&gt;did you ever try the free SecureRDP? Simple, easy lockdown of rdp by ip address, computer name, etc. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637207" width="1" height="1"&gt;</description></item><item><title>re: Unfettered access to port 3389</title><link>http://msmvps.com/blogs/bradley/archive/2008/06/23/unfettered-access-to-port-3389.aspx#1637206</link><pubDate>Tue, 24 Jun 2008 10:44:40 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1637206</guid><dc:creator>the_angry_angel</dc:creator><description>&lt;p&gt;In some instances it maybe politically troublesome to lock down RDP. In these instances, where you have no choice there are additional steps you can take to help, aside from altering the port number.&lt;/p&gt;
&lt;p&gt;In the given example tsgrinder script you will notice that the username argument doesn&amp;#39;t appear to be used, which means it&amp;#39;s grinding against the username &amp;#39;administrator&amp;#39;. Many brute attacks rely on this account, so renaming the administrator account to something else helps immeasurably. &lt;/p&gt;
&lt;p&gt;Secondly setup your server/domain to log failed logons and setup some monitoring. If you get it setup right you can take automated action to close 3389 to the attacking IP(s), or you can simply inform the admin via email who can take manual action to prevent the attack. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1637206" width="1" height="1"&gt;</description></item></channel></rss>