meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, April 8th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 April 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. RDP Scanning Increase; Exposed Atlassian Tools; Android Pixel 4 Awake Detection

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, April 8, 2020 edition of the Santernut Storms anders Stormcast.

0:07.4

My name is Johannes Ulrich.

0:09.1

And then I'm recording from Jacksonville, Florida.

0:12.9

I looked a little bit closer at RDP scanning traffic last week and summarized some of what I found in a post today.

0:23.7

And what is this really about is that Shodan reported an increase in exposed RDP servers.

0:30.6

Now, they had to reduce the number a bit, turn actually out, interestingly, and that may be

0:35.9

worth another sort of post that the increase

0:39.0

was more due to IPV6 than IPV4. So after they compared apples to apples and stuck with IPV4,

0:48.2

they still saw an increase was just not as pronounced as before of exposed RDP servers.

0:57.0

And, well, I talked about this a little bit last week when Shodan first reported it. It's probably due to administrators now having to work

1:03.5

from home, needing to quickly expose systems so they can be remote administered. So what I took a look at is to see whether or not the bad guys are sort of following that trend.

1:17.6

And this was a little bit difficult actually, well, in part because RDP port 3389 is one of the top port sort of consistently, so it's somewhat saturated already.

1:32.2

But what I saw was that attackers are actually dedicating more resources to scanning for

1:40.2

RDP. Typically, we have about 2,600 source IPs scanning for port 3389 each day.

1:49.1

Well, in March, that number went up to 3,540, so that's quite a significant increase.

1:56.6

About sort of 20, 30%, percent here that we have an increase.

2:01.8

So what this really means is do not expose RDP servers.

2:06.1

Attackers are actively looking for them.

2:08.0

They will find these RDP servers.

2:10.3

The number one attack that typically you'll see against an exposed RTP server is password brute forcing.

2:18.9

So if you have to expose an RDP server, then make absolutely sure that you use unique,

2:25.5

hard-to-guess passwords, even better two-factor authentication, but you need RTP gateway for that

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.