Solved

Preventing brute force attacks

Posted on 2013-06-30
4
275 Views
Last Modified: 2014-10-07
Hi all, I'm interested in software to prevent brute force attacks to RDP etc, I have found software called RDPguard but have never seen it mentioned before, anyone know if it's legit or another fake?

Also are there any other solutions to brute force attacks? I have changed the RDP port but still the event log fills with audit failures.

Thanks all
0
Comment
Question by:Leigh2004
4 Comments
 
LVL 16

Assisted Solution

by:Shaik M. Sajid
Shaik M. Sajid earned 167 total points
ID: 39287972
you can deploy certificate server SSL

to make it secure...

http://technet.microsoft.com/en-us/magazine/ff458357.aspx

as well

http://www.petri.co.il/securing_rdp_communications.htm

all the best
0
 

Author Comment

by:Leigh2004
ID: 39288087
Thanks shaiksaj, but I am more interested in the ip blocking method as RDPguard claims to be able to do, as that would also protect ftp, mssql etc

I have just found another called E-Guardo but that looks very dubious to me, also one called Syspeace with an outrageous pricing plan, any opinions on any of these ?
0
 
LVL 38

Assisted Solution

by:Rich Rumble
Rich Rumble earned 166 total points
ID: 39288496
The OS can do this for you, it's built-in... use Secpol.msc, got to account policies. Adjust the lockout and duration thresholds if need be. You can also try these settings: http://technet.microsoft.com/en-us/library/cc783225%28v=ws.10%29.aspx
You can use secpol.msc to limit what users and groups can RDP, remove administrator, and only allow those in the RemoteDesktop group. Change the Administrator account name as a best practice.
http://www.umanitoba.ca/about/media/IST_Securing_Remote_Desktop_on_XPpro.pdf
-rich
0
 
LVL 26

Accepted Solution

by:
skullnobrains earned 167 total points
ID: 39306484
you will ALWAYS have failed connections filling up your logs whenever any service is open to the internet whatever the port.

using secure passwords is a good start

monitoring successfull connection attempts is useful

monitoring failed attempts and locking out the ips is mildly useful because attacks can be run from plenty of ips at the same time

limiting the number of failed attemps per user is very efficient if combined with forced password changes but might efficiently make you unable to connect to your system because of an attack. but combined with the previous and possibly ip whitelisting policies uppon successfull attemps, this can produce excellent security.

opening the RDP port only to users who successfully connected to a different service can also be a good way to prevent most such attacks.

---

bottomline is it is not a matter of software but rather of policy. it is also very likely that you can reasonably ignore these events altogether. maybe tell us more about your situation (number of users, attck frequency, existing firewall...) so we can get a better idea.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Pop culture is prime bait for hackers seeking to infect user’s computers and mobile devices with malicious malware. Hackers know exactly what the latest trends are online and know how to use them to their advantage.
As a business owner, there are many things that keep you up at night. Profit margins, employee retention, human resource protocols, whether your product or service will remain competitive. When you own or manage a technology company that operates la…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question