1 00:00:00,057 --> 00:00:05,797 Windows ships with a giant backdoor, and Microsoft turns it on by default. 2 00:00:06,387 --> 00:00:12,117 I'm talking about RDP, which I say stands for the Ransomware Deployment Protocol. 3 00:00:12,687 --> 00:00:16,777 This week, Dr. Mike Saylor and Prasanna join me to talk about RDP 4 00:00:16,787 --> 00:00:18,767 and its security best practices. 5 00:00:19,237 --> 00:00:23,007 Why does port 3389 keep showing up in breach reports? 6 00:00:23,447 --> 00:00:26,467 Why do initial access brokers love RDP? 7 00:00:26,997 --> 00:00:31,127 We talk about blocking the port and the service, network-level authentication, 8 00:00:31,327 --> 00:00:36,047 bastion hosts, and the one rule that I'll go to the mattresses for, RDP 9 00:00:36,177 --> 00:00:38,277 does not belong on the internet. 10 00:00:39,247 --> 00:00:41,457 If this is your first time watching or listening to me, 11 00:00:41,457 --> 00:00:43,847 I'm W. Curtis Preston, AKA Mr. 12 00:00:43,847 --> 00:00:44,317 Backup. 13 00:00:44,807 --> 00:00:50,217 I've been obsessing over backup recovery and now cyber recovery for over 30 years. 14 00:00:50,547 --> 00:00:52,567 If that's your bag, I'm your guy. 15 00:00:52,947 --> 00:00:55,817 You're not gonna find anybody that cares about this topic more than me. 16 00:00:56,327 --> 00:01:00,417 Ever since 1993 when I had to tell my boss that there were no backups 17 00:01:00,707 --> 00:01:02,317 of the database that we just lost. 18 00:01:02,827 --> 00:01:06,177 Now I've written five O'Reilly books, a blog, and now a podcast. 19 00:01:06,497 --> 00:01:10,467 Here we turn unappreciated admins into cyber recovery heroes. 20 00:01:10,617 --> 00:01:12,677 This is the Backup Wrap-Up 21 00:01:26,945 --> 00:01:28,735 hi, and welcome to the Backup Wrap Up. 22 00:01:28,735 --> 00:01:32,285 I'm your host, W. Curtis Preston, AKA Mr. Backup, and once again, I 23 00:01:32,295 --> 00:01:35,635 have a guy with me that followed me vicariously this weekend as I 24 00:01:35,645 --> 00:01:42,225 visited roughly a dozen random strange people's houses, Prasanna Malaiyandi. 25 00:01:42,225 --> 00:01:43,265 How's it going, Prasanna? 26 00:01:43,660 --> 00:01:50,050 I'm good, Curtis, and I'm glad that you were not kidnapped or missing a kidney 27 00:01:50,060 --> 00:01:54,640 or anything else like that because I know that you had to go around and pick up 28 00:01:54,640 --> 00:01:59,310 things from people you found on Facebook Marketplace, but those things worry me, 29 00:01:59,360 --> 00:02:02,790 I will say there was at least one house where we're like, "Okay, I'm 30 00:02:02,790 --> 00:02:06,210 not entering this fen-," if I was in Texas, it would be zero houses, right? 31 00:02:06,260 --> 00:02:10,130 but I'm like, "I'm not cracking this fence, but I'm not going into the 32 00:02:10,130 --> 00:02:12,110 yard to knock on a door," right? 33 00:02:12,140 --> 00:02:15,420 I'm like, I'm calling, I'm texting, I'm, But then there was one guy that 34 00:02:15,470 --> 00:02:19,880 came out in his, he was barefoot in his pajamas, and I'm like, "My God." have 35 00:02:19,880 --> 00:02:24,710 some decency, sir," plus his crib was d- But Mike, we, for the, daycare that 36 00:02:24,710 --> 00:02:32,970 I work with, I was, purchasing, 10, infant cribs, two rocking chairs, and 37 00:02:34,560 --> 00:02:34,990 table 38 00:02:35,080 --> 00:02:35,400 Yeah. 39 00:02:35,880 --> 00:02:36,880 that was my weekend. 40 00:02:37,450 --> 00:02:42,200 anyway, speaking of Mike, here we have my co-author of the lovely book right 41 00:02:42,200 --> 00:02:45,250 over my, left shoulder, Dr. Mike Saylor. 42 00:02:45,250 --> 00:02:45,990 How's it going, Mike? 43 00:02:47,551 --> 00:02:47,981 Oh, thank you. 44 00:02:48,021 --> 00:02:50,821 I didn't have any excitement over the weekend, but, hopefully this 45 00:02:50,821 --> 00:02:54,701 coming weekend I'll get to do something that spikes my adrenaline. 46 00:02:54,701 --> 00:02:55,011 Who knows? 47 00:02:55,318 --> 00:02:55,768 Yeah. 48 00:02:55,818 --> 00:02:58,678 just try walking up to 12 random strangers' houses. 49 00:02:58,708 --> 00:03:01,288 That is guaranteed, especially in Texas, to 50 00:03:01,923 --> 00:03:02,993 That's, that's old hat for me. 51 00:03:02,993 --> 00:03:04,223 I d- I used to do that all the time. 52 00:03:04,522 --> 00:03:05,462 Oh, no thank you. 53 00:03:05,492 --> 00:03:06,122 No thank you 54 00:03:06,493 --> 00:03:09,493 I'm gonna, I think I'm gonna, I'm gonna get in the middle of, a fight 55 00:03:09,493 --> 00:03:12,183 between, Black Vulture and my rooster. 56 00:03:12,213 --> 00:03:14,343 See if that'll, that maybe that'll get me charged 57 00:03:14,343 --> 00:03:14,563 up 58 00:03:15,018 --> 00:03:17,978 that I, is a story I wanna hear, but not today. 59 00:03:18,438 --> 00:03:24,558 today we are, we ha- we have been hinting at this episode many weeks. 60 00:03:24,798 --> 00:03:27,428 This is w- a favorite topic that I bring up. 61 00:03:27,428 --> 00:03:28,978 I allude to it quite a bit. 62 00:03:29,398 --> 00:03:36,338 It is my favorite protocol, of all because it is used to deploy ransomware, which is 63 00:03:36,338 --> 00:03:41,288 why it is called the ransomware deployment protocol, otherwise known as RDP. 64 00:03:42,518 --> 00:03:43,138 so 65 00:03:43,646 --> 00:03:46,596 I know you love this topic, so what I'm gonna do is I'm just 66 00:03:46,596 --> 00:03:48,116 gonna mute myself right now. 67 00:03:48,536 --> 00:03:53,576 And for all of the listeners out there, this is just gonna be the Curtis time. 68 00:03:53,646 --> 00:03:57,326 Mike, maybe you might get a word or two in here or there, but, I'm 69 00:03:57,326 --> 00:03:58,466 just gonna mute myself at this point 70 00:03:58,748 --> 00:03:59,448 You're killing me. 71 00:03:59,598 --> 00:04:02,018 This- it's just it's like, don't do this, right? 72 00:04:02,048 --> 00:04:03,848 But so many people do this, right? 73 00:04:04,028 --> 00:04:09,278 it's just there, there's so many initial breaches that are done via RDP, especially 74 00:04:09,278 --> 00:04:11,578 RDP that is accessible via the internet. 75 00:04:11,818 --> 00:04:14,388 I, I joke that it's like, that it's like having a, a kick 76 00:04:14,388 --> 00:04:16,278 me sign on your back, right? 77 00:04:16,318 --> 00:04:18,438 except it's a hack me, it's a hack me 78 00:04:18,620 --> 00:04:23,230 So, before you keep going on, maybe for some people who hopefully everyone's 79 00:04:23,230 --> 00:04:29,150 familiar with RDP, but maybe you should spend 30 seconds talking about what is R- 80 00:04:29,254 --> 00:04:30,044 my intro. 81 00:04:30,210 --> 00:04:31,310 I know, b- 82 00:04:31,364 --> 00:04:31,644 My 83 00:04:31,710 --> 00:04:34,620 you were getting like so intense and you're just about 84 00:04:34,620 --> 00:04:35,850 to go like jumping right in 85 00:04:37,971 --> 00:04:38,831 Like an old married couple 86 00:04:39,372 --> 00:04:41,642 I tell you, yeah, this is why. 87 00:04:41,702 --> 00:04:43,042 I don't know, I don't know why I put up 88 00:04:43,084 --> 00:04:44,194 This is why you keep me around 89 00:04:45,082 --> 00:04:45,942 Yeah, okay. 90 00:04:46,452 --> 00:04:53,382 So the actual name of this product is the Remote Desktop Protocol. 91 00:04:53,862 --> 00:04:56,652 And for those of you that don't know, this is the way that you can 92 00:04:56,692 --> 00:05:01,922 administer, especially, specifically a, a Windows-based… And by that, 93 00:05:01,952 --> 00:05:05,772 I actually don't mean the Windows with a capital W. like a, either a… 94 00:05:05,992 --> 00:05:08,342 what's the… What's… Is it Motif? 95 00:05:08,362 --> 00:05:10,532 Is that the, the Unix version? 96 00:05:10,932 --> 00:05:11,852 Isn't that what it's called? 97 00:05:13,412 --> 00:05:15,512 It's been a while since I've used that term. 98 00:05:15,672 --> 00:05:19,542 But basically a windowing type platform, which very commonly 99 00:05:19,542 --> 00:05:21,422 is, of course, Windows, right? 100 00:05:21,732 --> 00:05:27,672 if it is on, if it is enabled, you can basically run that other system as if 101 00:05:27,672 --> 00:05:29,762 you were sitting there with your mouse. 102 00:05:30,092 --> 00:05:33,112 And, which means that also, so can a hacker. 103 00:05:33,492 --> 00:05:36,712 And over the years, there have been all kinds of vulnerabilities 104 00:05:36,992 --> 00:05:41,542 that have resulted in all kinds of, hacks and, and therefore incidents 105 00:05:41,562 --> 00:05:44,682 and therefore ransoms, et cetera. 106 00:05:44,782 --> 00:05:49,432 And, Mike, do you also have a similar relationship with RDP? 107 00:05:51,871 --> 00:05:53,641 It depends on which, which hat I'm wearing. 108 00:05:54,361 --> 00:05:54,711 so if I'm 109 00:05:54,726 --> 00:05:54,976 Okay 110 00:05:55,121 --> 00:05:57,591 the blue hat, I hate RDP. 111 00:05:57,641 --> 00:05:59,621 If I'm wearing the red hat, love RDP 112 00:06:00,528 --> 00:06:00,958 yeah. 113 00:06:01,038 --> 00:06:01,828 That makes sense. 114 00:06:01,988 --> 00:06:02,588 That makes sense. 115 00:06:02,608 --> 00:06:02,928 Yeah. 116 00:06:03,288 --> 00:06:05,038 I can, I can ma- it makes sense a lot. 117 00:06:05,966 --> 00:06:06,706 But, is 118 00:06:06,918 --> 00:06:10,078 You're al- you're always, you always have a big but, Prasanna. 119 00:06:10,268 --> 00:06:10,448 Go 120 00:06:10,632 --> 00:06:11,192 No, okay. 121 00:06:11,552 --> 00:06:21,352 But, is RDP getting a lot of flack though because ad- administrators, users are 122 00:06:21,702 --> 00:06:27,162 misconfiguring it or not securing it in the proper way, or just taking, the easy 123 00:06:27,162 --> 00:06:31,082 route, and therefore it gets a bad name? 124 00:06:31,082 --> 00:06:37,612 Or does it truly deserve the, nickname ransomware deployment protocol? 125 00:06:38,196 --> 00:06:40,516 I think it's, I think it's a little bit of both, right? 126 00:06:40,566 --> 00:06:45,826 I think it, it got the name because it was so often used as, d- to deploy ransomware. 127 00:06:46,106 --> 00:06:50,226 But, it is, I would say it's a combination, and Mike, I, I am 128 00:06:50,226 --> 00:06:51,646 curious of your opinion here. 129 00:06:52,016 --> 00:06:57,386 it's both like just a protocol and the software underneath it that 130 00:06:57,506 --> 00:06:59,806 runs that protocol have had so many 131 00:07:01,946 --> 00:07:08,686 and therefore, breaches it, it's just a really dangerous protocol. 132 00:07:09,366 --> 00:07:12,926 And then, and people don't know, I don't think they realize 133 00:07:12,926 --> 00:07:14,156 just how dangerous this is. 134 00:07:14,196 --> 00:07:15,746 They leave it unprotected. 135 00:07:15,746 --> 00:07:20,076 They leave it connected to the internet, as a result, they get, they get hacked. 136 00:07:20,156 --> 00:07:23,436 what, w- would you agree with any of that, Mike? 137 00:07:23,729 --> 00:07:26,039 something you… I agree with a lot of that. 138 00:07:26,119 --> 00:07:28,179 and it, RDP has its purpose. 139 00:07:28,179 --> 00:07:28,939 It's a tool. 140 00:07:29,809 --> 00:07:33,249 it's a dollar store hammer instead of, the Home Depot, you know, 141 00:07:33,269 --> 00:07:35,299 professional roofing hammer, right? 142 00:07:35,749 --> 00:07:40,159 so it's still a tool, and you use what you have to use when, sometimes you 143 00:07:40,159 --> 00:07:42,499 don't have budget for more robust tool. 144 00:07:43,189 --> 00:07:46,959 But to your point about, it's not protected, it's connected to the internet, 145 00:07:47,359 --> 00:07:51,539 no one's monitoring when it's being used, all those other things that are 146 00:07:51,539 --> 00:07:56,999 also free and come with your Microsoft environment could help protect the use 147 00:07:57,009 --> 00:08:00,119 of RDP and just traditionally it's not. 148 00:08:00,689 --> 00:08:03,129 And so we're just leaving that dollar store hammer out there on 149 00:08:03,129 --> 00:08:04,769 the table for anybody to pick up. 150 00:08:05,749 --> 00:08:06,379 yeah, there, there's 151 00:08:06,399 --> 00:08:08,169 ways of making it better, 152 00:08:08,236 --> 00:08:08,406 and 153 00:08:08,629 --> 00:08:09,939 traditionally it doesn't 154 00:08:10,176 --> 00:08:11,686 isn't it on by default, Mike? 155 00:08:15,303 --> 00:08:16,203 The serv- yes, 156 00:08:16,278 --> 00:08:16,648 Yeah. 157 00:08:16,808 --> 00:08:17,108 This, 158 00:08:17,233 --> 00:08:17,493 it is. 159 00:08:17,528 --> 00:08:17,828 yeah, 160 00:08:18,023 --> 00:08:19,063 even on the work, even on the 161 00:08:19,063 --> 00:08:19,693 endpoints it's 162 00:08:19,846 --> 00:08:20,796 Just on by default 163 00:08:21,558 --> 00:08:22,108 and but 164 00:08:22,163 --> 00:08:25,903 the endpoint you can't turn, you can't turn all the RDP services off. 165 00:08:26,133 --> 00:08:29,373 You can only turn the, the primary, RDP call service off 166 00:08:30,210 --> 00:08:32,650 But, and everything you said, Mike, makes a lot of sense. 167 00:08:32,650 --> 00:08:36,870 A, there are certain things you can't do, and by the way comes by default, 168 00:08:36,880 --> 00:08:41,320 it's very insecure or could be very insecure if you aren't securing your 169 00:08:41,320 --> 00:08:43,550 firewall to prevent access, right? 170 00:08:43,550 --> 00:08:45,310 This could be externally facing. 171 00:08:46,080 --> 00:08:49,640 But it's, in my mind, that's like similar to being like, I have an 172 00:08:49,640 --> 00:08:54,980 amazing home alarm system, and I'm gonna leave the front door unlocked, right? 173 00:08:55,020 --> 00:08:59,180 Or, like there's certain things that are a little bit like user error, if you will, 174 00:08:59,190 --> 00:09:05,210 or users not using it in the way it was intended to be used or not understanding. 175 00:09:05,920 --> 00:09:10,310 And so I wonder if it's like, yes, there is this tool, yes, they could 176 00:09:10,310 --> 00:09:14,460 have done a better job of securing it or setting the right defaults, 177 00:09:15,570 --> 00:09:17,160 but maybe it's just getting a bad… 178 00:09:17,190 --> 00:09:20,180 And I sound like I'm pro-RDP. 179 00:09:20,190 --> 00:09:24,140 I am not pro-RDP, but I'm just taking the fl- I'm just taking the flip side 180 00:09:24,140 --> 00:09:27,830 and just trying to say, because I think it's useful in some environments, right? 181 00:09:27,900 --> 00:09:29,840 If you can secure it internally, right? 182 00:09:30,204 --> 00:09:33,884 Well, that, that's basically, that's what… It's not that RDP is evil, 183 00:09:34,134 --> 00:09:38,624 it's that it just ha- it, it can really be used for evil, right? 184 00:09:38,884 --> 00:09:42,904 but to take your analogy and maybe just tweak it a little bit, it's as if 185 00:09:42,944 --> 00:09:48,484 every new house comes with a back door that's wide open, and nobody thinks 186 00:09:48,484 --> 00:09:52,134 to maybe lock the back door, right? 187 00:09:52,384 --> 00:09:55,664 like every single builder puts in this door, and then 188 00:09:55,664 --> 00:09:58,154 advertises the door is open. 189 00:09:58,434 --> 00:10:03,854 It's got a big flashing, "I'm not locked," thing above it, and then nobody's like, 190 00:10:03,944 --> 00:10:07,854 "Hey, maybe we should do something." Did you wanna say something, Mike? 191 00:10:07,979 --> 00:10:12,149 It, it's a known protocol, so to your point, if that protocol was available 192 00:10:12,179 --> 00:10:16,799 at, in your house, bad guys just query the whole neighborhood, and 193 00:10:16,819 --> 00:10:20,419 I'll… Very quickly I can find out who's got RDP exposed to the internet. 194 00:10:21,069 --> 00:10:27,349 but Prasanna, made a comment about it, being a, a bad tool. 195 00:10:27,349 --> 00:10:28,569 It's not a bad tool. 196 00:10:29,679 --> 00:10:32,549 and there's a lot of tools out there that are used for evil. 197 00:10:32,879 --> 00:10:38,239 In fact, most tools that guys use to help do their job better are now used for evil. 198 00:10:38,719 --> 00:10:44,619 all the CIS internal tools are, have been cannibalized and turned to the dark side. 199 00:10:47,089 --> 00:10:51,019 it's all about risk mitigation and understanding what the risks are. 200 00:10:51,389 --> 00:10:54,089 So if you're using RDP in your environment, great. 201 00:10:54,149 --> 00:10:57,039 Have you thought about how to protect your environment from the 202 00:10:57,039 --> 00:11:01,329 RDP tool that you think you have to use in- instead of some other tool? 203 00:11:01,959 --> 00:11:04,839 And then cleaning up after yourself, too. 204 00:11:04,849 --> 00:11:08,549 to Curtis's point, it comes dis- installed or turned on by default. 205 00:11:08,579 --> 00:11:11,409 what if your default approach was not to use RDP? 206 00:11:11,419 --> 00:11:16,279 You're using some other remote management tool, but you forgot to turn RDP off. 207 00:11:17,099 --> 00:11:19,789 So there's just, there's just diligence, common sense, and the 208 00:11:19,789 --> 00:11:23,089 analysis of your environment, the risks, and all those things. 209 00:11:23,099 --> 00:11:27,319 So it's no different than taking something out of the box and plugging 210 00:11:27,319 --> 00:11:32,109 it in and thinking everything's fine, knowing that out of the box it's not 211 00:11:32,109 --> 00:11:35,819 fine and doing other things without consideration for reading the manual 212 00:11:36,209 --> 00:11:37,759 and knowing what you've turned on 213 00:11:38,148 --> 00:11:39,998 This manual thing of which you speak 214 00:11:41,270 --> 00:11:42,380 Do, you know, Mike? 215 00:11:42,409 --> 00:11:43,679 about this documentation 216 00:11:44,410 --> 00:11:48,720 Mike, so I totally get for an on-premises environment where you're deploying 217 00:11:48,720 --> 00:11:51,800 Microsoft servers and other things like that, it's on you to secure it. 218 00:11:52,290 --> 00:11:59,440 Do you know if cloud providers, when you are deploying Microsoft Windows 219 00:11:59,480 --> 00:12:05,470 in, say, Amazon AWS EC2 Compute, do they do a better job of helping 220 00:12:05,480 --> 00:12:11,340 secure things by default rather than what you would have on premises, 221 00:12:11,340 --> 00:12:12,760 or they're also in the same boat? 222 00:12:14,059 --> 00:12:18,559 it… You're also in the same… Depending on who your vendor is, you just by default 223 00:12:18,559 --> 00:12:22,369 spin up an Azure environment and put servers out there, absolutely Microsoft 224 00:12:22,379 --> 00:12:24,249 is gonna feed you their Kool-Aid. 225 00:12:24,259 --> 00:12:25,649 they're gonna be using RDP. 226 00:12:25,649 --> 00:12:29,649 It's gonna be configured the way they want it done, unless you tell them differently. 227 00:12:30,519 --> 00:12:34,809 So absolutely, yeah, Microsoft is a Microsoft shop, and they're gonna use all 228 00:12:34,809 --> 00:12:36,309 their stuff, and they think it's great. 229 00:12:36,979 --> 00:12:40,829 it's up to you to mitigate all that or to, to change whatever that might be. 230 00:12:41,109 --> 00:12:42,359 AWS is different. 231 00:12:42,479 --> 00:12:47,819 a lot of AWS, it's either you or a, a, a vendor that you've hired 232 00:12:47,819 --> 00:12:50,789 to help you build your virtualized environment, your cloud environment. 233 00:12:51,549 --> 00:12:52,669 that's kinda on you. 234 00:12:53,159 --> 00:12:56,859 so other environments that aren't Azure are a little different, but in most 235 00:12:56,859 --> 00:13:02,689 cases, unless you dictate how your servers are built, that, especially w- 236 00:13:03,019 --> 00:13:08,169 and it's only Windows, how your Windows servers are built, if you don't, if you 237 00:13:08,169 --> 00:13:12,439 don't spec- if you don't specify, then RDP is gonna be turned on by default. 238 00:13:12,469 --> 00:13:16,179 It's gonna be there whether you use it or not, and if you do use it, it's really 239 00:13:16,179 --> 00:13:20,549 no different than making sure you're using it appropriately and it's secured 240 00:13:20,549 --> 00:13:23,349 appropriately on-premise or in the cloud. 241 00:13:24,189 --> 00:13:27,409 The biggest problem, though, is if you've got it turned on in the 242 00:13:27,409 --> 00:13:29,329 cloud, it's already in the internet, 243 00:13:29,768 --> 00:13:30,098 Yeah 244 00:13:30,169 --> 00:13:33,369 So you've gotta be more cautious about, how am I using RDP? 245 00:13:33,429 --> 00:13:37,579 am I VPN-ing into a cloud environment and then using RDP, or am I using RDP 246 00:13:37,589 --> 00:13:40,909 from my desk through the firewall, out to the internet, through another firewall? 247 00:13:41,359 --> 00:13:44,209 That's even worse almost, 'cause just really, 248 00:13:46,489 --> 00:13:47,819 it, it all depends. 249 00:13:47,869 --> 00:13:50,419 it depends on your environment, depends on your budget, depends 250 00:13:50,419 --> 00:13:53,489 on your skill set, depends on your partners, depends on the environment. 251 00:13:53,569 --> 00:13:54,009 I'm just… 252 00:13:54,356 --> 00:13:57,076 We should, I think we should do a poll on how long 253 00:13:57,114 --> 00:13:57,534 To be a shirt 254 00:13:57,606 --> 00:14:00,336 Mike to say the phrase, "It depends," in each episode. 255 00:14:00,806 --> 00:14:05,356 but, Mike, let's move forward with, so the, e- earlier you were talking 256 00:14:05,356 --> 00:14:08,766 about wandering around the neighborhood and looking for the, in my analogy, 257 00:14:08,766 --> 00:14:11,026 the, the red flashing light, on. 258 00:14:11,386 --> 00:14:12,576 who would do that? 259 00:14:12,586 --> 00:14:18,006 Let's talk about, this, this really important group, the, the IABs 260 00:14:22,477 --> 00:14:24,077 it's, it ranges. 261 00:14:24,157 --> 00:14:30,017 security companies will search for those exposed services in order to identify 262 00:14:30,017 --> 00:14:32,367 opportunities for business development. 263 00:14:32,617 --> 00:14:37,167 there, it's not a… I frown upon that approach, but there are security 264 00:14:37,167 --> 00:14:39,727 companies out there that are the ambulance chasers, if you will. 265 00:14:40,427 --> 00:14:43,737 they're looking for known security flaws, and then they call you and go, 266 00:14:43,737 --> 00:14:46,107 "Hey, just to let you know, you've got this problem. We can help you fix it." 267 00:14:46,587 --> 00:14:48,657 I don't appreciate that, or condone it. 268 00:14:49,117 --> 00:14:54,257 Then there are people, people learning about cyber and this thing. 269 00:14:54,347 --> 00:14:55,667 "Hey, I heard that RDP's bad. 270 00:14:55,667 --> 00:14:57,767 I listened to this, Backup Wrap-Up podcast. 271 00:14:57,767 --> 00:15:00,477 I wanna go check that out." so they're gonna search for 272 00:15:00,487 --> 00:15:02,247 RDP. "All right, I found it. 273 00:15:02,247 --> 00:15:04,347 What do I do with it?" And so there's that. 274 00:15:04,347 --> 00:15:05,967 We call those script kiddies or newbies. 275 00:15:07,717 --> 00:15:11,237 and then you've got the people that really understand what it, the value 276 00:15:11,237 --> 00:15:15,677 of that exposed service, and they're gonna use tools like Shodan, which is a 277 00:15:18,233 --> 00:15:18,963 Nefarious. 278 00:15:19,023 --> 00:15:22,523 it's not, it's a legitimate search engine, but it's 100% 279 00:15:22,563 --> 00:15:25,023 used for bad stuff of the time. 280 00:15:25,523 --> 00:15:30,363 So in Shodan it's so in Google you would say, "What is RDP?" In Shodan you would 281 00:15:30,363 --> 00:15:37,783 say, "Show me every network that has RDP service exposed to the internet around 282 00:15:37,783 --> 00:15:40,133 the entire globe." And it will tell you. 283 00:15:40,593 --> 00:15:42,713 It, so it looks for those types of things. 284 00:15:43,023 --> 00:15:48,333 It doesn't look for articles, it looks for technical stuff, 285 00:15:48,648 --> 00:15:48,978 Right 286 00:15:49,393 --> 00:15:55,033 So Shodan is probably the, the number one if… It's probably the number 287 00:15:55,033 --> 00:16:00,383 one from a volume perspective for searching for stuff like that, and 288 00:16:00,383 --> 00:16:02,543 it gives you pretty verbose results. 289 00:16:02,553 --> 00:16:07,463 It'll tell you the IP address, the type of device that's promoting RDP. 290 00:16:07,463 --> 00:16:08,253 Is it a firewall? 291 00:16:08,253 --> 00:16:10,663 Is it a, a server out on the edge? 292 00:16:10,673 --> 00:16:11,623 Is it, what is it? 293 00:16:14,493 --> 00:16:16,703 country of origin, how long it's been there. 294 00:16:17,843 --> 00:16:19,853 there's any… And that's all on the normal internet. 295 00:16:20,053 --> 00:16:23,193 Then you can take that information into the dark net and see if, 296 00:16:23,203 --> 00:16:24,573 who, who else has attacked this. 297 00:16:24,643 --> 00:16:27,593 are there credentials that I can buy or find? 298 00:16:28,283 --> 00:16:30,053 So it's a process on the recon. 299 00:16:30,083 --> 00:16:34,043 So all that would be considered reconnaissance, and today all that can be 300 00:16:34,043 --> 00:16:39,733 done very quickly, especially with some of the dark net AI tools that are out there. 301 00:16:39,793 --> 00:16:43,918 you can put an attack list and a strategy together in 30 seconds 302 00:16:44,019 --> 00:16:44,609 But Mike, 303 00:16:44,831 --> 00:16:45,701 that… Hang on. 304 00:16:45,781 --> 00:16:46,491 Hang on, Prasanna. 305 00:16:46,731 --> 00:16:48,221 Mike, that was a great answer. 306 00:16:48,671 --> 00:16:49,321 It was not 307 00:16:49,371 --> 00:16:49,951 Now what you 308 00:16:49,961 --> 00:16:50,971 question I asked. 309 00:16:51,371 --> 00:16:55,801 the question I asked was who are initial access brokers? 310 00:16:56,830 --> 00:16:59,330 I thought I'd t- oh, no, I apologize. 311 00:16:59,330 --> 00:17:02,250 thought you were asking if IABs were the ones 312 00:17:02,383 --> 00:17:02,823 okay. 313 00:17:02,873 --> 00:17:03,383 Okay. 314 00:17:04,273 --> 00:17:04,713 Yeah, so 315 00:17:04,730 --> 00:17:05,210 and so my 316 00:17:05,453 --> 00:17:07,080 who, is this en- who is this entity, 317 00:17:07,178 --> 00:17:07,328 much 318 00:17:07,780 --> 00:17:09,630 and how do they figure into this? 319 00:17:10,518 --> 00:17:14,218 Yeah, initial access brokers are the guys that have, or, I'm gonna say guys, 320 00:17:14,278 --> 00:17:16,038 they are the, the group that has… 321 00:17:16,088 --> 00:17:19,018 They've already done the, the, the validation. 322 00:17:19,408 --> 00:17:23,448 so they searched for, and we'll just stick on the RDP theme for now. 323 00:17:24,938 --> 00:17:28,618 they've already identified all the assets with RDP accessible to the internet. 324 00:17:28,948 --> 00:17:33,108 They've already done their homework on are there known or published credentials 325 00:17:33,108 --> 00:17:35,868 for that device, for that RDP service. 326 00:17:37,068 --> 00:17:39,598 and they've packaged that together and they're, they've got that for 327 00:17:39,598 --> 00:17:44,618 sale for someone that wants to utilize it for an attack or whatever reason 328 00:17:44,847 --> 00:17:50,387 But is it safe to say though that without those credentials, just 329 00:17:50,397 --> 00:17:54,677 having RDP exposed out is bad? 330 00:17:56,112 --> 00:17:56,712 It is. 331 00:17:57,132 --> 00:17:57,812 it depends. 332 00:17:58,092 --> 00:18:03,242 No, it is because is it RDP… I- is it truly outbound RDP? 333 00:18:03,582 --> 00:18:05,582 so RDP from your environment to the cloud? 334 00:18:06,202 --> 00:18:11,032 or is it exposed to the internet so you can RDP in home or wherever if there's 335 00:18:11,032 --> 00:18:15,902 a problem or hopefully that's not your remote access mechanism for normal users. 336 00:18:18,292 --> 00:18:21,452 and then the other question is, did you change the password? 337 00:18:21,602 --> 00:18:22,432 Is it default? 338 00:18:22,462 --> 00:18:23,372 Is it easy? 339 00:18:23,372 --> 00:18:26,032 Is it, is it, 1234 and admin? 340 00:18:28,312 --> 00:18:33,142 so yeah, there's any number of ways that we can abuse, 341 00:18:35,232 --> 00:18:36,372 published RDP service 342 00:18:36,866 --> 00:18:43,346 But it also, in addition to, either guessing or obtaining the credentials 343 00:18:43,346 --> 00:18:47,426 to do this, my understanding is that there's also times where there are 344 00:18:47,426 --> 00:18:51,506 vulnerabilities of RDP that where you don't need said credentials. 345 00:18:52,196 --> 00:18:52,906 Is that correct? 346 00:18:55,344 --> 00:19:01,774 Yes, because of the vulnerabilities with RDP aren't specific to authenticating 347 00:19:01,814 --> 00:19:06,004 to RDP versus just capturing RDP traffic 348 00:19:08,590 --> 00:19:13,420 So internal to the network, default, RDP traffic is not encrypted 349 00:19:15,534 --> 00:19:17,044 So I can capture keystrokes. 350 00:19:17,084 --> 00:19:21,204 In fact, I've got a video from years ago where we did a DNS poisoning. 351 00:19:22,004 --> 00:19:23,954 it wasn't DNS, it was a 352 00:19:24,151 --> 00:19:24,861 At least DNS 353 00:19:26,394 --> 00:19:28,274 it was a routing table poisoning. 354 00:19:28,914 --> 00:19:33,234 and so we were able to get a router to sh- to, to send us the keystrokes 355 00:19:33,644 --> 00:19:38,294 that an admin was sending to a server, and we captured all of it, because 356 00:19:38,294 --> 00:19:42,074 our, at the, at, in that case, RDP, the RDP traffic was not encrypted. 357 00:19:43,284 --> 00:19:46,264 so I don't need access to be able to use RDP. 358 00:19:46,264 --> 00:19:47,534 I just need to be on the network. 359 00:19:47,554 --> 00:19:48,664 I just need to be in the middle 360 00:19:49,490 --> 00:19:49,680 to, 361 00:19:49,710 --> 00:19:50,080 to capture- 362 00:19:50,427 --> 00:19:54,917 to take your, that concept, and you said normally on an internal 363 00:19:54,917 --> 00:19:56,047 network it's not encrypted. 364 00:19:56,527 --> 00:20:00,497 If the server is directly on the internet, it's considering the internet the 365 00:20:00,497 --> 00:20:02,077 internal network at that point, right? 366 00:20:03,157 --> 00:20:06,557 So meaning, meaning that the, that your traffic would also not be encrypted 367 00:20:09,770 --> 00:20:10,780 It depends. 368 00:20:10,950 --> 00:20:13,120 So that point-to-point part, so if 369 00:20:13,145 --> 00:20:13,615 Right 370 00:20:14,540 --> 00:20:17,410 talking to the cloud firewall, is that a VPN? 371 00:20:17,523 --> 00:20:17,913 okay. 372 00:20:17,943 --> 00:20:19,573 assume, assuming there's no VPN. 373 00:20:19,733 --> 00:20:23,733 I'm just, I g- I got, a stupid server just sitting flat on the internet, is 374 00:20:23,733 --> 00:20:25,553 what I'm saying, not behind a firewall. 375 00:20:25,893 --> 00:20:31,073 the dumbest server ever, and no firewall, th- it, then it would be unencrypted. 376 00:20:32,708 --> 00:20:32,968 Right 377 00:20:32,993 --> 00:20:33,363 Okay. 378 00:20:33,503 --> 00:20:36,323 Which w- which I think we can all agree would be it, which is the point 379 00:20:36,373 --> 00:20:37,673 of this whole discussion, right? 380 00:20:38,213 --> 00:20:41,413 so I think we can agree, I think all three of us can agree is the never 381 00:20:41,413 --> 00:20:43,703 t- on the internet rule for RDP, 382 00:20:44,497 --> 00:20:45,487 I don't think it's just RDP. 383 00:20:45,487 --> 00:20:48,237 I think it's everything should not be on the internet unless 384 00:20:48,237 --> 00:20:49,337 it needs to be on the internet. 385 00:20:49,929 --> 00:20:50,759 That is true. 386 00:20:51,039 --> 00:20:54,509 I think there are some other services that are perhaps a little more secure 387 00:20:54,509 --> 00:20:58,879 that are s- safer to have on the internet, but, that is a much longer discussion. 388 00:20:59,369 --> 00:21:03,659 Mike, in the book, you talked about something called the survival stack. 389 00:21:03,719 --> 00:21:07,109 if people are gonna… If they need RDP, and by the way, I 390 00:21:07,109 --> 00:21:08,409 still think they don't need it. 391 00:21:08,529 --> 00:21:10,599 They need remote access, right? 392 00:21:10,869 --> 00:21:14,269 If you need remote access and you cannot afford a third-party remote 393 00:21:14,269 --> 00:21:18,439 access solution, then you need, is that, am I on the right track here? 394 00:21:18,459 --> 00:21:20,909 Then we start talking about the network survival stack. 395 00:21:21,319 --> 00:21:22,289 you wanna talk about that? 396 00:21:23,480 --> 00:21:26,520 Sure, and I wanna clear up a misconception about 397 00:21:28,640 --> 00:21:32,780 there are so many enterprise class tools out there now for VPN and 398 00:21:32,780 --> 00:21:37,890 zero trust that, I can think of offhand is, Zscaler, and it's $6 a month. 399 00:21:38,860 --> 00:21:40,390 and that… So that's enterprise. 400 00:21:40,390 --> 00:21:44,160 I'm not talking about the, the people at home that wanna be able to surf the 401 00:21:44,160 --> 00:21:48,560 internet and not, through a VPN and not have, traceability or whatever. 402 00:21:48,560 --> 00:21:52,030 You wanna… If you wanna use some of those other consumer 403 00:21:52,030 --> 00:21:54,160 level that's up to you. 404 00:21:54,160 --> 00:21:59,470 But enterprise stuff, Zscaler is very affordable, and it's very good, 405 00:22:00,183 --> 00:22:01,063 Six, that's $6 a month 406 00:22:01,130 --> 00:22:01,150 So 407 00:22:01,863 --> 00:22:03,333 per, box or per? 408 00:22:03,606 --> 00:22:04,376 per user. 409 00:22:04,423 --> 00:22:05,093 user, okay. 410 00:22:05,173 --> 00:22:05,353 Okay 411 00:22:06,136 --> 00:22:07,946 And that's mid-size. 412 00:22:07,946 --> 00:22:10,286 obviously a lot of companies will scale with you. 413 00:22:10,296 --> 00:22:15,056 if you wanna put 1,000 users on it, maybe it's not $6, maybe it's $4 or 414 00:22:15,155 --> 00:22:15,514 Gotcha. 415 00:22:15,914 --> 00:22:16,174 Okay 416 00:22:16,376 --> 00:22:17,906 it's affordable is what I'm getting at. 417 00:22:18,526 --> 00:22:22,216 And it's, and they're a lot easier to use than, back in the day you 418 00:22:22,226 --> 00:22:23,576 had to have a client installed. 419 00:22:23,586 --> 00:22:28,326 The client had to have a code or a cert or a token that tied it to the server, 420 00:22:28,326 --> 00:22:30,156 and then you had to put credentials in. 421 00:22:30,166 --> 00:22:32,196 Hopefully you had to put credentials in, and that they 422 00:22:32,196 --> 00:22:33,646 were different than your domain. 423 00:22:33,966 --> 00:22:35,766 So then you connect it, and then you have your domain. 424 00:22:36,186 --> 00:22:40,006 or you had to have a, a token with a, a key, a code on it. 425 00:22:40,476 --> 00:22:41,716 Two hours later 426 00:22:41,775 --> 00:22:42,045 things. 427 00:22:43,025 --> 00:22:43,455 Yes. 428 00:22:44,155 --> 00:22:48,895 so long story short, RDP on its own, if you have to use it, you 429 00:22:49,085 --> 00:22:53,935 need to have more controls in place to mitigate the risk of using it. 430 00:22:54,355 --> 00:22:56,975 So you don't wanna RDP directly into your environment. 431 00:22:57,005 --> 00:23:01,505 You want some other method, whether that's VPN or some zero 432 00:23:01,505 --> 00:23:04,865 trust solution, and then use RDP. 433 00:23:04,895 --> 00:23:07,355 So don't let RDP be exposed to the internet. 434 00:23:07,705 --> 00:23:12,735 Just have it running internally, and then u- use some other, more robust, 435 00:23:12,815 --> 00:23:16,895 trusted, configurable, remote access 436 00:23:16,975 --> 00:23:17,835 into the environment, 437 00:23:17,910 --> 00:23:22,770 and Mike, when we say don't let, it be exposed to the internet, the, is 438 00:23:22,770 --> 00:23:25,790 the easiest way to do that is just block that port on the firewall? 439 00:23:26,965 --> 00:23:27,485 Block it at the 440 00:23:27,670 --> 00:23:27,950 Yeah. 441 00:23:28,040 --> 00:23:28,400 Okay. 442 00:23:28,475 --> 00:23:31,610 Both the service and the port, or the protocol and the port 443 00:23:31,774 --> 00:23:33,174 so you talk… Yeah, go ahead 444 00:23:34,858 --> 00:23:40,138 that's important you could block the port and then you're compromised 445 00:23:40,148 --> 00:23:45,048 some other way, because you're not blocking the service, bad guys will 446 00:23:45,048 --> 00:23:46,308 just put it out a different port 447 00:23:49,264 --> 00:23:50,354 Yeah, that makes sense. 448 00:23:51,105 --> 00:23:51,475 But 449 00:23:52,424 --> 00:23:52,584 go ahead 450 00:23:53,195 --> 00:23:59,565 in this case though, Mike, that prevents external access to RDP, correct? 451 00:24:00,715 --> 00:24:03,805 In the sense of your RDP server is no longer visible on the internet. 452 00:24:04,865 --> 00:24:11,375 Is there things you could do in case a, an attacker comes in through some 453 00:24:11,415 --> 00:24:17,235 other, exploit or compromise, gets onto your network to prevent the 454 00:24:17,235 --> 00:24:22,105 lateral movement and exploiting RDP after they're inside your network? 455 00:24:24,120 --> 00:24:26,720 So that, I'm trying not to say depends. 456 00:24:26,790 --> 00:24:30,250 That, that is, it's based on how your architecture's built. 457 00:24:31,350 --> 00:24:35,130 So if you've got a simple flat architecture, you could still 458 00:24:35,130 --> 00:24:39,083 potentially define that rule on your firewall or your core switch. 459 00:24:40,003 --> 00:24:44,133 if you've got a complex environment, then you've gotta, you've gotta replicate 460 00:24:44,133 --> 00:24:46,053 that rule a- across your environment. 461 00:24:46,433 --> 00:24:50,263 You could also have group policy if you're a Windows environment 462 00:24:50,373 --> 00:24:51,763 that prevents it at the endpoint. 463 00:24:52,613 --> 00:24:57,913 You could also have an endpoint anti-malware solution like Huntress, 464 00:24:57,943 --> 00:25:01,833 as an example, that will trigger on the use of those protocols. 465 00:25:02,583 --> 00:25:05,933 You can… This is back to living on the land. 466 00:25:06,003 --> 00:25:09,303 Don't let it be available on that endpoint, right? 467 00:25:09,353 --> 00:25:10,983 Uninstall it, turn it off. 468 00:25:12,103 --> 00:25:15,373 bad guys, if a bad guy's made it to the endpoint and they wanna 469 00:25:15,373 --> 00:25:17,723 pivot, they're not gonna use RDP. 470 00:25:17,743 --> 00:25:20,923 They're gonna… They're probably gonna bring their own remote 471 00:25:20,923 --> 00:25:25,643 management tool like, ServiceNow or Splashtop or something like that 472 00:25:25,831 --> 00:25:28,471 So how does, NLA, network level authentication, 473 00:25:28,511 --> 00:25:29,761 figure into this discussion? 474 00:25:32,449 --> 00:25:35,169 Oh, what… Your architecture will, 475 00:25:35,838 --> 00:25:36,898 It depends. 476 00:25:36,929 --> 00:25:40,589 your architecture will dictate that as well. 477 00:25:41,009 --> 00:25:43,359 So if, again, if you've got a flat environment, you've 478 00:25:43,359 --> 00:25:44,659 got a domain controller. 479 00:25:44,859 --> 00:25:47,919 What, there's a lot of environments don't even have domain controllers. 480 00:25:51,565 --> 00:25:55,005 if you don't have a domain controller, your users are not authenticated to 481 00:25:55,005 --> 00:25:59,495 the network, they're just users that have access to other assets and the 482 00:25:59,495 --> 00:26:06,515 internet, that's probably actually not as risky because the endpoints don't 483 00:26:06,515 --> 00:26:09,605 have access to other stuff, unless you've created shares and things. 484 00:26:09,605 --> 00:26:12,965 But an environment where you've got a domain controller and you're 485 00:26:12,965 --> 00:26:17,885 authenticating to it, domain controller now has to be configured well so that 486 00:26:18,325 --> 00:26:24,575 the authentication of one device can't be cloned or duplicated or stolen. 487 00:26:24,965 --> 00:26:29,825 those Kerberos tickets or, sessions, from one asset to the other. 488 00:26:29,855 --> 00:26:34,585 And you can define in your architecture those routing restrictions that 489 00:26:34,585 --> 00:26:40,875 says, Mike's identity, can only persist on one device at a time. 490 00:26:42,265 --> 00:26:47,245 So group policy, architecture, good architecture design, good domain 491 00:26:47,245 --> 00:26:50,595 controller configuration, firewall rules. 492 00:26:50,755 --> 00:26:53,255 A-again, depends on, architecture. 493 00:26:53,795 --> 00:26:55,715 but all of that is, it's not new. 494 00:26:55,785 --> 00:26:59,645 It just takes time to work through, and if it's done right to begin 495 00:26:59,645 --> 00:27:01,035 with, it's a lot easier to manage 496 00:27:01,949 --> 00:27:05,739 The, yeah, let's move to the sort of the, the things that they should do, right? 497 00:27:05,739 --> 00:27:07,159 We talked about things not to do. 498 00:27:07,709 --> 00:27:08,239 you talked 499 00:27:08,572 --> 00:27:09,472 Don't use Windows. 500 00:27:10,439 --> 00:27:14,499 Oh, I remember, B- by the way, I did… while you two were talking at some 501 00:27:14,499 --> 00:27:19,999 point, I did look, and by the way, I was correct on Motif, but I do date myself. 502 00:27:20,019 --> 00:27:22,679 Apparently, it's not used very much anymore. 503 00:27:22,699 --> 00:27:24,899 That is the Windows manager for 504 00:27:25,428 --> 00:27:26,068 The gnome? 505 00:27:26,569 --> 00:27:28,449 old school Unix and Linux. 506 00:27:28,759 --> 00:27:32,349 and, it's still used… It's very lightweight, and it's still used 507 00:27:32,349 --> 00:27:36,849 in some distributions, but mainly for those that want a retro '90s 508 00:27:36,849 --> 00:27:38,474 aesthetic, according to that. 509 00:27:38,834 --> 00:27:44,094 I've got Openbox, Fluxbox, IceWM, there's a bunch of other ones. 510 00:27:44,094 --> 00:27:46,364 Anyway, just wanna make sure I wasn't crazy. 511 00:27:46,714 --> 00:27:50,764 So one, one of the things that we talked earlier about blocking the, the port 512 00:27:50,764 --> 00:27:57,174 and the service, the port's 3389, but, is something apparently that could 513 00:27:57,174 --> 00:27:59,584 result in a problem if you do that. 514 00:27:59,644 --> 00:28:01,194 but so you wanna talk about that, Mike? 515 00:28:04,800 --> 00:28:07,460 3389 could be used by something else. 516 00:28:07,540 --> 00:28:11,310 And so similar to, other recommendations we've given, you need to do some 517 00:28:11,350 --> 00:28:18,160 analysis in your environment to make sure that there's not some preexisting 518 00:28:18,160 --> 00:28:25,040 rule or service or connection, going out this or any other suspicious port. 519 00:28:25,090 --> 00:28:27,170 you wanna… you don't wanna impact business. 520 00:28:27,530 --> 00:28:35,200 we recommend 3389 'cause that's common for RDP or default RDP, but 521 00:28:35,200 --> 00:28:39,690 your environment could very well be using 3389 for a database connection 522 00:28:39,690 --> 00:28:41,840 or a, a session call or something 523 00:28:42,004 --> 00:28:44,764 It's sad, but, you have that problem, sad on you. 524 00:28:44,764 --> 00:28:48,364 So the next thing I've got on our to-do list here is to, if 525 00:28:48,394 --> 00:28:51,754 possible, I think everything, everything we're saying, right? 526 00:28:51,764 --> 00:28:55,164 No… Everything we're saying is investigate this 527 00:28:55,174 --> 00:28:56,774 in your environment, right? 528 00:28:57,004 --> 00:29:01,584 And that is, if possible, enforce network-level authentication, right? 529 00:29:01,584 --> 00:29:05,854 Because that's gonna support, or that's gonna, require users to prove who they 530 00:29:05,854 --> 00:29:08,494 are before they, start a- an RDP session. 531 00:29:09,034 --> 00:29:11,544 and then prasanna, what's our final recommendation? 532 00:29:12,375 --> 00:29:18,775 Final recommendation is if you are coming from external into an RDP environment 533 00:29:18,775 --> 00:29:23,515 or connecting from one to an RDP environment, use something to secure 534 00:29:23,515 --> 00:29:28,855 that external connection like a VPN such that you have-- you are not exposing 535 00:29:28,865 --> 00:29:33,825 RDP directly to the internet, but you do have that sort of proxy or secure 536 00:29:33,835 --> 00:29:39,345 connection into your network to then pass off into the VP, into the RDP session. 537 00:29:40,520 --> 00:29:43,220 Related to that, I w- I, we didn't have it on our list, but 538 00:29:43,220 --> 00:29:44,520 we discussed it in the book. 539 00:29:44,580 --> 00:29:47,060 that of course would be learning ransomware response and recovery. 540 00:29:47,060 --> 00:29:49,010 I can't believe I didn't mention the name earlier. 541 00:29:49,450 --> 00:29:53,580 We d- we discussed the concept of a bastion host, where you configure it 542 00:29:53,580 --> 00:29:59,330 so that if you're going to use RDP, and anything else that's dangerous, 543 00:29:59,330 --> 00:30:00,980 a- as I make quotes in the air, right? 544 00:30:01,230 --> 00:30:05,020 that you consider a bastion host, where all RDP has to go 545 00:30:05,020 --> 00:30:06,550 via this connection, right? 546 00:30:06,590 --> 00:30:08,770 And I think VPN is one of those ways. 547 00:30:09,090 --> 00:30:10,760 A bastion host would be another way. 548 00:30:11,160 --> 00:30:12,860 And, we seem to have lost Mike. 549 00:30:12,890 --> 00:30:13,150 I don't know 550 00:30:13,315 --> 00:30:14,045 No, he's back 551 00:30:14,110 --> 00:30:14,630 over there? 552 00:30:15,780 --> 00:30:16,430 You're glitching 553 00:30:17,306 --> 00:30:18,936 My all fuzzy. 554 00:30:18,936 --> 00:30:19,996 I'm not sure what's going on 555 00:30:21,214 --> 00:30:22,334 maybe you've been day drinking. 556 00:30:22,604 --> 00:30:23,074 All right, 557 00:30:23,204 --> 00:30:25,794 Wait, I have one more thing to ask or see. 558 00:30:26,484 --> 00:30:32,074 Mike, is there anything from an auditing perspective that you would recommend 559 00:30:32,524 --> 00:30:34,944 for remote desktop connections? 560 00:30:37,448 --> 00:30:38,228 or monitoring 561 00:30:40,073 --> 00:30:41,433 Oh, monitoring for sure. 562 00:30:41,483 --> 00:30:43,763 and there's, there are different ways of doing that too. 563 00:30:43,763 --> 00:30:44,533 There's layers. 564 00:30:44,533 --> 00:30:47,493 There's the endpoint layer, the network layer, the firewall perimeter 565 00:30:47,493 --> 00:30:49,333 layer for all those protocols. 566 00:30:50,123 --> 00:30:55,273 The important part is the governance layer, which is what we, establishing the 567 00:30:55,273 --> 00:31:00,443 policy of what we allow, what we prohibit, and then what are the exceptions. 568 00:31:00,473 --> 00:31:04,243 And then documenting that so when things do come up, we can very quickly 569 00:31:04,243 --> 00:31:06,383 determine if it's allowed or not. 570 00:31:07,113 --> 00:31:10,493 And then your incident response policy would, or procedure would say, 571 00:31:10,493 --> 00:31:13,593 "When these do, when these things happen, here are the people we need 572 00:31:13,593 --> 00:31:16,643 to involve in the conversation so we can determine how to address it." 573 00:31:18,392 --> 00:31:19,622 you heard it here, folks. 574 00:31:19,682 --> 00:31:21,672 Prasanna is pro RDP. 575 00:31:23,002 --> 00:31:26,232 I'm against it, and, Mike is with me. 576 00:31:26,332 --> 00:31:28,692 Well, no, Mike purple hat is with you. 577 00:31:28,702 --> 00:31:30,352 Mike red hat is against you 578 00:31:43,919 --> 00:31:44,069 so 579 00:31:44,069 --> 00:31:50,089 blue says, "No RDP." Red says, "I love RDP." Purple says, "Let's, 580 00:31:50,119 --> 00:31:53,970 let's educate each other on the, the appropriate use of RDP or not." 581 00:32:02,794 --> 00:32:07,494 The Backup Wrap-Up is written, recorded, and produced by me, W. Curtis Preston. 582 00:32:08,084 --> 00:32:12,844 If you need backup or DR consulting, content generation, or expert witness 583 00:32:12,844 --> 00:32:15,644 work, check out backupcentral.com. 584 00:32:16,154 --> 00:32:19,214 You can also find links for my O'Reilly books on the same website. 585 00:32:19,944 --> 00:32:23,914 Remember, this is an independent podcast, and any opinions that 586 00:32:23,914 --> 00:32:27,884 you hear are those of the speaker and not necessarily an employer. 587 00:32:28,754 --> 00:32:29,414 Thanks for listening