๐ย Secure Bits ๐ก
๐ฌ๐ผ๐๐ฟ ๐ฅ๐๐ฃ ๐๐ฒ๐๐๐ถ๐ผ๐ป ๐บ๐ถ๐ด๐ต๐ ๐น๐ฒ๐ฎ๐๐ฒ ๐ฎ ๐๐ถ๐๐๐ฎ๐น ๐๐ฟ๐ฎ๐ถ๐นโฆ
Did you know thatย Remote Desktop Protocol (RDP)ย ๐ฐ๐ฎ๐ฐ๐ต๐ฒ๐ ๐ณ๐ฟ๐ฎ๐ด๐บ๐ฒ๐ป๐๐ of your screen on the client?
๐ผ๏ธ Theseย bitmap cachesย are stored locally to improve performance โ but they ๐ฐ๐ฎ๐ป ๐ฎ๐น๐๐ผ ๐ฟ๐ฒ๐๐ฒ๐ฎ๐น ๐๐ต๐ฎ๐ ๐๐ฎ๐ ๐๐ฒ๐ฒ๐ป ๐ฑ๐๐ฟ๐ถ๐ป๐ด ๐๐ผ๐๐ฟ ๐๐ฒ๐๐๐ถ๐ผ๐ป. For forensic investigators (or attackers), that meansย possible insight into screen content from previous RDP activity.
๐ย ๐๐ถ๐น๐ฒ ๐น๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป:
%UserProfile%AppDataLocalMicrosoftTerminal Server ClientCache*.bin
๐งฐ ๐ช๐ฎ๐ป๐ ๐๐ผ ๐ฒ๐
๐๐ฟ๐ฎ๐ฐ๐ ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐ฐ๐ผ๐ป๐๐๐ฟ๐๐ฐ๐ ๐๐ต๐ฒ๐บ?
Check out:ย bmc-tools-pyย โ it can turn the cache into a full image collage.
Did you know about this “feature”?
