RDP certificate warning

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

Have you ever seen this ๐—ฅ๐——๐—ฃ ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ ๐˜„๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด? Do you know ๐˜„๐—ต๐—ฎ๐˜ ๐—ถ๐˜ ๐—บ๐—ฒ๐—ฎ๐—ป๐˜€?

It means the certificate presented by the target during RDP ๐—ถ๐˜€๐—ปโ€™๐˜ ๐˜๐—ฟ๐˜‚๐˜€๐˜๐—ฒ๐—ฑ. Often itโ€™s just a self-signed certโ€”which isnโ€™t a huge problem: you can make it trusted or distribute your own certificate. But it can also mean you connected by ๐—œ๐—ฃ ๐—ฎ๐—ฑ๐—ฑ๐—ฟ๐—ฒ๐˜€๐˜€โ€”๐—ฎ๐—ป๐—ฑ ๐˜๐—ต๐—ฎ๐˜โ€™๐˜€ ๐—ฎ ๐—ฏ๐—ถ๐—ด ๐—ฑ๐—ฒ๐—ฎ๐—น โš ๏ธ.

In a default environment, using an ๐—œ๐—ฃ ๐˜๐—ฟ๐—ถ๐—ด๐—ด๐—ฒ๐—ฟ๐˜€ ๐—ก๐—ง๐—Ÿ๐— , which is weaker than Kerberos from a cryptography perspective.

For access, always ๐˜‚๐˜€๐—ฒ ๐—ต๐—ผ๐˜€๐˜๐—ป๐—ฎ๐—บ๐—ฒ๐˜€ so you trigger ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ (ideally with AES). The same applies when configuring services or applicationsโ€”donโ€™t use IPs unless itโ€™s truly necessary.

You can also ๐—ฐ๐—ต๐—ฒ๐—ฐ๐—ธ ๐˜๐—ต๐—ฒ ๐—ฅ๐——๐—ฃ ๐—ฐ๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป: click the lock iconโ€”you want to see Kerberos mentioned there โœ….

๐—ฆ๐—ถ๐—บ๐—ฝ๐—น๐—ฒ ๐˜€๐˜๐—ฒ๐—ฝ, ๐—ฏ๐—ถ๐—ด ๐—ต๐—ฒ๐—น๐—ฝ. If you want to learn more about cybersecurity in Windows infrastructures, check out my ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—ฟ๐—ฒ๐˜€๐—ผ๐˜‚๐—ฟ๐—ฐ๐—ฒ๐˜€:

https://academy.horizon-secured.com/p/free-resources

๐™‡๐™š๐™–๐™ง๐™ฃ โ€ข ๐˜ฝ๐™ช๐™ž๐™ก๐™™ โ€ข ๐˜ฟ๐™š๐™›๐™š๐™ฃ๐™™