So my server began to crawl this afternoon. I logged into it via RDP and found that there were 200+ winlogin.exe, csrss.exe and loginui.exe processes running utilizing 100% of the server CPU. I checked the System Security event viewer and found that my server was experiencing an RDP hijack attack. I went through all failed audit, recorded the IP addresses and blocked them in the firewall. Shortly after the attack ceased.
This is something I seem to have to do often (block IPs). I would like to craft a firewall rule (if possible) that will deny all RDP login attempts with the exception of IP address that I specify (my own for example). Is this possible in the Windows server 2008 firewall?
Here is an example of one of the thousands of login attempts:
---------------------------------------------------------------------------------------------------
An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: hostway42$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 10
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: user
Account Domain: NN1609
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064
Process Information:
Caller Process ID: 0x6e5c
Caller Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Workstation Name: hostway42
Source Network Address: 66.188.27.98
Source Port: 32944
Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This is something I seem to have to do often (block IPs). I would like to craft a firewall rule (if possible) that will deny all RDP login attempts with the exception of IP address that I specify (my own for example). Is this possible in the Windows server 2008 firewall?
Here is an example of one of the thousands of login attempts:
---------------------------------------------------------------------------------------------------
An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: hostway42$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 10
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: user
Account Domain: NN1609
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc0000064
Process Information:
Caller Process ID: 0x6e5c
Caller Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Workstation Name: hostway42
Source Network Address: 66.188.27.98
Source Port: 32944
Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0