Anyone else getting their windows login bruteforced?

Rickster

EVGA Fanatic
Joined
Jul 31, 2012
Messages
23,167
Reaction score
5,435
Location
Joe'berg
So im looking at my Windows event logs and i can see under security that they are trying random usernames and passwords every 2 seconds.

Its coming from 2 different IP's, what have done is blocked the IP's in windows firewall and that seems to have sorted the issue.

762104

Here are the IP's in question, can you guys see if the IP's are attacking you too?

762106


Is this via RDP? Because im using a random uncommon port.
 
rdp bruteforce happens 24/7, and more recently some bluekeep opportunists


your box should never be exposed to the internet without some sort of whitelisting/firewall
 
Setting an uncommon port doesn't solve your problem. Don't open RDP to the internet. Use a VPN.
100% this. Don't open port 3389,3390 etc or some uncommon port directly to the internet. Also don't use port 80 for anything open from the internet either.
 
whitelist access to that port

setup vpn on the box, like ipsec or something

vpn in, then rdp via the vpn
 
Security through obscurity (changing ports etc.) will only keep out 1% of the attacks out there. The other 99% are bots that scan for open ports. This is a VERY insecure way of accessing your home network.

Use a certificate based VPN with ipsec and use port knocking or fail2ban with jails setup to keep them from trying to bruteforce their way into your network
 
Are home PC's safe from this type of attack?

I don't want to come home and find that Jamal Pravesh from Kolkata has been all over my ****.
 
Are home PC's safe from this type of attack?

I don't want to come home and find that Jamal Pravesh from Kolkata has been all over my ****.
That depends on your neighbours and the complexity of your WiFi password.....
 
Top
Sign up to the MyBroadband newsletter
X