NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
1–10 of 40 posts
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#2It has the potential to do some serious damage.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#3I'd say those are the first things that should be done, regardless of the presence of exploits; exposing a port/listening service to the Internet you don't need, especially one that can remotely give complete control to an attacker, is always a bad idea. Fortunately the majority of computers out there are probably behind a NAT, which helps greatly to keep them from being hacked remotely.
Disable remote Desktop Services if they are not required. Disabling unused and unneeded services helps reduce exposure to security vulnerabilities overall and is a best practice even without the BlueKeep threat.
Very good advice --- too bad latest Windows versions have not-so-clearly-described tons of services running by default, many of which phone home in some way, and some of which are nearly impossible to disable...
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#4I do!
So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony:
https://www.zdnet.com/article/even-the-nsa-is-urging-windows...
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#5In order to increase resilience against this threat while large networks patch and upgrade, there are additional measures that can be taken I'd say those are the first things that should be done, regardless of the presence of exploits; exposing a port/listening service to the Internet you don't need, especially one that can remotely give complete control to an attacker, is always a bad idea. Fortunately the majority…
Source: https://blog.erratasec.com/2019/05/almost-one-million-vulner...
Eventually someone will wormify that vuln in a few weeks or months and it's going to be a big mess when it happens.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#6Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#7- your friendly neighborhood intelligence agency.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#8Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...
If the NSA was planning to hack you, it wouldn't be via you visiting NSA.gov
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#9You can totally trust our advice for all your digital security needs. - your friendly neighborhood intelligence agency.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#10You can totally trust our advice for all your digital security needs. - your friendly neighborhood intelligence agency.