I’ve recently dug into my firewall logs and the most traffic I seem to receive from internet is targeting port 3389.
While I could just blacklist the source IPs and call it a day, I would like to actually listen on this port and “trap” them in a fake RDP connection.
There are tools like endlessh, and I’ve found that you can do the same for http by sending an endless stream of headers. I would like to do the same for RDP, and before I start digging into the whole spec, I was wondering if there is already something similar for RDP.
Is anyone aware of that ? Is that even a thing ?
Only thing that comes to mind is https://github.com/citronneur/rdpy
Is there a linuxserver.io but for infosec?
No idea, I like to build/make my own.
That’s more of a framework for RDP right ?