<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Dan Kaminsky&#039;s Blog</title>
	<atom:link href="http://dankaminsky.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://dankaminsky.com</link>
	<description>(Or:  The Blog Formerly Known As DoxPara Research)</description>
	<lastBuildDate>Fri, 30 Mar 2012 04:36:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Chris Kubecka</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-6407</link>
		<dc:creator><![CDATA[Chris Kubecka]]></dc:creator>
		<pubDate>Fri, 30 Mar 2012 04:36:07 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-6407</guid>
		<description><![CDATA[What we have been advising is to apply the patch to all at risk assets, review the status of all at risk assets (are they patched, do they have AV, are they being pen and/or vulnerability tested, are there other issues like out of date backup software, etc....), minimize the attack surface, apply a second layer of security controls and monitor the logs and access of any at risk systems. 
Do you have any additional guidance?]]></description>
		<content:encoded><![CDATA[<p>What we have been advising is to apply the patch to all at risk assets, review the status of all at risk assets (are they patched, do they have AV, are they being pen and/or vulnerability tested, are there other issues like out of date backup software, etc&#8230;.), minimize the attack surface, apply a second layer of security controls and monitor the logs and access of any at risk systems.<br />
Do you have any additional guidance?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Chris Kubecka</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-6405</link>
		<dc:creator><![CDATA[Chris Kubecka]]></dc:creator>
		<pubDate>Fri, 30 Mar 2012 04:29:53 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-6405</guid>
		<description><![CDATA[Very nice passive technique to scan especially if you are in a country which might consider scanning IP ranges (ore any IP)  &quot;hacking&quot;.]]></description>
		<content:encoded><![CDATA[<p>Very nice passive technique to scan especially if you are in a country which might consider scanning IP ranges (ore any IP)  &#8220;hacking&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on White Hat Hacker Flowchart by Touz</title>
		<link>http://dankaminsky.com/2012/02/20/whitehat/#comment-5721</link>
		<dc:creator><![CDATA[Touz]]></dc:creator>
		<pubDate>Fri, 23 Mar 2012 10:01:01 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2472#comment-5721</guid>
		<description><![CDATA[Hilariously painfully true! Can&#039;t believe I missed this when it was posted. Too many cool shiny article objects on your site!  BTW: Sometimes my &quot;Ruh Roh&quot; has occurred in the midst of &quot;Sending Unusual Traffic&quot;.  Going up on my office wall.  thanks!]]></description>
		<content:encoded><![CDATA[<p>Hilariously painfully true! Can&#8217;t believe I missed this when it was posted. Too many cool shiny article objects on your site!  BTW: Sometimes my &#8220;Ruh Roh&#8221; has occurred in the midst of &#8220;Sending Unusual Traffic&#8221;.  Going up on my office wall.  thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Dan Kaminsky</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5407</link>
		<dc:creator><![CDATA[Dan Kaminsky]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 08:42:13 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5407</guid>
		<description><![CDATA[It&#039;s a base of 5M or so.  I wouldn&#039;t be surprised if there&#039;s a hundred thousand RDP listeners on 443, not to mention TSG, but I&#039;d be surprised if there were another 1-2M.

My data isn&#039;t showing how vulnerable RDP, just that it&#039;s exposed.  Specifically it doesn&#039;t show what is and isn&#039;t patched.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s a base of 5M or so.  I wouldn&#8217;t be surprised if there&#8217;s a hundred thousand RDP listeners on 443, not to mention TSG, but I&#8217;d be surprised if there were another 1-2M.</p>
<p>My data isn&#8217;t showing how vulnerable RDP, just that it&#8217;s exposed.  Specifically it doesn&#8217;t show what is and isn&#8217;t patched.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by A.K</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5406</link>
		<dc:creator><![CDATA[A.K]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 08:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5406</guid>
		<description><![CDATA[So true of Joe Gatt&#039;s reply. There is another point on using PAT on external firewalls later then translate to respective 3389/tcp hosts. While Dan&#039;s research gave us brief overview on how vulnerable RDP on internet, we still have to know there are always more underlying issues.]]></description>
		<content:encoded><![CDATA[<p>So true of Joe Gatt&#8217;s reply. There is another point on using PAT on external firewalls later then translate to respective 3389/tcp hosts. While Dan&#8217;s research gave us brief overview on how vulnerable RDP on internet, we still have to know there are always more underlying issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by anon y mouse</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5397</link>
		<dc:creator><![CDATA[anon y mouse]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 06:11:28 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5397</guid>
		<description><![CDATA[Note there&#039;s a non-standard port of Windows Home Server and Windows Small Business server - http://social.technet.microsoft.com/wiki/contents/articles/922.windows-home-server-router-setup.aspx#Manual_Router_Configuration has it on 4125 and WHS/SBS will happy use uPNP to open that port on your router and forward it to the exposed service.]]></description>
		<content:encoded><![CDATA[<p>Note there&#8217;s a non-standard port of Windows Home Server and Windows Small Business server &#8211; <a href="http://social.technet.microsoft.com/wiki/contents/articles/922.windows-home-server-router-setup.aspx#Manual_Router_Configuration" rel="nofollow">http://social.technet.microsoft.com/wiki/contents/articles/922.windows-home-server-router-setup.aspx#Manual_Router_Configuration</a> has it on 4125 and WHS/SBS will happy use uPNP to open that port on your router and forward it to the exposed service.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Dan Kaminsky</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5395</link>
		<dc:creator><![CDATA[Dan Kaminsky]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 05:45:54 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5395</guid>
		<description><![CDATA[Interesting idea.]]></description>
		<content:encoded><![CDATA[<p>Interesting idea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Joe Gatt</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5394</link>
		<dc:creator><![CDATA[Joe Gatt]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 05:40:32 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5394</guid>
		<description><![CDATA[Hey Dan,  I know it&#039;s crazy, but have you considered scanning for hosts listening on RDP on non-standard ports like 80/tcp and 443/tcp?  We recently implemented egress filtering in my organization only allow these ports outbound.  So some of our &quot;IT guys&quot; complained to me because they had to change their home RDP listeners to 80 or 443 :(]]></description>
		<content:encoded><![CDATA[<p>Hey Dan,  I know it&#8217;s crazy, but have you considered scanning for hosts listening on RDP on non-standard ports like 80/tcp and 443/tcp?  We recently implemented egress filtering in my organization only allow these ports outbound.  So some of our &#8220;IT guys&#8221; complained to me because they had to change their home RDP listeners to 80 or 443 <img src='http://s0.wp.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Matthew Hackling</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5391</link>
		<dc:creator><![CDATA[Matthew Hackling]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 04:48:06 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5391</guid>
		<description><![CDATA[Check out http://www.rdpcheck.com to test your IP address]]></description>
		<content:encoded><![CDATA[<p>Check out <a href="http://www.rdpcheck.com" rel="nofollow">http://www.rdpcheck.com</a> to test your IP address</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RDP and the Critical Server Attack Surface by Dan Kaminsky</title>
		<link>http://dankaminsky.com/2012/03/18/rdp/#comment-5333</link>
		<dc:creator><![CDATA[Dan Kaminsky]]></dc:creator>
		<pubDate>Sun, 18 Mar 2012 13:29:41 +0000</pubDate>
		<guid isPermaLink="false">http://dankaminsky.com/?p=2494#comment-5333</guid>
		<description><![CDATA[Thanks!  Yeah, I had lots of interpretation I was going to throw onto to this data, and may yet still, but I wanted to get the raw survey data out ASAP.

I actually suspect that there&#039;s a lot of enterprise RDP, in the same way there&#039;s lots of enterprise SSH.  It&#039;s just the default mechanism for Microsoft shops, for those not deploying TS Gateway at least...]]></description>
		<content:encoded><![CDATA[<p>Thanks!  Yeah, I had lots of interpretation I was going to throw onto to this data, and may yet still, but I wanted to get the raw survey data out ASAP.</p>
<p>I actually suspect that there&#8217;s a lot of enterprise RDP, in the same way there&#8217;s lots of enterprise SSH.  It&#8217;s just the default mechanism for Microsoft shops, for those not deploying TS Gateway at least&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
