SECURITY BE WHAT?!?!? OPEN VNCs! Yeah, that's the ticket!
Okay, this is just nuts. Years ago, there was a Twitter account that posted live vids of them getting into everything via an open VNC from blast furnace controllers to foundries to so many other such systems that could leave a city sized crater if manipulated to do so.
It's 2024 and folks _STILL_ have VNCs published to the Internet?
Seriously?
computernewb.com/vncresolver…
The language herein shall remain professional, but ... wow.
:0(
NEVER publish or plug in directly to the Internet.
- Redfish
- IPMI
- RDP
- VNC
- SSH
- RMM
- SMTP
- ETC. ETC. ETC.
Why does this need to be said? Why?
And no, Security by Obscurity by moving the port for the service does not work. See TSGrinder.
RD Gateway DUO (or other 2FA/MFA) is, in my opinion, the best way to publish that Jump Server, or Jump Servers, or RD Endpoint for remote access.
UserVille gets access to their endpoint whether that be a desktop, workstation, RD Session Host Farm, RD VDI, or RemoteApps in a secure manner using 2FA/MFA.
Admin gets access to their Jump Server(s) to then work on needed systems/problems/tickets.
Taking the thought one step further, if we're segmenting _everything_ as we should be between the various Active Directory Forests/Domains (Infrastructure, Production, Development, ETC) then one should be doing so with an RD Gateway in between each. Do you see where this is going?
Use a unique Security Group, or Groups, to whitelist that remote access. Do _not_ under any condition use the default RD Security Group which is Domain Users for access!
Never put a Domain Admin account into _any_ remote access group. Ever.
Use. A. Jump. Server. Via. PAW!!!
VPN? Uh, that's a hard NO.
Acronyms
RD = Remote Desktop
2FA/MFA = 2 Factor/Multi-Factor Authentication
VDI = Virtual Desktop Infrastructure
PAW = Privileged Access Workstation
Tags
#NetworkSecurity #NoNetworkSecurity
#NetworkSegmentation #PAW
#PrivilegedAccessWorkstation
#RDS #RemoteDesktopServices