Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

4 New BlueKeep-like 'Wormable' Windows Remote Desktop Flaws Discovered
The Hacker News ^ | August 13, 2019 | Swati Khandelwal

Posted on 08/15/2019 4:12:46 AM PDT by rarestia

click here to read article


Navigation: use the links below to view more comments.
first 1-2021-27 next last
I already know where this thread is going to go with the inevitable "Upgrade to Mint" or "Microsoft can pry Windows XP from my cold dead hands," but seriously, install this patch! I work in the IT security sector and can tell you that this one is bad. It WILL be exploited in the very near future.
1 posted on 08/15/2019 4:12:46 AM PDT by rarestia
[ Post Reply | Private Reply | View Replies]

To: rarestia

Can’t we successfully turn off RDP?


2 posted on 08/15/2019 4:18:29 AM PDT by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Thanks, I downloaded the security updates while reading the article.


3 posted on 08/15/2019 4:19:27 AM PDT by deks
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeMind
You can disable it, sure.

Disable Windows Remote Desktop

4 posted on 08/15/2019 4:20:26 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rarestia

Folks, disable RDP and you should be okay.

Disable it, anyway, even if you plan to do the update.

https://www.laptopmag.com/articles/disable-remote-desktop


5 posted on 08/15/2019 4:20:58 AM PDT by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Bfl


6 posted on 08/15/2019 4:22:57 AM PDT by pigsmith (Liberals can't make the connection between their politics and the decline of everything around them.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

Every time Win 10 updates it does it several times, crashes and has to uninstall for whatever reason and I wait for the “updating” circle and % shxt then “uninstalling updates” which can take a couple hrs over all.

Then I search for some “unique” MS BS that will allow the upgrade if I’m having problems with the “latest” update. It’s endless......


7 posted on 08/15/2019 4:55:08 AM PDT by maddog55
[ Post Reply | Private Reply | To 1 | View Replies]

To: rarestia

My W10 Home says it doesn’t support RemoteDesktop. I always disable any program that would allow another PC to connect...


8 posted on 08/15/2019 5:08:07 AM PDT by jeffc (The U.S. media are our enemy)
[ Post Reply | Private Reply | To 1 | View Replies]

To: jeffc

If your PC is connected to any network, wireless or wired, another PC can connect to it. More common protocols like RDP are just what the public understands. RPC, DCOM, and WMI are examples of other Microsoft protocols that allow access to your computer remotely, but they’re more secure than RDP in some ways.


9 posted on 08/15/2019 5:15:50 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: rarestia; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Windows 10 Update --CRITICAL-- ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

 
 

DO IT! JUST DO IT!

10 posted on 08/15/2019 5:56:26 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeMind; rarestia
> Folks, disable RDP and you should be okay. Disable it, anyway, even if you plan to do the update.

Which is fine, unless you need to use RDP. You'd be surprised...

Especially at any place of business.

11 posted on 08/15/2019 5:58:22 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 5 | View Replies]

To: rarestia

Why not go proactive. ID the hackers and blow them away with a drone.


12 posted on 08/15/2019 5:59:32 AM PDT by Mouton (The media is the enemy of the people.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: maddog55

Yep... And the hits keep on coming. Only 89 patches for all versions going back 10 years.


13 posted on 08/15/2019 6:01:45 AM PDT by Openurmind
[ Post Reply | Private Reply | To 7 | View Replies]

To: Mouton

This particular vulnerability is not exploited (yet). It was discovered by Microsoft while working through hardening of the RDP security layer.


14 posted on 08/15/2019 6:03:51 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: rarestia

Yep, mine woke up on it’s own a couple times even though RDP was off. I happened to hear the fan come on and the display light up and I jumped out of bed to hold down the power button before it could fully boot. Someone had power it up remotely. Haven’t trusted MS since.


15 posted on 08/15/2019 6:11:13 AM PDT by Openurmind
[ Post Reply | Private Reply | To 9 | View Replies]

To: Openurmind

Not necessarily. You have a task scheduler on your system, much like Linux cron, and certain tasks can be configured to wake the computer. Often enough your mouse and keyboard are configured to wake the computer from sleep, and if a cat, dog, or wayward critter hit a button or wiggle the mouse, it will wake your machine.

You can go into Windows event viewer > System log, and look for event ID 1 (Power-Troubleshooter) to show you the wake events and what kicked them off.


16 posted on 08/15/2019 6:18:16 AM PDT by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: rarestia

Just don’t open port 3389 on your router’s firewall.


17 posted on 08/15/2019 6:35:33 AM PDT by miliantnutcase
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeMind

Hmmmm...my version of WIN10 (Home) does not support remote desktop....yippee


18 posted on 08/15/2019 7:14:05 AM PDT by goodnesswins (White Privilege EQUALS Self Control & working 50-80 hrs/wk for 40 years!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: rarestia

I am fairly versed in how it works, been into it since the 80s and have NEVER allowed self driving configurations or tasks from any of my computers. When I am not on it I power down and it is down, and after those two events years ago I also make sure and disconnect all possible connections when I power down. I still practice these habits even now with Linux. The remote events were indeed in my logs as not local, someone came in a backdoor and powered it up, and they tried to do it twice before I started my habit of disconnecting everything when I’m not on it.


19 posted on 08/15/2019 7:16:41 AM PDT by Openurmind
[ Post Reply | Private Reply | To 16 | View Replies]

To: rarestia

There is a PAUSE setting for updates under Settings, Advanced Options....mine is set for Aug 29...I DID NOT SET THIS....and I cannot reset it, except till Aug 16th....HELP


20 posted on 08/15/2019 7:42:09 AM PDT by goodnesswins (White Privilege EQUALS Self Control & working 50-80 hrs/wk for 40 years!)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-27 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson