Let's assume that we found an exposed RDP
service on port 3026. We can use a tool such as RDPassSpray
to password spray against RDP
. First, install the tool on your attacking machine by following the installation instructions in the tool’s GitHub repo. As a new user of this tool, we will start by executing the python3 RDPassSpray.py -h command to see how the tools can be used.
-u option to specify the victim as a username and the (-p) option set the Spring2021!. The (-t) option is to select a single host to attack.Note that we can specify a domain name using the -d option if we are in an Active Directory environment.
python3 RDPassSpray.py -U usernames-list.txt -p Spring2021! -d THM-labs -T RDP_servers.txt