RDP backdoors
Last updated
Last updated
Windows supports a feature called Sticky Keys, which is an Accessibility feature built into the OS and available pre-logon (at the login screen, either via a physical console or via Remote Desktop). It runs as SYSTEM.
If you set Sethc.exe (Sticky Keys) to spawn cmd.exe, you have a backdoor you can use if you are locked out of a box โ you have SYSTEM access, so you can do anything even without an account. You can do this by either replacing sethc.exe with cmd.exe โ this requires a reboot, and physical access to the box โ or just set the registry key using the command below.
The box is now permanently backdoored. Just Remote Desktop in and at the login screen, hit F5 a bunch of times.
tโs exactly the same as StickyKeys, just trojan utilman.exe instead. At the login screen, press Windows Key+U, and you get a cmd.exe window as SYSTEM.
Group Policy โ use Group Policy to log off disconnected sessions, either immediately or soon after the user disconnects. This will NOT be popular in IT environments โ but the risk is now completely real that they can very easily โ with one built in command โ be hijacked more or less silently in the real world. I would also log off idle sessions.