Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Finding 0-days in Enterprise Application

A tale of ‘Site-wide Account Takeover’Continue reading on InfoSec Write-ups »
Read more...
hacking: security in practice
How does Shodan grab RDP screenshots of Windows machines, post-Server 2003?

Hi folks,

Something I've been curious about is how Shodan manages to grab screenshots of unauthenticated Console sessions ("RDP Screenshots") on machines newer than Server 2003, and how I can do the same from my machine. On Server 2003 and older, you can use the -console flag with mstsc.exe (e.g. mstsc -v:(Hostname or IP Address) -console) to initiate this console session, and present a logon screen as if you were physically at the device, with no authentication needed.

However, this was removed in Server 2008 for obvious security reasons, and trying to use the -console flag to connect to a Server 2008 and later machine is ignored - you are prompted for authentication and if successful enter a standard RDP session.

Does anyone know how Shodan does it? Thanks in advance!

submitted by /u/BloodyGenius
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video