Hacker got into server via account who has NO RDP role, how Microsoft?

I

Ivicask

So we where hacked via RDC, hacker managed bruteforce pass of one account, but that account has no role aassigned Remote Desktop Users!


I can still remote into this account even that it doesnt have this role, only domain users rule(which has no RDC acces).

Server is 2012R2 with latest updates!

How?What can i check how this account has RDC rule while it doesnt?

Continue reading...
 
Back
Top Bottom