{"id":41229,"date":"2020-02-06T20:43:00","date_gmt":"2020-02-06T17:43:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/opasno-li-derzhat-otkrytym-rdp-v-internete"},"modified":"2020-02-06T20:43:00","modified_gmt":"2020-02-06T17:43:00","slug":"opasno-li-derzhat-otkrytym-rdp-v-internete","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/opasno-li-derzhat-otkrytym-rdp-v-internete","title":{"rendered":"\u00c8 pericoloso mantenere aperto RDP su Internet?","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u041d\u0435\u0440\u0435\u0434\u043a\u043e \u044f \u0447\u0438\u0442\u0430\u043b \u043c\u043d\u0435\u043d\u0438\u0435, \u0447\u0442\u043e \u0434\u0435\u0440\u0436\u0430\u0442\u044c RDP (Remote Desktop Protocol) \u043f\u043e\u0440\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u2014 \u044d\u0442\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e, \u0438 \u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a \u043d\u0435 \u043d\u0430\u0434\u043e. \u0410 \u043d\u0430\u0434\u043e \u0434\u043e\u0441\u0442\u0443\u043f \u043a RDP \u0434\u0430\u0432\u0430\u0442\u044c \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 VPN, \u0438\u043b\u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 &quot;\u0431\u0435\u043b\u044b\u0445&quot; IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432.<\/p>\n<p><\/p>\n<p>Amministro diversi server Windows per piccole aziende, dove mi \u00e8 stato chiesto di garantire l'accesso remoto ai server Windows per i contabili. \u00c8 una tendenza moderna: lavorare da casa. Ho rapidamente capito che costringere i contabili a utilizzare una VPN \u00e8 un compito ingrato, e non \u00e8 possibile raccogliere tutti gli IP per la white list, perch\u00e9 gli indirizzi IP delle persone sono dinamici.<\/p>\n<p><\/p>\n<p>Perci\u00f2 ho scelto la soluzione pi\u00f9 semplice: ho esposto il port RDP all'esterno. Ora, per accedere, i contabili devono avviare RDP e inserire il nome host (incluso il port), il nome utente e la password.<\/p>\n<p><\/p>\n<p>In questo articolo condivider\u00f2 la mia esperienza (sia positiva che negativa) e alcune raccomandazioni.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Rischi<\/h3>\n<p><\/p>\n<p>Quali rischi si corrono aprendo il port RDP?<\/p>\n<p><\/p>\n<p><b>1) Accesso non autorizzato a dati sensibili<\/b><br \/>\n\u0415\u0441\u043b\u0438 \u043a\u0442\u043e-\u0442\u043e \u043f\u043e\u0434\u0431\u0435\u0440\u0451\u0442 \u043f\u0430\u0440\u043e\u043b\u044c \u043a RDP, \u0442\u043e \u043e\u043d \u0441\u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0435, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b \u0445\u043e\u0442\u0438\u0442\u0435 \u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u044b\u043c\u0438: \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0441\u0447\u0435\u0442\u043e\u0432, \u0431\u0430\u043b\u0430\u043d\u0441\u044b, \u0434\u0430\u043d\u043d\u044b\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432, &#8230;<\/p>\n<p><\/p>\n<p><b>2) Perdita di dati<\/b><br \/>\nAd esempio, a causa dell'azione di un virus di crittografia.<br \/>\nO per azioni mirate di un malintenzionato.<\/p>\n<p><\/p>\n<p><b>3) Perdita della stazione di lavoro<\/b><br \/>\nI dipendenti devono lavorare, ma il sistema \u00e8 compromesso e necessita di reinstallazione \/ ripristino \/ configurazione.<\/p>\n<p><\/p>\n<p><b>4) Compromesso della rete locale<\/b><br \/>\nSe un malintenzionato ha accesso a un computer Windows, pu\u00f2 accedere a sistemi inaccessibili dall'esterno, da Internet. Ad esempio, a condivisioni di file, stampanti di rete, ecc.<\/p>\n<p>\n<b class=\"spoiler_title\">Ho avuto un caso in cui un Windows Server \u00e8 stato infettato da un software di crittografia<\/b><\/p>\n<p>e questo software ha inizialmente criptato la maggior parte dei file sul disco C:, poi ha iniziato a criptare i file su NAS attraverso la rete. Poich\u00e9 il NAS era un Synology con snapshot configurati, ho ripristinato il NAS in 5 minuti, mentre il Windows Server l'ho reinstallato da zero.<\/p>\n<p><\/p>\n<h3>Osservazioni e Raccomandazioni<\/h3>\n<p><\/p>\n<p>Monitoro i server Windows utilizzando <noindex><a rel=\"nofollow\" href=\"https:\/\/www.elastic.co\/beats\/winlogbeat\">Winlogbeat<\/a><\/noindex>, che invia i log a ElasticSearch. In Kibana ci sono diverse visualizzazioni e ho anche impostato un dashboard personalizzato.<br \/>\nIl monitoraggio di per s\u00e9 non protegge, ma aiuta a determinare le misure necessarie.<\/p>\n<p><\/p>\n<p>Ecco alcune osservazioni:<br \/>\n<b>a) RDP verr\u00e0 attaccato con brute force.<\/b><br \/>\nSu uno dei server ho impostato RDP non sulla porta standard 3389, ma sulla 443 \u2014 per mimetizzarmi come HTTPS. Cambiare la porta da quella standard \u00e8 probabilmente una buona idea, ma l'effetto \u00e8 limitato. Ecco le statistiche di questo server:<\/p>\n<p>\n<img decoding=\"async\" alt=\"\u00c8 pericoloso mantenere aperto RDP su Internet?\" src=\"\/wp-content\/uploads\/2020\/02\/6f7fccd9378d323b67a6186bde54fc2c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Si pu\u00f2 vedere che in una settimana ci sono stati quasi 400.000 tentativi falliti di accesso tramite RDP.<br \/>\nSi nota che i tentativi di accesso sono provenuti da 55.001 indirizzi IP (alcuni indirizzi IP erano gi\u00e0 stati bloccati da me).<\/p>\n<p><\/p>\n<p>Qui si pu\u00f2 trarre la conclusione che sia necessario installare fail2ban, ma <\/p>\n<p>\n<b class=\"spoiler_title\">\u0434\u043b\u044f Windows \u0442\u0430\u043a\u043e\u0439 \u0443\u0442\u0438\u043b\u0438\u0442\u044b &#8212; \u043d\u0435\u0442\u0443.<\/b><\/p>\n<p>Ci sono un paio di progetti abbandonati su GitHub che sembrano farlo, ma non li ho nemmeno provati:<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/glasnt\/wail2ban\">https:\/\/github.com\/glasnt\/wail2ban<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/EvanAnderson\/ts_block\">https:\/\/github.com\/EvanAnderson\/ts_block<\/a><\/noindex><\/p>\n<p><\/p>\n<p>Ci sono anche utility a pagamento, ma non le ho prese in considerazione.<\/p>\n<p><\/p>\n<p>Se conoscete un'utility aperta per questo scopo \u2014 condividete nei commenti.<\/p>\n<p><\/p>\n<p><strong>Update<\/strong>: Nei commenti \u00e8 stato fatto notare che la porta 443 \u00e8 una scelta poco efficace, e sarebbe meglio scegliere porte alte (32000+), perch\u00e9 la 443 viene scansionata pi\u00f9 frequentemente, e riconoscere RDP su quella porta non \u00e8 un problema.<\/p>\n<p><\/p>\n<p><strong>Aggiornamento:<\/strong> Nei commenti \u00e8 stato fatto notare che esiste un'utility di questo tipo:<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/digitalruby\/ipban\">https:\/\/github.com\/digitalruby\/ipban<\/a><\/noindex><\/p>\n<p><\/p>\n<p><b>b) Ci sono determinati username che i malintenzionati preferiscono.<\/b><br \/>\n\u00c8 evidente che si sta effettuando un attacco basato su un dizionario con nomi diversi.<br \/>\nMa quello che ho notato \u00e8 che una parte significativa dei tentativi utilizza il nome del server come login. Raccomandazione: non utilizzare lo stesso nome per il computer e per l'utente. Inoltre, a volte il nome del server sembra essere in qualche modo analizzato: ad esempio, per un sistema con il nome DESKTOP-DFTHD7C, ci sono stati pi\u00f9 tentativi di accesso con il nome DFTHD7C.<\/p>\n<p>\n<img decoding=\"async\" alt=\"\u00c8 pericoloso mantenere aperto RDP su Internet?\" src=\"\/wp-content\/uploads\/2020\/02\/cd13cf169b3b9ed57db9e5706c735c06.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Di conseguenza, se avete un computer chiamato DESKTOP-MARIA, \u00e8 probabile che ci siano tentativi di accesso con l'username MARIA.<\/p>\n<p><\/p>\n<p>\u0415\u0449\u0451, \u0447\u0442\u043e \u044f \u0437\u0430\u043c\u0435\u0442\u0438\u043b \u0438\u0437 \u043b\u043e\u0433\u043e\u0432: \u043d\u0430 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0435 \u0441\u0438\u0441\u0442\u0435\u043c, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u043f\u043e\u043f\u044b\u0442\u043e\u043a \u0437\u0430\u0439\u0442\u0438 \u2014 \u044d\u0442\u043e \u0441 \u0438\u043c\u0435\u043d\u0435\u043c &quot;administrator&quot;. \u0418 \u044d\u0442\u043e \u043d\u0435\u0441\u043f\u0440\u043e\u0441\u0442\u0430, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 Windows, \u044d\u0442\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442. \u0411\u043e\u043b\u0435\u0435 \u0442\u043e\u0433\u043e \u2014 \u0435\u0433\u043e \u043d\u0435\u043b\u044c\u0437\u044f \u0443\u0434\u0430\u043b\u0438\u0442\u044c. \u042d\u0442\u043e \u0443\u043f\u0440\u043e\u0449\u0430\u0435\u0442 \u0437\u0430\u0434\u0430\u0447\u0443 \u0434\u043b\u044f \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u0432: \u0432\u043c\u0435\u0441\u0442\u043e \u043f\u043e\u0434\u0431\u043e\u0440\u0430 \u0438\u043c\u0435\u043d\u0438 \u0438 \u043f\u0430\u0440\u043e\u043b\u044f \u043d\u0443\u0436\u043d\u043e \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u0434\u043e\u0431\u0440\u0430\u0442\u044c \u043f\u0430\u0440\u043e\u043b\u044c.<br \/>\nA proposito, il sistema che ha catturato il ransomware aveva l'utente Administrator e la password Murmansk#9. Non sono ancora sicuro di come abbiano compromesso quel sistema, perch\u00e9 ho iniziato a monitorare proprio dopo quel caso, ma penso che un attacco a forza bruta sia probabile.<br \/>\nSe l'utente Administrator non pu\u00f2 essere eliminato, cosa si pu\u00f2 fare? Pu\u00f2 essere rinominato!<\/p>\n<p><\/p>\n<p>Le raccomandazioni di questo punto: <\/p>\n<p><\/p>\n<ul>\n<li>non utilizzare il nome utente nel nome del computer<\/li>\n<li>assicurati che nel sistema non ci sia l'utente Administrator<\/li>\n<li>usa password robuste<\/li>\n<\/ul>\n<p><\/p>\n<p>Cos\u00ec, ho monitorato come alcuni Windows Server sotto il mio controllo siano stati attaccati con forza bruta per circa un paio d'anni, senza successo.<\/p>\n<p><\/p>\n<p>Come lo so, che non hanno avuto successo?<br \/>\nPerch\u00e9 negli screenshot sopra si vede che ci sono registri di accessi riusciti via RDP, che contengono informazioni:<\/p>\n<p><\/p>\n<ul>\n<li>da quale IP<\/li>\n<li>da quale computer (hostname)<\/li>\n<li>nome utente<\/li>\n<li>Informazioni GeoIP<\/li>\n<\/ul>\n<p><\/p>\n<p>E controllo regolarmente \u2014 non ho riscontrato anomalie.<\/p>\n<p><\/p>\n<p>A proposito, se da un certo IP stanno forzando con particolare impegno, puoi bloccare singoli IP (o sottoreti) in questo modo in PowerShell:<\/p>\n<p><\/p>\n<pre><code class=\"powershell\">New-NetFirewallRule -Direction Inbound -DisplayName &quot;fail2ban&quot; -Name &quot;fail2ban&quot; -RemoteAddress (&quot;185.143.0.0\/16&quot;, &quot;185.153.0.0\/16&quot;, &quot;193.188.0.0\/16&quot;) -Action Block<\/code><\/pre>\n<p><\/p>\n<p>A proposito, in Elastic, oltre a Winlogbeat, c'\u00e8 anche <noindex><a rel=\"nofollow\" href=\"https:\/\/www.elastic.co\/beats\/auditbeat\">Auditbeat<\/a><\/noindex>, che pu\u00f2 monitorare file e processi nel sistema. C'\u00e8 anche un'applicazione SIEM (Gestione delle Informazioni e degli Eventi di Sicurezza) in Kibana. Ho provato entrambe le cose, ma non ho notato molti vantaggi \u2014 sembra che Auditbeat sia pi\u00f9 utile per i sistemi Linux, mentre SIEM finora non mi ha mostrato nulla di concreto.<\/p>\n<p><\/p>\n<p>E infine, alcune raccomandazioni:<\/p>\n<p><\/p>\n<ul>\n<li>effettuate regolari backup automatici.<\/li>\n<li>installate tempestivamente gli aggiornamenti di sicurezza.<\/li>\n<\/ul>\n<p>\n<b class=\"spoiler_title\">Bonus: elenco di 50 utenti utilizzati pi\u00f9 frequentemente per tentativi di accesso RDP.<\/b><\/p>\n<p>&quot;user.name: Descending&quot;<br \/>\nConteggio<\/p>\n<p>dfthd7c (hostname)<br \/>\n842941<\/p>\n<p>winsrv1 (hostname)<br \/>\n266525<\/p>\n<p>AMMINISTRATORE<br \/>\n180678<\/p>\n<p>amministratore<br \/>\n163842<\/p>\n<p>Amministratore<br \/>\n53541<\/p>\n<p>michael<br \/>\n23101<\/p>\n<p>server<br \/>\n21983<\/p>\n<p>steve<br \/>\n21936<\/p>\n<p>john<br \/>\n21927<\/p>\n<p>paul<br \/>\n21913<\/p>\n<p>reception<br \/>\n21909<\/p>\n<p>mike<br \/>\n21899<\/p>\n<p>office<br \/>\n21888<\/p>\n<p>scanner<br \/>\n21887<\/p>\n<p>scan<br \/>\n21867<\/p>\n<p>david<br \/>\n21865<\/p>\n<p>chris<br \/>\n21860<\/p>\n<p>proprietario<br \/>\n21855<\/p>\n<p>manager<br \/>\n21852<\/p>\n<p>administrateur<br \/>\n21841<\/p>\n<p>brian<br \/>\n21839<\/p>\n<p>administrador<br \/>\n21837<\/p>\n<p>mark<br \/>\n21824<\/p>\n<p>staff<br \/>\n21806<\/p>\n<p>ADMIN<br \/>\n12748<\/p>\n<p>ROOT<br \/>\n7772<\/p>\n<p>ADMINISTRADOR<br \/>\n7325<\/p>\n<p>SUPPORT<br \/>\n5577<\/p>\n<p>SOPORTE<br \/>\n5418<\/p>\n<p>UTENTE<br \/>\n4558<\/p>\n<p>admin<br \/>\n2832<\/p>\n<p>TEST<br \/>\n1928<\/p>\n<p>MySql<br \/>\n1664<\/p>\n<p>Admin<br \/>\n1652<\/p>\n<p>OSPITE<br \/>\n1322<\/p>\n<p>USER1<br \/>\n1179<\/p>\n<p>SCANNER<br \/>\n1121<\/p>\n<p>SCAN<br \/>\n1032<\/p>\n<p>ADMINISTRATEUR<br \/>\n842<\/p>\n<p>ADMIN1<br \/>\n525<\/p>\n<p>BACKUP<br \/>\n518<\/p>\n<p>MySqlAdmin<br \/>\n518<\/p>\n<p>RECEPTION<br \/>\n490<\/p>\n<p>USER2<br \/>\n466<\/p>\n<p>TEMP<br \/>\n452<\/p>\n<p>SQLADMIN<br \/>\n450<\/p>\n<p>USER3<br \/>\n441<\/p>\n<p>1<br \/>\n422<\/p>\n<p>MANAGER<br \/>\n418<\/p>\n<p>PROPRIETARIO<br \/>\n410<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/487056\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0440\u0435\u0434\u043a\u043e \u044f \u0447\u0438\u0442\u0430\u043b \u043c\u043d\u0435\u043d\u0438\u0435, \u0447\u0442\u043e \u0434\u0435\u0440\u0436\u0430\u0442\u044c RDP (Remote Desktop Protocol) \u043f\u043e\u0440\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u2014 \u044d\u0442\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e, \u0438 \u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a \u043d\u0435 \u043d\u0430\u0434\u043e. \u0410 \u043d\u0430\u0434\u043e \u0434\u043e\u0441\u0442\u0443\u043f \u043a RDP \u0434\u0430\u0432\u0430\u0442\u044c \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 VPN, \u0438\u043b\u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 &quot;\u0431\u0435\u043b\u044b\u0445&quot; IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u042f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u0443\u044e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e Windows Server \u0434\u043b\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u0438\u0445 \u0444\u0438\u0440\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043d\u0435 \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u043b\u0438 \u0437\u0430\u0434\u0430\u0447\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":41230,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0440\u0435\u0434\u043a\u043e \u044f \u0447\u0438\u0442\u0430\u043b \u043c\u043d\u0435\u043d\u0438\u0435, \u0447\u0442\u043e \u0434\u0435\u0440\u0436\u0430\u0442\u044c RDP (Remote Desktop Protocol) \u043f\u043e\u0440\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u2014 \u044d\u0442\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e, \u0438 \u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a \u043d\u0435 \u043d\u0430\u0434\u043e. \u0410 \u043d\u0430\u0434\u043e \u0434\u043e\u0441\u0442\u0443\u043f \u043a RDP \u0434\u0430\u0432\u0430\u0442\u044c \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 VPN, \u0438\u043b\u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 &quot;\u0431\u0435\u043b\u044b\u0445&quot; IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u042f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u0443\u044e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e Windows Server \u0434\u043b\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u0438\u0445 \u0444\u0438\u0440\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043d\u0435 \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u043b\u0438 \u0437\u0430\u0434\u0430\u0447\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/opasno-li-derzhat-otkrytym-rdp-v-internete\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u043e \u043b\u0438 \u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c RDP \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0435? | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0440\u0435\u0434\u043a\u043e \u044f \u0447\u0438\u0442\u0430\u043b \u043c\u043d\u0435\u043d\u0438\u0435, \u0447\u0442\u043e \u0434\u0435\u0440\u0436\u0430\u0442\u044c RDP (Remote Desktop Protocol) \u043f\u043e\u0440\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u2014 \u044d\u0442\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e, \u0438 \u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a \u043d\u0435 \u043d\u0430\u0434\u043e. \u0410 \u043d\u0430\u0434\u043e \u0434\u043e\u0441\u0442\u0443\u043f \u043a RDP \u0434\u0430\u0432\u0430\u0442\u044c \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 VPN, \u0438\u043b\u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 &quot;\u0431\u0435\u043b\u044b\u0445&quot; IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u042f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u0443\u044e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e Windows Server \u0434\u043b\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u0438\u0445 \u0444\u0438\u0440\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043d\u0435 \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u043b\u0438 \u0437\u0430\u0434\u0430\u0447\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/opasno-li-derzhat-otkrytym-rdp-v-internete\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-02-06T17:43:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-06T17:43:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c8 pericoloso tenere aperto RDP su Internet? | ProHoster","description":"Spesso ho letto opinioni secondo cui tenere aperto il port RDP (Remote Desktop Protocol) su Internet \u00e8 molto insicuro e non si dovrebbe fare. \u00c8 consigliabile fornire accesso a RDP solo tramite VPN o solo da determinati indirizzi IP \"bianchi\". Amministro diversi Windows Server per piccole aziende, dove mi \u00e8 stato richiesto di garantire l'accesso remoto.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/opasno-li-derzhat-otkrytym-rdp-v-internete","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0430\u0441\u043d\u043e \u043b\u0438 \u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c RDP \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0435? | ProHoster","og:description":"\u041d\u0435\u0440\u0435\u0434\u043a\u043e \u044f \u0447\u0438\u0442\u0430\u043b \u043c\u043d\u0435\u043d\u0438\u0435, \u0447\u0442\u043e \u0434\u0435\u0440\u0436\u0430\u0442\u044c RDP (Remote Desktop Protocol) \u043f\u043e\u0440\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u043c \u0432 \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u2014 \u044d\u0442\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e, \u0438 \u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a \u043d\u0435 \u043d\u0430\u0434\u043e. \u0410 \u043d\u0430\u0434\u043e \u0434\u043e\u0441\u0442\u0443\u043f \u043a RDP \u0434\u0430\u0432\u0430\u0442\u044c \u0438\u043b\u0438 \u0447\u0435\u0440\u0435\u0437 VPN, \u0438\u043b\u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 &quot;\u0431\u0435\u043b\u044b\u0445&quot; IP \u0430\u0434\u0440\u0435\u0441\u043e\u0432. \u042f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u0443\u044e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e Windows Server \u0434\u043b\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u0438\u0445 \u0444\u0438\u0440\u043c, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043d\u0435 \u043f\u043e\u0441\u0442\u0430\u0432\u0438\u043b\u0438 \u0437\u0430\u0434\u0430\u0447\u0443 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f","og:url":"https:\/\/prohoster.info\/it\/blog\/opasno-li-derzhat-otkrytym-rdp-v-internete","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-02-06T17:43:00+00:00","article:modified_time":"2020-02-06T17:43:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"41229","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:21:32","updated":"2022-09-28 03:38:38"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/41229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=41229"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/41229\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/41230"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=41229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=41229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=41229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}