開始輸入,可搜尋發票、服務、域名、工單,以及 更多...
公網上的 Windows 伺服器開機幾分鐘就會被掃描 3389 埠並嘗試暴力破解,Windows VPS 安全加固是上線後的第一件事。本文適用於 Windows Server 2016/2019/2022,按順序完成:修改管理員強密碼並重新命名、設定帳戶鎖定策略、啟用遠端桌面 NLA、限制只有你的 IP 能連 RDP、關閉不用的服務、確認 Defender 正常,以及用 Get-WinEvent 檢視 4625 失敗登入記錄。
密碼建議 16 位以上,混合大小寫、數字和符號,不要與其他網站共用。暴力破解工具幾乎都以 Administrator 為使用者名稱,重新命名後可以擋掉大部分無差別攻擊。
# Set a new strong password (you will be prompted, nothing is echoed)
net user Administrator *
# Rename the built-in Administrator account
Rename-LocalUser -Name "Administrator" -NewName "srvadmin"
Get-LocalUser | Format-Table Name,Enabled,LastLogon帳戶鎖定策略可以讓連續輸錯密碼的帳戶暫時鎖定,顯著拖慢暴力破解。也可在 secpol.msc → 帳戶策略 → 帳戶鎖定策略 中圖形化設定。
# Lock an account for 30 minutes after 5 failed attempts within 30 minutes
net accounts /lockoutthreshold:5 /lockoutduration:30 /lockoutwindow:30
net accountsNLA 要求在建立完整遠端桌面會話之前先完成身份驗證,可減少未認證連線對伺服器資源的佔用,也能防禦部分 RDP 漏洞。在“系統屬性 → 遠端”中勾選“僅允許執行使用網路級別身份驗證的遠端桌面的計算機連線”,或執行:
$rdp = "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp"
Set-ItemProperty -Path $rdp -Name UserAuthentication -Value 1
Get-ItemProperty -Path $rdp -Name UserAuthentication, PortNumber這是防爆破效果最好的一步。下面修改系統內建的遠端桌面防火牆規則,只放行你的辦公 IP 或網段。規則名稱在中文、英文等各語言系統上都一致。如果你修改過 RDP 埠並新建了自定義規則,請對自定義規則同樣設定 -RemoteAddress。
# Built-in Remote Desktop rules (names are the same on every OS language)
Set-NetFirewallRule -Name RemoteDesktop-UserMode-In-TCP, RemoteDesktop-UserMode-In-UDP -RemoteAddress 203.0.113.10, 198.51.100.0/24
Get-NetFirewallRule -Name RemoteDesktop-UserMode-In-TCP | Get-NetFirewallAddressFilter
# Undo: allow RDP from anywhere again
Set-NetFirewallRule -Name RemoteDesktop-UserMode-In-TCP, RemoteDesktop-UserMode-In-UDP -RemoteAddress Any每個執行中的服務都是潛在的攻擊面。先列出正在執行的服務,確認用途後再停用。列印後臺處理程式(Spooler)在伺服器上通常用不到,且歷史上出現過嚴重漏洞。不確定用途的系統服務不要隨意關閉。
Get-Service | Where-Object { $_.Status -eq "Running" } | Sort-Object DisplayName | Format-Table Name,DisplayName
# Example: print spooler is rarely needed on a server
Stop-Service -Name Spooler
Set-Service -Name Spooler -StartupType DisabledWindows Server 2016 及以上自帶 Microsoft Defender 防病毒。確認即時保護已開啟、病毒庫為最新,並執行一次快速掃描。
Get-MpComputerStatus | Select-Object AMServiceEnabled,RealTimeProtectionEnabled,AntivirusSignatureLastUpdated
Set-MpPreference -DisableRealtimeMonitoring $false
Update-MpSignature
Start-MpScan -ScanType QuickScan事件 ID 4625 表示一次失敗的登入。下面的命令可以列出最近的失敗登入,以及過去 24 小時嘗試次數最多的來源 IP,方便判斷是否正在被暴力破解,並把可疑 IP 加入防火牆阻止規則。
# Make sure failed logons are audited (GUID = "Logon" subcategory, language independent)
auditpol /set /subcategory:"{0CCE9215-69AE-11D9-BED3-505054503030}" /failure:enable
# Last 20 failed logons
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} -MaxEvents 20 |
Select-Object TimeCreated, @{n='User';e={$_.Properties[5].Value}}, @{n='SourceIP';e={$_.Properties[19].Value}}
# Top attacking IPs in the last 24 hours
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} |
ForEach-Object { $_.Properties[19].Value } | Group-Object | Sort-Object Count -Descending |
Select-Object -First 10 Count, Name改埠能減少自動掃描的噪音,但不能替代強密碼和 IP 限制。三者配合效果最好,改埠方法見“Windows 修改遠端桌面埠”教程。
可以放行運營商的整個網段,或通過一台固定 IP 的跳板機 / VPN 登入,再從那裡連線遠端桌面。
一般是本地登入或 NLA 階段未能記錄來源地址。若大量出現,可結合防火牆日誌一起分析。
如按以上步驟仍無法解決,請提交工單聯絡 IMIDC 7×24 技術支援,並附上伺服器 IP、作業系統版本、執行過的命令和報錯截圖,方便工程師快速定位問題。