The general idea is we use shodan.io an advanced search engine and Bruteforce RDP w/ default logs.
So:
-
Go to shodan.io or beta.shodan.io create an account using temp mail.
-
Choose one of these queries to search for (just copy paste)
port:“5984”+Server: “CouchDB/2.1.0”
“authentication disabled” “RFB 003.008”
“\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00”
port:“3389”
NOTE: dvrdvs-webs mostly have default passwords
When you get an RDP copy the IP address and try default logins. (ex: admin:admin) or copy this username_list, pass_list in your bruteforcer.
!