robertdavidgraham / rdpscan

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
894 stars 243 forks source link

System reboots when scanned #12

Open tabooki opened 5 years ago

tabooki commented 5 years ago

When scanning a bunch of systems we got a few that came back with the following.

10.xx.28.119 - UNKNOWN - RDP protocol error - receive timeout 10.xx.24.240 - UNKNOWN - RDP protocol error - receive timeout 10.xx.28.228 - UNKNOWN - RDP protocol error - receive timeout 10.xx.26.167 - UNKNOWN - RDP protocol error - receive timeout 10.xx.31.129 - UNKNOWN - RDP protocol error - receive timeout

Tried scanning these a second time and some report back the same while others show a patch status as hoped.

Unfortunately some reboot. Not cool. Any ideas on how to help avoid this?

lgrangeia commented 5 years ago

Can you elaborate? Can you replicate the reboots? Are these windows XP or Windows 7/8?

tabooki commented 5 years ago

Unfortunately I can't help debug this one too much. It was a Windows 7 Japanese language with the RDP patch applied. We were able to replicate it while testing but unfortunately the user was on DHCP and we didn't get his computer name.