You know the CVE-2019-0708 is around and everyone is looking for a PoC, and I followed this article to do some workaround to harden my old windows server. Yes, I enabled NLA. The NLA is working. But after a reboot, the NLA is not working properly, I was disconnected from server immediately after enter the password and click ok. There is no message pop up I just got disconnected. Weird.
I can give you a Wireshark capture packets if needed.
You can take a glimpse of what is going on. With password auto fill. Wireshark Captured Packets
So what is going on? I am not familiar with windows and really don't know why... And the worst thing is that I can't connect to it now because it is really a remote server...T_T...
I got following error log, too:
[I] RDP ClientActiveX is trying to connect to the server (srv1.domain.com)
[I] Server supports SSL = supported
[I]Base64(SHA256(UserName)) is = -
[W] RDPClient_SSL: An error was encountered when transitioning from TsSslStateHandshakeInProgress to TsSslStateDisconnecting in response to TsSslEventHandshakeContinueFailed (error code 0x80004005)
[I] The multi-transport connection has been disconnected.
[I] RDP ClientActiveX has been disconnected (Reason = xx)
[I] The multi-transport connection has been disconnected.