[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLG7hnB8DW0pS3qPvH1vTsRwJlfPDAq88wZ-b-TdEm5I":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},902,"What is rdpwrap and how does it enable multi-user RDP without modifying system files?","rdpwrap is a tool from GitHub (stascorp\u002Frdpwrap) that supports multi-user remote desktop on Windows Vista through 10 without altering `termsrv.dll`. It works by injecting its own `rdpwrap.dll` into the same process, passing different parameters to the service. To install, run `RDPWInst.exe -i`; to uninstall, use `-u`. This method is ideal for penetration testing where you want to avoid permanent system changes. Learn more about this and related techniques in the full article.","\u003Cp>rdpwrap is a tool from GitHub (stascorp\u002Frdpwrap) that supports multi-user remote desktop on Windows Vista through 10 without altering `termsrv.dll`. It works by injecting its own `rdpwrap.dll` into the same process, passing different parameters to the service. To install, run `RDPWInst.exe -i`; to uninstall, use `-u`. This method is ideal for penetration testing where you want to avoid permanent system changes. Learn more about this and related techniques in the full article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-multi-user-login-for-windows-remote-desktop\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-rdpwrap-and-how-does-it-enable-multi-user-rdp-without-modifying-system-f-1777481426257","rdpwrap, RDP wrapper, multi-user, remote desktop, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},219,"Penetration Techniques - Multi-user Login for Windows Remote Desktop","penetration-techniques-multi-user-login-for-windows-remote-desktop","Learn how to enable multi-user remote desktop on non-server Windows systems using mimikatz and registry tweaks for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, we often encounter Windows server remote desktop services, managing servers through the interface. For regular Windows systems, interface operations are also required under certain conditions.\u003C\u002Fp>\u003Cp>Although we can achieve interface operations by writing programs (capturing desktop information, compressing transmission, sending mouse and keyboard messages, etc.), wouldn't it be more convenient and efficient if we could use remote desktop services?\u003C\u002Fp>\u003Cp>So, for non-server versions of Windows systems, what issues should be noted when using remote desktop services? This article will analyze and introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to enable remote desktop\u003C\u002Fli>\u003Cli>Principles of using mimikatz to support multi-user remote desktop\u003C\u002Fli>\u003Cli>Improvement ideas\u003C\u002Fli>\u003Cli>Testing tool rdpwrap\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to enable remote desktop\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check if the system allows 3389 remote connection\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>1 indicates disabled, 0 indicates enabled\u003C\u002Fp>\u003Cp>Check the port for remote connection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Port format is hexadecimal, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017360465_0_ab76ea84b7.jpeg\">\u003C\u002Fp>\u003Cp>0xd3d converted to decimal is 33389\u003C\u002Fp>\u003Ch3>2. Methods to enable 3389 remote connection on the local machine\u003C\u002Fh3>\u003Ch4>Method 1: Via cmd\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method 2: Via reg file\u003C\u002Fh4>\u003Cp>Content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server]\u003Cbr>\"fDenyTSConnections\"=dword:00000000\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp]\u003Cbr>\"PortNumber\"=dword:00000d3d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Import registry file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs a.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the connection port is modified, it will take effect only after the system restarts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the remote desktop service has not been configured on the system, when enabling it for the first time, you also need to add a firewall rule to allow port 3389, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017389207_1_e448e7f54d.jpeg\">\u003C\u002Fp>\u003Cp>The command to modify firewall configuration and allow port 3389 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"Remote Desktop\" protocol=TCP dir=in localport=3389 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Remote connection method\u003C\u002Fh3>\u003Cp>Using Kali to connect remotely via 3389:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rdesktop 192.168.1.1:3389\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Windows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Non-server versions of Windows systems by default only allow one account to log in\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific manifestations are:\u003C\u002Fp>\u003Cp>When logging in remotely using the same account as the original system, the original system will be switched to the login screen\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017413912_2_87606c6af3.jpeg\">\u003C\u002Fp>\u003Cp>When using a different account, a prompt appears during login indicating that another user is already logged into this computer, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017460391_3_5dbca3a029.jpeg\">\u003C\u002Fp>\u003Cp>After selecting to continue, a dialog box will pop up on the original system desktop asking whether to disconnect the current connection (after 30 seconds, consent is selected by default, returning to the login screen)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017476725_4_7194109b57.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for enabling multi-user login on non-server versions of Windows systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using mimikatz\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>ts::multirdp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017486943_5_0eb967575c.jpeg\">\u003C\u002Fp>\u003Cp>Enable multi-user login functionality, with support up to Windows 7\u003C\u002Fp>\u003Cp>\u003Cstrong>Using the same account as the original system, the original system will still be switched to the login screen\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using a different account than the original system, login successful, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017497002_6_4bbacd0654.jpeg\">\u003C\u002Fp>\u003Cp>Find modification ideas by reviewing the source code of mimikatz, code location as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_ts.c\u003C\u002Fp>\u003Cp>When Windows enables the Remote Desktop Services service, it loads termsrv.dll, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017505797_7_1caea7ed30.jpeg\">\u003C\u002Fp>\u003Cp>Enable multi-user functionality by modifying termsrv.dll in memory, specific operations as follows:\u003C\u002Fp>\u003Cp>Win7 x86:\u003C\u002Fp>\u003Cp>Find: 0x3B86200300000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC78620030000FFFFFF7F9090\u003C\u002Fp>\u003Cp>Win7 x64:\u003C\u002Fp>\u003Cp>Find: 0x39873C0600000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC7873C060000FFFFFF7F9090\u003C\u002Fp>\u003Cp>However, this method becomes ineffective after a system reboot.\u003C\u002Fp>\u003Cp>Further, if we directly modify the file termsrv.dll, can we achieve the permanent activation of multi-user login functionality?\u003C\u002Fp>\u003Cp>Proceed with the following test.\u003C\u002Fp>\u003Ch3>2. Modify termsrv.dll\u003C\u002Fh3>\u003Cp>Recommended tool: CFF Explorer\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>Open termsrv.dll located at c:\\windows\\system32\u003C\u002Fp>\u003Cp>Hex Editor\u003C\u002Fp>\u003Cp>View hexadecimal data 39873C0600000F84\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017511237_8_c8fea4ece3.jpeg\">\u003C\u002Fp>\u003Cp>Starting from address 0x0001738A, select 12 bytes and replace them with C7873C060000FFFFFF7F9090\u003C\u002Fp>\u003Cp>Save the dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Services must be stopped before replacing termsrv.dll\u003C\u002Fp>\u003Cp>After replacing termsrv.dll, restart the TermService service\u003C\u002Fp>\u003Cp>Attempt to connect remotely using different users, successful, verifying that this approach is correct\u003C\u002Fp>\u003Cp>Complete steps are as follows:\u003C\u002Fp>\u003Cp>1. Check the status of the Remote Desktop Services service\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc qc TermService\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. If the service is running, stop it first\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net stop TermService \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Delete the original termsrv.dll\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del c:\\windows\\system32\\termsrv.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Replace the new termsrv.dll\u003C\u002Fp>\u003Cp>5. Start the service\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start TermService\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>6. Remote connection\u003C\u002Fp>\u003Cp>Successfully implemented multi-user login\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x86:\u003C\u002Fp>\u003Cp>Find: 0x3B86200300000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC78620030000FFFFFF7F9090\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 2\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Common Windows system version numbers:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>System\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>Version Number\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win7\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.1.7600\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win7sp1\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.1.7601\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win8\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.2.9200\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win8.1\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.3.9600\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Using the tool rdpwrap\u003C\u002Fh3>\u003Cp>Project address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstascorp\u002Frdpwrap\u003C\u002Fp>\u003Cp>Tool address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstascorp\u002Frdpwrap\u002Freleases\u003C\u002Fp>\u003Cp>Supports Win Vista - Win 10\u003C\u002Fp>\u003Cp>Does not modify termsrv.dll, achieved by passing different parameters\u003C\u002Fp>\u003Cp>Installation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RDPWInst.exe -i is\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017517165_9_b72a9abeb3.jpeg\">\u003C\u002Fp>\u003Cp>Release rdpwrap.dll and rdpwrap.ini to the System32 folder\u003C\u002Fp>\u003Cp>rdpwrap.dll will be loaded into the same process as termsrv.dll\u003C\u002Fp>\u003Cp>At this point, remote connections can be made using different users\u003C\u002Fp>\u003Cp>Uninstall:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RDPWInst.exe -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three methods to support multi-user remote desktop login, applicable under different conditions. For the termsrv.dll replacement method, different replacement locations must be used depending on the specific system version.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, we often encounter Windows server remote desktop services, managing servers through the interface. For regular Windows systems, interface operations are also required under certain conditions.\u003C\u002Fp>\u003Cp>Although we can achieve interface operations by writing programs (capturing desktop information, compressing transmission, sending mouse and keyboard messages, etc.), wouldn't it be more convenient and efficient if we could use remote desktop services?\u003C\u002Fp>\u003Cp>So, for non-server versions of Windows systems, what issues should be noted when using remote desktop services? This article will analyze and introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to enable remote desktop\u003C\u002Fli>\u003Cli>Principles of using mimikatz to support multi-user remote desktop\u003C\u002Fli>\u003Cli>Improvement ideas\u003C\u002Fli>\u003Cli>Testing tool rdpwrap\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to enable remote desktop\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check if the system allows 3389 remote connection\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>1 indicates disabled, 0 indicates enabled\u003C\u002Fp>\u003Cp>Check the port for remote connection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Port format is hexadecimal, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017360465_0_ab76ea84b7-1.jpeg\">\u003C\u002Fp>\u003Cp>0xd3d converted to decimal is 33389\u003C\u002Fp>\u003Ch3>2. Methods to enable 3389 remote connection on the local machine\u003C\u002Fh3>\u003Ch4>Method 1: Via cmd\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method 2: Via reg file\u003C\u002Fh4>\u003Cp>Content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Windows Registry Editor Version 5.00\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server]\u003Cbr>\"fDenyTSConnections\"=dword:00000000\u003Cbr>[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp]\u003Cbr>\"PortNumber\"=dword:00000d3d\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Import registry file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs a.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the connection port is modified, it will take effect only after the system restarts.\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the remote desktop service has not been configured on the system, when enabling it for the first time, you also need to add a firewall rule to allow port 3389, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017389207_1_e448e7f54d-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to modify firewall configuration and allow port 3389 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"Remote Desktop\" protocol=TCP dir=in localport=3389 action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Remote connection method\u003C\u002Fh3>\u003Cp>Using Kali to connect remotely via 3389:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rdesktop 192.168.1.1:3389\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Windows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Non-server versions of Windows systems by default only allow one account to log in\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific manifestations are:\u003C\u002Fp>\u003Cp>When logging in remotely using the same account as the original system, the original system will be switched to the login screen\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017413912_2_87606c6af3-1.jpeg\">\u003C\u002Fp>\u003Cp>When using a different account, a prompt appears during login indicating that another user is already logged into this computer, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017460391_3_5dbca3a029-1.jpeg\">\u003C\u002Fp>\u003Cp>After selecting to continue, a dialog box will pop up on the original system desktop asking whether to disconnect the current connection (after 30 seconds, consent is selected by default, returning to the login screen)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017476725_4_7194109b57-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Methods for enabling multi-user login on non-server versions of Windows systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using mimikatz\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>ts::multirdp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017486943_5_0eb967575c-1.jpeg\">\u003C\u002Fp>\u003Cp>Enable multi-user login functionality, with support up to Windows 7\u003C\u002Fp>\u003Cp>\u003Cstrong>Using the same account as the original system, the original system will still be switched to the login screen\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using a different account than the original system, login successful, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017497002_6_4bbacd0654-1.jpeg\">\u003C\u002Fp>\u003Cp>Find modification ideas by reviewing the source code of mimikatz, code location as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_ts.c\u003C\u002Fp>\u003Cp>When Windows enables the Remote Desktop Services service, it loads termsrv.dll, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017505797_7_1caea7ed30-1.jpeg\">\u003C\u002Fp>\u003Cp>Enable multi-user functionality by modifying termsrv.dll in memory, specific operations as follows:\u003C\u002Fp>\u003Cp>Win7 x86:\u003C\u002Fp>\u003Cp>Find: 0x3B86200300000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC78620030000FFFFFF7F9090\u003C\u002Fp>\u003Cp>Win7 x64:\u003C\u002Fp>\u003Cp>Find: 0x39873C0600000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC7873C060000FFFFFF7F9090\u003C\u002Fp>\u003Cp>However, this method becomes ineffective after a system reboot.\u003C\u002Fp>\u003Cp>Further, if we directly modify the file termsrv.dll, can we achieve the permanent activation of multi-user login functionality?\u003C\u002Fp>\u003Cp>Proceed with the following test.\u003C\u002Fp>\u003Ch3>2. Modify termsrv.dll\u003C\u002Fh3>\u003Cp>Recommended tool: CFF Explorer\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Cp>Open termsrv.dll located at c:\\windows\\system32\u003C\u002Fp>\u003Cp>Hex Editor\u003C\u002Fp>\u003Cp>View hexadecimal data 39873C0600000F84\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017511237_8_c8fea4ece3-1.jpeg\">\u003C\u002Fp>\u003Cp>Starting from address 0x0001738A, select 12 bytes and replace them with C7873C060000FFFFFF7F9090\u003C\u002Fp>\u003Cp>Save the dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Services must be stopped before replacing termsrv.dll\u003C\u002Fp>\u003Cp>After replacing termsrv.dll, restart the TermService service\u003C\u002Fp>\u003Cp>Attempt to connect remotely using different users, successful, verifying that this approach is correct\u003C\u002Fp>\u003Cp>Complete steps are as follows:\u003C\u002Fp>\u003Cp>1. Check the status of the Remote Desktop Services service\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc qc TermService\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. If the service is running, stop it first\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net stop TermService \u002Fy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Delete the original termsrv.dll\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>del c:\\windows\\system32\\termsrv.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Replace the new termsrv.dll\u003C\u002Fp>\u003Cp>5. Start the service\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start TermService\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>6. Remote connection\u003C\u002Fp>\u003Cp>Successfully implemented multi-user login\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 1:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win7 x86:\u003C\u002Fp>\u003Cp>Find: 0x3B86200300000F84\u003C\u002Fp>\u003Cp>Replace with: 0xC78620030000FFFFFF7F9090\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement 2\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Common Windows system version numbers:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>System\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>Version Number\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win7\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.1.7600\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win7sp1\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.1.7601\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win8\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.2.9200\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>\u003Cp>Win8.1\u003C\u002Fp>\u003C\u002Ftd>\u003Ctd>\u003Cp>6.3.9600\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Using the tool rdpwrap\u003C\u002Fh3>\u003Cp>Project address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstascorp\u002Frdpwrap\u003C\u002Fp>\u003Cp>Tool address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fstascorp\u002Frdpwrap\u002Freleases\u003C\u002Fp>\u003Cp>Supports Win Vista - Win 10\u003C\u002Fp>\u003Cp>Does not modify termsrv.dll, achieved by passing different parameters\u003C\u002Fp>\u003Cp>Installation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RDPWInst.exe -i is\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017517165_9_b72a9abeb3-1.jpeg\">\u003C\u002Fp>\u003Cp>Release rdpwrap.dll and rdpwrap.ini to the System32 folder\u003C\u002Fp>\u003Cp>rdpwrap.dll will be loaded into the same process as termsrv.dll\u003C\u002Fp>\u003Cp>At this point, remote connections can be made using different users\u003C\u002Fp>\u003Cp>Uninstall:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RDPWInst.exe -u\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces three methods to support multi-user remote desktop login, applicable under different conditions. For the termsrv.dll replacement method, different replacement locations must be used depending on the specific system version.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",671,"Onedaysec",4,"published","2026-02-02T07:38:21.177Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Enable Multi-User RDP on Windows: Penetration Testing Guide","Windows remote desktop, multi-user login, RDP penetration, mimikatz, rdpwrap, 3389 enable",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],903,901,900,899,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.925Z","2026-07-23T16:02:15.097Z","draft","2026-07-23T16:15:26.316Z"]