Port 3389 is a remote Terminal Services port, remote Terminal Services in Windows system is a very powerful service, but also become an intruder long-standing host channel, intruders can use some means to get administrator account and password and intrusion host.
As we all know, intruders usually first scan the host open port, once found that it opened 3389 port, will be the next intrusion, so we only need to modify the default port to avoid the majority of intruder's eyes and ears.
1. Step: Open "Start → run", enter "regedit", open the registry, enter the following path,
2. Open the following path in turn:
Hkey_local_machine/system/currentcontrolset/control/terminal server/wds/rdpwd/tds/tcp
Find the Portnamber value whose default value is 3389, modify it to the desired port, for example: 12547, and note the use of decimal. See:
3. Open the path again:
Hkey_local_machine/system/currentcontrolset/control/terminal server/winstations/rdp-tcp
Modify the value of PortNumber (default is 3389) to Port 12547, and note the use of decimal.
Note: In both places, the two ports need to be modified to be consistent.
4. In Windows Server
Add exception in firewall remote port: 12547;
How to: Network Neighbor-right-properties-Local Area Connection-right-click-Properties;
Local connection Properties--advanced--Set--windows Firewall--exception--Add port (TCP),
Add finished click OK to complete (the remote port number is modified to restart the system to take effect, the next login need to add port after IP login example: 136.215.xxx.xxx:12547)
VPS Host Modify system Remote port number/Add firewall