Someone has been able to logon to our server and change the port that Remote Desktop listens on. In the past, it has been changed to port 80. Recently, it has been changed to an unknown assignment.
My question is two-fold:
Is there a way to learn the listening port for Remote Desktop remotely? (I do not have access to the console.)
How can I prevent future attacks like these from happening?
Any ideas?