Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: VNC Security |
|---|---|
| Date: | Mon, 25 Apr 2005 19:46:48 -0400 |
a. Random user in cyberspace has a problem.
b. User installs VNC under direction of tech support:
i. strong password
ii. not installed as service
iii. temporary port forwarding onlyc. User allows remote person to login, generally for 20-30 mins.
d. User stops VNC server process and disables port forwarding
Andy
Mike Miller wrote:
On Tue, 19 Apr 2005, Andy Bruce - softwareAB wrote:
I have to agree with Steve that this is, for all practical purposes, a non-existent security risk. The only things that could go wrong:
a. "Somebody" is sniffing the packet stream while the VNC passwords are being exchanged, and, during that 20 minute interchange, cracks the password and logs onto the VNC server. Of course, we would notice this problem on both ends!
I don't know if it is possible to crack the VNC password, but I don't agree that you would necessarily notice this on both ends. If the attacker were to log into the session when you weren't using it, he could then make some changes to your system (for Windows) that would allow him more access to your machine later. If you were using Windows he could start up another VNC desktop that you might not notice, and he could use a different password if he wanted to (by copying the vnc password file, changing the password, and copying it back).
I hope that it is hard to crack the passwords. I think it is hard to do it but I'd like to hear more about that.
Mike _______________________________________________ VNC-List mailing list VNC-List@realvnc.com To remove yourself from the list visit: http://www.realvnc.com/mailman/listinfo/vnc-list
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: VNC Security, Mike Miller |
|---|---|
| Next by Date: | Re: VNC Security, Mike Miller |
| Previous by Thread: | Re: VNC Security, Mike Miller |
| Next by Thread: | Re: VNC Security, Mike Miller |
| Indexes: | [Date] [Thread] [Top] [All Lists] |