Jump to content

VNC Security Flaw


mookie

Recommended Posts

So I was browsing the web tonight, when suddenly my mouse pointer keeps jerking up to the top corner of the screen. Then the mouse starts moving around. Long story short, apparently there's a flaw in VNC that allows someone to connect without any password at all (which was fixed with a newer version 4.1.2 on 12th May). If you're running VNC on a machine that has a real IP address, you should probably upgrade; I reviewed my logs and found that 20 different people have connected over the past week or so. Luckily I'm very paranoid and always leave the machine locked when I'm not in front of it. :)

 

http://www.realvnc.com/upgrade.html

Link to comment
Share on other sites

hah interesting... makes you wonder how 20 different came across your IP address eh? Seriously, are there 20 people in the world sitting there typing in random IP addresses trying to find one person without a password.

Link to comment
Share on other sites

hah interesting... makes you wonder how 20 different came across your IP address eh? Seriously, are there 20 people in the world sitting there typing in random IP addresses trying to find one person without a password.

 

The beautiful thing about computers is they are very efficient at repetitive tasks...

 

http://www.angryziber.com/ipscan/

 

It's harder to do now, what with the Heuristic algorithms in routers now and such, but ISPs overseas often don't have such strictures in place, and often ISPs here don't really protect that well against INCOMING port scans. They seem to feel more liable to the victims of outgoing port scans than incoming.

 

Regardless, as far as computers go, anonymity on the Internet is a joke. I don't know if anyone's done research, but from my personal experience, a 24/7 public computer with a static IP won't last a week on the internet before it is discovered and, if unsecured services are running, compromised.

 

$.02

Link to comment
Share on other sites

My first port scan was done back in spring of 97. oh man that is pushing 10 years... Technology changed alot since then and its no fun anymore. Simple port open in win 95, send a command to that port bam BSOD

Link to comment
Share on other sites

Hehhehe. The good ole days NOFX. Does anyone ever check their router logs anymore? I was browsing through mine yesterday and found like PODD operations like every 2 minutes since the router went live 6 months ago. I find it hilarious that something that become ineffective like 4 years ago is still showing up to this day.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...