security question

New to UltraVNC? Your questions are welcome in this subforum. :surprise:

security question

Postby Nummi » 2007-08-27 00:43

Lets assume I can set up UltraVNC and the ARC4 Plugin correctly, then open the ports on my router correctly, then get it all working correctly. Then, I leave the server running (with the ARC4 working and ports open) with UltraVNC waiting for a connection. My question is: can someone else gain access without the ARC4 key? And what if the ARC4 is not working, can someone gain access (assuming they can guess the UltraVNC password?
Nummi
 
Posts: 2
Joined: 2006-12-20 23:42

Re: security question

Postby redge » 2007-08-27 23:17

vncviewer without plugin he can reach the server with arc4plugin but fail to authenticate.

if vnc server crash for any reason, I'm not sure if there a security issue.
but as my knowledge, unpossible to reach the vnc server until restart and it auto restart with dsmplugin arc4plugin.
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
redge
Super-Mod
Super-Mod
 
Posts: 6815
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: security question

Postby UltraSam » 2007-08-28 07:54

If the viewer has not the good ARC4 key file, he just can't even start the handshaking process (RFB protocole version and so on) before the authentication process itself (VNC password).

The data is encrypted from the very first bytes. If the Viewer can't correctly encrypt these bytes with the same key than the server, they can't understand each other and the connection is immediatly dropped, even before the server to ask for the password.
UltraSam
UltraSam
Admin & Developer
Admin & Developer
 
Posts: 466
Joined: 2004-04-26 20:55


Return to Beginner questions

Who is online

Users browsing this forum: No registered users and 4 guests