Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: viewtopic.php?t=37864

Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://twitter.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc

Security

Post Reply
Guest

Security

Post by Guest »

Hello,

Does requiring MS Login/Password make the system more secure over the mere password requirement?

Thanks
Leonard

Cleartext

Post by Leonard »

While tying the vnc connection to the used ID helps in some aspects. but it is better to encrypt the communications for security.

ssh, stunnel and OpenVPN are my current choices for encrypting vnc connections.
Marscha
Former moderator
Former moderator
Posts: 464
Joined: 2004-05-14 06:48

What kind of security

Post by Marscha »

I think it depends on what you mean with security.
In my case we have a closed network, but we don't want to have 1 identical password on 10,000 machines :o
So I think it increases security to use MS logon because we can limit access to machines with domain groups to certain users :) .
Leonard

Packet capture

Post by Leonard »

All it takes is one person downloading one application and then they can capture IDs and passwords even on switched networks.

This is reality not make beleive. I won't disclose the application, but if you know how to search the internet It's not hard to find.
RobH
Former moderator
Former moderator
Posts: 113
Joined: 2004-05-03 18:04
Location: Chicago, IL

Post by RobH »

Use the MSRC4 Plugin to encrypt the session. 8)
GUest

Thanks

Post by GUest »

Thanks to all for reply.

I am in a process of setting up the plugins. (Have not done that yet because I am still trying to tweak the workings).

What I gather is then that the security reamins the same with or without login id/password vrs vnc password. It is just that the level of complexity for each station increases with haveing to know the login id and password for each station.
User avatar
Rudi De Vos
Admin & Developer
Admin & Developer
Posts: 6838
Joined: 2004-04-23 10:21
Contact:

Post by Rudi De Vos »

MS logon does not add any security.
But grand access based on the MS user account database.

+All local admins (or equivalant) have access..
+You can allow access to users of local or domain groups

When you disable vnc logon, you can handle the access from the central domain controler.
Add/remove access to users is just adding or removing a user from a group.
Marscha
Former moderator
Former moderator
Posts: 464
Joined: 2004-05-14 06:48

Post by Marscha »

Control access from the central domain controller only works with one (1) domain.
We have an Active Directory tree with ~ 30 domains. As a user in the Germany Domain I cannot get access to a machine in the Finland Domain.
Would be great if the MS logon functionality could be enhanced to allow this 8)
Should be similar to mapping e.g. a share in another domain, just specify the domain of the user or use the "domain\user" notation.
Guest

Post by Guest »

But then, when you setup your own server with domain (mydomain) and create a user in the access group....

Verifying against your domain server should give you access to all machines..no security.

There need to be a method that works on NT4 and AD domains..
Didn't find the trick to do it.
Possible it will only be secure on a AD domain and using the
AA.bb.cc name convention. Not that easy to setup and test
on a home network...

Rudi
Post Reply