Hello.
I want to use UVNC as main remote control tool in my company, but when I checked the security of storing password - I was horrified. 2 mins of googling and I found tool for fast getting password from uvnc hash. This tool gave me a password just in seccond. And yes, this password was from upper case and lowwer case letters, numbers, and special symbols (like !@#$%^&*())
So the problem is:
- if I will use same password on all user PC's
- if any user will get hash of uvnc password from config file (or from regestry)
= this user will be able to control any other machines, just like admin. File transfer, blocking PC, spying
My question is: is there any other way to store password as strong hash? For example SHA-2
Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: viewtopic.php?t=37864
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://twitter.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
Important: Please update to latest version before to create a reply, a topic or an issue: viewtopic.php?t=37864
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://twitter.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
UVNC Server. Store strong hash of password
- Rudi De Vos
- Admin & Developer
- Posts: 6832
- Joined: 2004-04-23 10:21
- Contact:
Re: UVNC Server. Store strong hash of password
*Use the encryption plugin with a passphrase
or
*Use the encryption plugin with an encryption key, then ony the viewer with the contra key can connect.
or
*Use the encryption plugin with an encryption key, then ony the viewer with the contra key can connect.