Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: viewtopic.php?t=37864

Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://twitter.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc

Port scans shown as balloon tip despite blocking in AuthHost

Post Reply
Novgorod
Posts: 3
Joined: 2016-08-11 13:22

Port scans shown as balloon tip despite blocking in AuthHost

Post by Novgorod »

Hi,

Since UVNC got the function to show failed connection attempts (e.g. port scans) as a balloon tip, it's popping up from time to time and can get quite annoying if it happens a lot. I know it's possible to turn it off completely, but on the other hand it's interesting to see who's trying to hack me ;).. However, sometimes a single IP is doing connection attempts over and over again, which makes "annoying" win over "interesting". I tried therefore to block a particular IP completely using AuthHost in the ini file, but the balloon tips still appear with that IP address:
Image Image

Did I do anything wrong or is this by design? I assumed that blocking through AuthHost will immediately drop any connection and not mention it as a failed connection attempt...
User avatar
Rudi De Vos
Admin & Developer
Admin & Developer
Posts: 6838
Joined: 2004-04-23 10:21
Contact:

Re: Port scans shown as balloon tip despite blocking in Auth

Post by Rudi De Vos »

Took some time to debug

The connection break because it's not a rfb message ( like some port scanner) , no rfb -> disconnect
Only if message is rfb we check the auth list, in that case we send a message to the viewer telling he is refused before breaking the connection.

The ballon tip popup was not intended for this, but some site effect. No option exist to disable it.
Novgorod
Posts: 3
Joined: 2016-08-11 13:22

Re: Port scans shown as balloon tip despite blocking in Auth

Post by Novgorod »

Thanks for looking into it. Would it make sense to "fix" this in a future version, since the balloon popup is not intended to show connections without rfb messages (as you said), such as port scans? I think many people get these "false alerts" now, since port scans are so prevalent on the internet...
User avatar
Rudi De Vos
Admin & Developer
Admin & Developer
Posts: 6838
Joined: 2004-04-23 10:21
Contact:

Re: Port scans shown as balloon tip despite blocking in Auth

Post by Rudi De Vos »

The alert was actual added for the outgoing connection. ( server connect to viewer)
In case the viewer is offline we only get the initial rfb exhange fail and that's the p)opup you see.

The method should differentiate between in/outgoing and skip for in.
Novgorod
Posts: 3
Joined: 2016-08-11 13:22

Re: Port scans shown as balloon tip despite blocking in Auth

Post by Novgorod »

Rudi De Vos wrote:The method should differentiate between in/outgoing and skip for in.
This sounds perfect! Looking forward to the next release :thumbs: ...
Post Reply