I am using port forwarding for my viewer which is listening to outside requests from SC.
Since I will leave this port open on my computer, what security issues do I need to worry about?  what general security steps do I need to take to prevent hacks into my computer via this port?  Thank you.
			
			
									
						
										
						After more 1 000 000 (one million) views on forum for 1.5.0.x development versions... and 1.6.1.0, 1.6.3.0-dev versions
A new stable version, UltraVNC 1.6.4.0 and UltraVNC SC 1.6.4.0 have been released: https://forum.uvnc.com/viewtopic.php?t=38095
Feedback is welcome
Celebrating the 22th anniversary of the UltraVNC (25th anniversary since the laying of the foundation stone): https://forum.uvnc.com/viewtopic.php?t=38031
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864
Forum password change request: https://forum.uvnc.com/viewtopic.php?t=38078
Development: UltraVNC development is always here... Any help is welcome.
Feedback is welcome
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Bluesky/AT Protocol: https://bsky.app/profile/ultravnc.bsky.social
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
	A new stable version, UltraVNC 1.6.4.0 and UltraVNC SC 1.6.4.0 have been released: https://forum.uvnc.com/viewtopic.php?t=38095
Feedback is welcome
Celebrating the 22th anniversary of the UltraVNC (25th anniversary since the laying of the foundation stone): https://forum.uvnc.com/viewtopic.php?t=38031
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864
Forum password change request: https://forum.uvnc.com/viewtopic.php?t=38078
Development: UltraVNC development is always here... Any help is welcome.
Feedback is welcome
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Bluesky/AT Protocol: https://bsky.app/profile/ultravnc.bsky.social
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
General security question for SC using port forwarding
Re: General security question for SC using port forwarding
in port forwarding biggest risk is someone else capturing your secreat data so i would recommend using dsm plugins 
of recent there have been various security risks in the viewer running in listing mode ( see up just below the address bar, even now you can see Please update your viewer to 1.0.5.4! Read on about the found vulnerability. that is what i mean, never keep the viewer running in a listening state unless you are using a vpn and a firewall.
also open ports are not security risks.
how are you connected to the internet ? using a router and a nat ? that should provide some protection.
however if you are directly connected to the internet then use some security software. i would recommend comodo ( its free, has all : antivirus firewall and hips )
http://www.personalfirewall.comodo.com/ ... ewall.html however this software is for technical users or power users or people who understand what is happening in their pc ..
or use any security software that you are comfortable with on both the sides of the ultravnc ie on the client and server side
			
			
									
						
										
						of recent there have been various security risks in the viewer running in listing mode ( see up just below the address bar, even now you can see Please update your viewer to 1.0.5.4! Read on about the found vulnerability. that is what i mean, never keep the viewer running in a listening state unless you are using a vpn and a firewall.
also open ports are not security risks.
how are you connected to the internet ? using a router and a nat ? that should provide some protection.
however if you are directly connected to the internet then use some security software. i would recommend comodo ( its free, has all : antivirus firewall and hips )
http://www.personalfirewall.comodo.com/ ... ewall.html however this software is for technical users or power users or people who understand what is happening in their pc ..
or use any security software that you are comfortable with on both the sides of the ultravnc ie on the client and server side
Re: General security question for SC using port forwarding
Thanks.   A few answers to your questions
I am using the dsm plugin.
I have a standard dlink gamer router with all the default settings (except for passwords!) connected to cable internet. The listening pc is behind the router and has a commercial software firewall.
I do not have vpn. Is this essential?
The main concern I wanted to understand and avoid was the risk of someone using the port I have opened and forwarded to take control of the listening pc.
			
			
									
						
										
						I am using the dsm plugin.
I have a standard dlink gamer router with all the default settings (except for passwords!) connected to cable internet. The listening pc is behind the router and has a commercial software firewall.
I do not have vpn. Is this essential?
The main concern I wanted to understand and avoid was the risk of someone using the port I have opened and forwarded to take control of the listening pc.
Re: General security question for SC using port forwarding
not a problem - since you are using dsmplugins - VPN was for added security since you are using dsmplugins no need for vpnI do not have vpn. Is this essential?
The main concern I wanted to understand and avoid was the risk of someone using the port I have opened and forwarded to take control of the listening pc.
to prevent someone from taking control of your pc without your authorization use a key file + strong password and your will be very much secure - nothing to worry about for a tutorial about how to generate a secure password go to http://www.diceware.com
and if what you told in the above post it would seem that you are secure enough.
					Last edited by nobody on 2009-04-13 02:36, edited 2 times in total.
									
			
						
										
						Re: General security question for SC using port forwarding
Thanks.
By key file, I assume you mean the ultravnc key file. I was not aware of one with windows.
By password I assume you mean the windows pc users passwords (SC does not have password access as well?)
			
			
									
						
										
						By key file, I assume you mean the ultravnc key file. I was not aware of one with windows.
By password I assume you mean the windows pc users passwords (SC does not have password access as well?)
Re: General security question for SC using port forwarding
.
			
			
									
						
										
						CorrectBy key file, I assume you mean the ultravnc key file. I was not aware of one with windows.
yes, i normally use the MSLOGIN2 which makes windows and ultravnc password the same and this can be even same as the Active dir - almost one password everywhereBy password I assume you mean the windows pc users passwords (SC does not have password access as well?)
Re: General security question for SC using port forwarding
there is minimal risk having an application like the viewer listening on your computer.dghundt wrote:I am using port forwarding for my viewer which is listening to outside requests from SC.
Since I will leave this port open on my computer, what security issues do I need to worry about? what general security steps do I need to take to prevent hacks into my computer via this port? Thank you.
if your concerned about it, simply close the app when not needed, then any connection attempt on that port simple goes no-where ...
there would be only a few people in the world that MAY know how to get somewhere using this forwarded (but not listening) port, and i doubt they are interested in small fries like us ...

its good to be asking questions about security, but in this regard, the risk is minimal (in my opinion anyway)
relax and enjoy
ask a silly question and remain a fool for 5 minutes...
don't ask, and remain a fool for life - JDaus 2003
without imperfections, neither you nor i would exist - Steven Hawkins
__
JD
SCPrompt - OpenSource Free Remote Screen\Desktop Sharing Solution: https://www.securetech.com.au/projects/scprompt
https://www.securetech.com.au/
			
						don't ask, and remain a fool for life - JDaus 2003
without imperfections, neither you nor i would exist - Steven Hawkins
__
JD
SCPrompt - OpenSource Free Remote Screen\Desktop Sharing Solution: https://www.securetech.com.au/projects/scprompt
https://www.securetech.com.au/



