The Geek Forum

  • May 16, 2024, 12:53:56 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

Due to the prolific nature of these forums, poster aggression is advised.

*

Recent Forum Posts

Shout Box

Members
  • Total Members: 4961
  • Latest: 41si
Stats
  • Total Posts: 129633
  • Total Topics: 7189
  • Online Today: 168
  • Online Ever: 1013
  • (January 12, 2023, 01:18:11 AM)

Author Topic: for RealVNC fans out there  (Read 3053 times)

Demosthenes

  • Evil Ex-HN Moderator
  • Administrator
  • Hacker
  • *
  • Coolio Points: +567/-72
  • Offline Offline
  • Gender: Male
  • Posts: 9904
  • Just try me. See what happens.
    • View Profile
    • Zombo
for RealVNC fans out there
« on: January 05, 2007, 05:43:43 PM »

FYI

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2369


I have to wonder how a virus could really exploit something like VNC.  So you script a virus that bypasses VNC's authentication.  Great.  What then?  It's not like it can script mouse movements or access the file system.

 :?

About the only use I could see in something like this for a black hat would be to gain access to a machine one at a time, with a human.  A "virus" wouldn't be able to do anything, and therefore wouldn't be able to replicate.
Logged

Coolio Points: 89,000,998,776,554,211,222
Detta Puzzle Points: 45

Banning forum idiots since 2001

pbsaurus

  • Hacker
  • ****
  • Coolio Points: +354/-31
  • Offline Offline
  • Gender: Male
  • Posts: 9981
  • Everyone Loves The King Of The Sea
    • View Profile
    • http://www.myspace.com/flipperpete
Re: for RealVNC fans out there
« Reply #1 on: January 05, 2007, 06:21:18 PM »

What about gaining access to a box with VNC and then using remote desktop to get to other boxes on the network?

Demosthenes

  • Evil Ex-HN Moderator
  • Administrator
  • Hacker
  • *
  • Coolio Points: +567/-72
  • Offline Offline
  • Gender: Male
  • Posts: 9904
  • Just try me. See what happens.
    • View Profile
    • Zombo
Re: for RealVNC fans out there
« Reply #2 on: January 05, 2007, 06:28:20 PM »

Sure, that's definitely a possibility... but not something a virus could do.

Don't get me wrong, a person could definitely wreak any manner of havoc with a vulnerability such as this... but I don't see how a virus could really exploit it.
Logged

Coolio Points: 89,000,998,776,554,211,222
Detta Puzzle Points: 45

Banning forum idiots since 2001

pbsaurus

  • Hacker
  • ****
  • Coolio Points: +354/-31
  • Offline Offline
  • Gender: Male
  • Posts: 9981
  • Everyone Loves The King Of The Sea
    • View Profile
    • http://www.myspace.com/flipperpete
Re: for RealVNC fans out there
« Reply #3 on: January 05, 2007, 06:36:08 PM »

But couldn't one exploit a box on the network and have it spread viruses?  Or better yet, get into the exchange or other email server on a network and eliminate email spamware, virus protection and then send out a message from the CEO with said server containing a disquised .pdf attachment with a bonus information or some such?

12AX7

  • Guest
Re: for RealVNC fans out there
« Reply #4 on: January 09, 2007, 09:13:39 AM »

Or better yet, get into the exchange or other email server on a network and eliminate email spamware, virus protection and then send out a message from the CEO with said server containing a disquised .pdf attachment with a bonus information or some such?
OSHIT!! Was that you, man? I never did cash mine, (didnt trust it) so I'm still all good. Nice j0rb!
Logged

pbsaurus

  • Hacker
  • ****
  • Coolio Points: +354/-31
  • Offline Offline
  • Gender: Male
  • Posts: 9981
  • Everyone Loves The King Of The Sea
    • View Profile
    • http://www.myspace.com/flipperpete
Re: for RealVNC fans out there
« Reply #5 on: January 09, 2007, 01:27:01 PM »

OSHIT!! Was that you, man? I never did cash mine, (didnt trust it) so I'm still all good. Nice j0rb!

Wasn't me.  I wouldn't know how to do that.

12AX7

  • Guest
Re: for RealVNC fans out there
« Reply #6 on: January 09, 2007, 02:06:09 PM »

Wasn't me.  I wouldn't know how to do that.
Ah! ok, gotcha.
Logged

Demosthenes

  • Evil Ex-HN Moderator
  • Administrator
  • Hacker
  • *
  • Coolio Points: +567/-72
  • Offline Offline
  • Gender: Male
  • Posts: 9904
  • Just try me. See what happens.
    • View Profile
    • Zombo
Re: for RealVNC fans out there
« Reply #7 on: January 10, 2007, 07:03:51 PM »

But couldn't one exploit a box on the network and have it spread viruses?  Or better yet, get into the exchange or other email server on a network and eliminate email spamware, virus protection and then send out a message from the CEO with said server containing a disquised .pdf attachment with a bonus information or some such?

Sure... but not without a user sitting at a machine somewhere actually doing that.  My point is, without a user moving the mouse, a virus that breaks VNC authentication can't actually do anything, much less replicate itself.

Which, by definition, means it can't be a virus.
Logged

Coolio Points: 89,000,998,776,554,211,222
Detta Puzzle Points: 45

Banning forum idiots since 2001

pbsaurus

  • Hacker
  • ****
  • Coolio Points: +354/-31
  • Offline Offline
  • Gender: Male
  • Posts: 9981
  • Everyone Loves The King Of The Sea
    • View Profile
    • http://www.myspace.com/flipperpete
Re: for RealVNC fans out there
« Reply #8 on: January 10, 2007, 07:04:40 PM »

point taken.

Crystalmonkey

  • Nazi Absinthe Drinker
  • Hacker
  • ****
  • Coolio Points: +167/-3
  • Offline Offline
  • Gender: Male
  • Posts: 1515
    • View Profile
Re: for RealVNC fans out there
« Reply #9 on: January 12, 2007, 01:49:01 AM »

Sure... but not without a user sitting at a machine somewhere actually doing that.  My point is, without a user moving the mouse, a virus that breaks VNC authentication can't actually do anything, much less replicate itself.

Which, by definition, means it can't be a virus.

Not true, you certainly know how to use a keyboard to get around, right?

Send a command for windows key > Up Arrow > Enter  (To be mean)

or whatever, the point is you don't need to move a mouse.

Heck, send them to a site that installs a virus! (And accept it automagically!)
Logged
"Philosophy is questions that may never be answered. Religion is answers that may never be questioned." - Anonymous

"Sadly, computers don't have rights, so moral arguments aside, I'm afraid it's quite legal to run Windows on them." - /. User 468275

Demosthenes

  • Evil Ex-HN Moderator
  • Administrator
  • Hacker
  • *
  • Coolio Points: +567/-72
  • Offline Offline
  • Gender: Male
  • Posts: 9904
  • Just try me. See what happens.
    • View Profile
    • Zombo
Re: for RealVNC fans out there
« Reply #10 on: January 12, 2007, 12:01:29 PM »

While technically true, I don't think something like that would be very successful as viruses go.
Logged

Coolio Points: 89,000,998,776,554,211,222
Detta Puzzle Points: 45

Banning forum idiots since 2001