VNC (Virtual Network Computing) shares a graphical desktop over the Remote Framebuffer (RFB) protocol, usually on TCP 5900 and up (display N on 5900+N). Its security is weak by design and by deployment. The classic VNC authentication is a DES challenge-response using a password truncated to eight characters, trivial to brute force or crack from a captured challenge. Many servers run with no authentication at all. The screen contents and keystrokes travel in cleartext unless tunnelled. The RFB security type is negotiated and can be downgraded. And specific implementations (RealVNC, TightVNC) have shipped outright authentication bypasses.
nmap -p5900-5902 --script vnc-info,vnc-title,realvnc-auth-bypass <target>
vncviewer <target>::5900 # connect to test auth/no-auth
Subtopics#
- Enumeration: RFB version, security types, and implementation.
- Authentication: no-auth, defaults, brute force, and bypasses.
- Weak cryptography: cleartext, weak encryption, and downgrade.