VNC authentication is weak in several independent ways, and any one gives a full interactive desktop. Servers are commonly left with the "None" security type (no authentication). The classic VNC password scheme is a DES challenge-response over a password truncated to eight characters, which is brute-forceable online and crackable offline from a captured challenge, and such passwords are often vendor defaults or trivial. And particular implementations (RealVNC, TightVNC) have had authentication bypasses that skip the check entirely. The payoff is the same regardless: interactive control of the remote desktop.
vncviewer <target>::5900 # prompts (or not) depending on security type
nmap -p5900 --script vnc-info,realvnc-auth-bypass <target>
Subtopics#
- No authentication: servers offering the None security type.
- Default passwords: vendor and guessable VNC passwords.
- Password brute force: online and offline attacks on the VNC password.
- RealVNC auth bypass: the RealVNC security-type bypass.
- TightVNC bypass: TightVNC authentication flaws.