Default passwords

Where a VNC server does use the password scheme, that password is often weak: appliances, KVM-over-IP devices, and bundled remote tools ship with fixed or documented defaults, and the classic VNC password is truncated to eight characters, shrinking the keyspace. Trying the device's default and common VNC passwords frequently works. Separately, VNC stores its password on disk obfuscated with a fixed, publicly known DES key (not a hash), so a recovered password file is decrypted directly to the plaintext password, which is then reused.

bash
# try defaults/common passwords (8-char cap means short lists are effective)
vncviewer <target>::5900        # enter documented default or common password
nmap -p5900 --script vnc-brute --script-args passdb=vnc-defaults.txt <target>
# decrypt a stored VNC password file (fixed DES key, reversible)
#   files: ~/.vnc/passwd, UltraVNC.ini, registry values
echo -n "<hex-of-passwd-file>" | xxd -r -p | openssl enc -d -des-cbc -K e84ad660c4721ae0 -iv 0000000000000000 2>/dev/null
vncpwd passwd      # tools that apply the known key directly

Exploitation notes#

  • The eight-character truncation means only the first eight bytes of any password matter, so short default/common-password lists are disproportionately effective; identify the device for its documented default.
  • Stored VNC passwords are obfuscated, not hashed: the DES key is fixed and public, so any recovered passwd file, UltraVNC.ini, or registry value decrypts straight to the plaintext with a known-key tool.
  • A decrypted VNC password is reusable, test it on other VNC endpoints and consider it for other services, since operators reuse it.
  • Where brute force is needed rather than defaults, see Password brute force; where the server has no password, see No authentication.

Tools#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more