Password brute force

VNC's standard authentication (security type 2) is a challenge-response: the server sends a 16-byte challenge, the client encrypts it with DES keyed by the password (truncated to eight characters, with a quirk that reverses the bit order of each key byte), and returns the result. Two attacks follow. Online brute force tries passwords against the server directly. More powerfully, capturing one challenge-response pair (by sniffing or MITM) allows offline cracking: the password space is tiny (eight characters, and the algorithm is known), so a wordlist or brute force recovers the password quickly without touching the server again.

bash
# online brute force
nmap -p5900 --script vnc-brute --script-args passdb=rockyou.txt <target>
hydra -P rockyou.txt vnc://<target>
# offline: capture the challenge + response (sniff/MITM), then crack
#   VNC auth is a known DES-challenge format; feed challenge+response to a cracker
#   (the 8-char cap and reversed-bit key make the keyspace small and fast to search)

Exploitation notes#

  • The eight-character truncation is the decisive weakness: only the first eight characters are keyed, so the effective space is small and wordlists are highly effective; longer passwords add nothing beyond eight bytes.
  • Offline cracking from a captured challenge-response is quiet and fast, and avoids online lockout/logging; a single sniffed authentication (the traffic is otherwise cleartext) yields the pair, see cleartext transmission.
  • Online brute force works where you cannot capture, but VNC servers may limit or delay attempts; keep lists short given the 8-char cap.
  • A cracked password is reusable across VNC endpoints and sometimes other services; the recovered desktop access is interactive control of the target.

Tools#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more