VNC's handshake is informative before any authentication: the server announces its RFB protocol version and the list of security types it supports, and the implementation can be fingerprinted from version strings and behaviour. The security-type list is the key finding, it shows whether the server offers "None" (no authentication), the weak VNC DES password scheme, or vendor schemes, and the implementation (RealVNC, TightVNC, UltraVNC) maps to known authentication-bypass vulnerabilities, so enumeration directs the whole attack.
nmap -p5900 --script vnc-info <target> # RFB version + supported security types
# raw handshake: the server sends "RFB 003.00X" then the security-type list
nc <target> 5900 | head -c 12 # RFB protocol version banner
Subtopics#
- Banner grabbing: the RFB version string.
- Implementation detection: identifying RealVNC, TightVNC, UltraVNC.