Banner grabbing

The RFB protocol begins with the server sending a 12-byte version string such as RFB 003.008\n, immediately on connection and before any authentication. Reading it identifies the protocol generation (3.3, 3.7, 3.8), which matters because older versions negotiate security differently (in 3.3 the server dictates the single security type; 3.7+ offer a list the client chooses from, which enables downgrade). After the version, the server presents the security types it accepts, the first real indication of whether authentication is required.

bash
nc <target> 5900 | head -c 12                  # "RFB 003.008"
nmap -p5900 --script vnc-info <target>         # version + security type list
# the security-type byte(s) that follow: 1 = None, 2 = VNC auth (weak), 16/18 = Tight/VeNCrypt

Exploitation notes#

  • The version string is pre-auth and free; 003.003 versus 003.007/003.008 tells you whether the client can choose the security type (enabling security type downgrade) or the server dictates it.
  • The security types offered right after are the decisive fact: security type 1 is "None" (no authentication), type 2 is the weak VNC DES password, and vendor types (Tight, VeNCrypt) point at implementation-specific handling.
  • Combine the version with implementation detection to map to known bypasses (RealVNC/TightVNC).
  • Displays beyond the first sit on 5901, 5902, etc.; scan the range, as multiple VNC servers on one host are common.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more