Weak cryptography

Base VNC has no transport encryption: the RFB session, framebuffer updates (the screen), client input (keystrokes and mouse), and even the authentication challenge-response travel in cleartext. A positioned attacker therefore reads the desktop and captures the authentication material. On top of that, the security type is negotiated and can be downgraded to a weaker or no-authentication option, and the encryption that some implementations bolt on (vendor schemes, VeNCrypt/TLS) is often weak, optional, or not verified, so it frequently fails to protect the session in practice.

bash
# confirm the session is cleartext (no VeNCrypt/TLS security type)
nmap -p5900 --script vnc-info <target>         # security types; absence of VeNCrypt(19) => cleartext
tcpdump -i eth0 -w vnc.pcap port 5900          # capture for analysis

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more