Base VNC has no transport encryption: the RFB session, framebuffer updates (the screen), client input (keystrokes and mouse), and even the authentication challenge-response travel in cleartext. A positioned attacker therefore reads the desktop and captures the authentication material. On top of that, the security type is negotiated and can be downgraded to a weaker or no-authentication option, and the encryption that some implementations bolt on (vendor schemes, VeNCrypt/TLS) is often weak, optional, or not verified, so it frequently fails to protect the session in practice.
# confirm the session is cleartext (no VeNCrypt/TLS security type)
nmap -p5900 --script vnc-info <target> # security types; absence of VeNCrypt(19) => cleartext
tcpdump -i eth0 -w vnc.pcap port 5900 # capture for analysis
Subtopics#
- Cleartext transmission: reading the unencrypted desktop and credentials.
- Weak encryption: weak or optional encryption modes.
- Security type downgrade: forcing a weaker security type.