VNC Security Alert

James Mc Parlane james "at" ebom.org
Tue, 30 Jun 1998 13:12:46 +0000


I've spent the last few days writing tiny VNC server for Win32 and linux and
I noticed that a ClientCutTextMsg was sent to every VNC server I was
connected to, every time I copied something into the clipboard on my local
machine (Win32).

Even if the VNC client was minimised.

This means that if you have a VNC session open to a remote machine on the
internet, then every time your clipboard changes, it will be sent out in
plain text onto the net.

It also means that if you copy a HUGE piece of text. (I tested it with a web
log file) it will waste bandwidth by uselessly transmitting it to the
server.

I wouldn't mind it it if the text was sent only if the window was active.

Some basic encryption would be nice too.



---------------------
This message came to you via the VNC mailing list.
For more information about the list see http://www.orl.co.uk/vnc/intouch.html