VNC "man in the middle" attack

Robert_Bunker@cchcs.org Robert_Bunker@cchcs.org
Mon Dec 2 19:30:00 2002


Is RealVNC's WinVNC 3.3.4 still susceptible to this attack?

http://www.securiteam.com/exploits/6S0040A6AW.html

http://www.iss.net/security_center/static/5992.php

If so, is any newer version not susceptible to this attack?

If all versions of RealVNC/WinVNC are susceptible to this attack is there 
another flavor of VNC that is not?

I cannot setup a tunnel / use SSH in my current situation so this attack 
presents possible a problem.

Thanks.