Thin client security presentation

Constantin Kaplinsky const "at"
Thu, 07 Mar 2002 20:45:36 +0000

Hello Andrew,

>>>>> "AvdS" == Andrew van der Stock <ajv "at"> writes:

AvdS> * the inbuilt web server on port 5800 is not necessary for most
AvdS>   people, and is a good DoS target (look at code for greater
AvdS>   clarity on this risk)

Also, Xvnc's RFB port is an _extremely_ easy target for DoS attacks:
single-process and single-threaded Xvnc uses blocking I/O for RFB

With Best Wishes,
To unsubscribe, mail majordomo "at" with the line:
'unsubscribe vnc-list' in the message BODY
See also: