VNC 4 password length

William Hooper whooper "at" freeshell.org
Thu Jul 8 14:05:01 2004


Kent Anderson said:
> I use an 8 character password for VNC with the new server I've found
> that if I have my 8 character password entered correctly, I can enter any
> amount of characters after that and it will authenticate as if I entered
> the correct password.

http://www.uk.research.att.com/archive/vnc/faq.html#q55
"While we're on the subject of security, you should also be aware that only the first 8 characters of VNC passwords are significant. This is because the 'getpass' call used in the Unix server to read a password has this restriction, and the other platforms have been made compatible with this."

> For example let's say my password is 12345678, if I enter
> 12345678hfjkslaks it will authenticate fine.  I've tried this with both
> the new viewer and the older 3.3.7 and I get the same result, also I tested
> this on a 3.3.7 server and it rejected the bad password.

Try again.  Every version of RealVNC has had this limitation.

-- 
William Hooper