VNC
Beauford, Jason
jbeauford "at" EightInOnePet.com
Mon Sep 18 21:43:01 2006
Lloyd Abberton wrote:
> Dear Sir / Madam
>
> I think VNC is great.
>
> I have a windows xp sp2 pc, and I was running vnc v 4.1.1, but I got
> hacked.
>
> I now have version 4.1.2, can someone tell me the best way to protect
> myself when running vnc please?
>
> I have an encryption password set, but what more can i do to protect
> myself whe using vnc.
>
> Thanks
>
> Lloyd
Don't worry too much now. 4.1.1 had a known exploit.
http://www.securityfocus.com/archive/1/433994
If you've upgraded, you should be good to go.
But just in case, here are some ideas:
Tunnel it over SSH http://www.erikjheels.com/vnc-over-ssh.html
Use non standard ports
http://www.tweakxp.com/article37251.aspx
Restrictive firewall ACL's that grant access to small selection of known
originating IP's
Hamachi
http://www.help2go.com/Tutorials/Software_Utilities/Remote_Control_Anoth
er_PC_Securely_with_VNC_and_Hamachi.html
http://www.hamachi.cc/
VPN
Check out SSL-Explorer. It has a VNC plugin.
http://sourceforge.net/projects/sslexplorer/
And of course,
Complex passwords.
Cheers!
JMB