Re: Ultra VNC-3DES-is it secure



On Jan 18, 2008 12:46 PM, pentestr <pentestr@xxxxxxxxx> wrote:
hi hackers,
I am doing a VA/PT for one our client and found one of the servers is
using Ultra VNC. The ports (5800 & 5900) are open to Internet. Is it
secure against Man in the middle attack?
Do I need to report this as a CRITICAL/HIGH security issue..

Thanks & Rgds.
P.T.


Personally, I would rate it as a critical issue. There are a number
of much more secure solutions
to remote server administration rather than ultra-vnc. I have not
reviewed the actual SSL plugin, but that can always be checked for
existing vulnerabilities depending on the version of OpenSSL
implemented.

Regards,
Randy

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: How the #$%& can it be possible!
    ... They should have had secured servers and controlled all the log ins and any ... who is doing what no matter how "secure" your servers are. ... some incredibly HUGE factor the tune changes, doesn't it weasel? ... My business with them is privacy, ...
    (alt.privacy)
  • Re: Securing Communication Between Domain Members and their Domain Controllers
    ... look into using an ipsec tunnel into a gateway computer or ipsec endpoint device or ... > located stand alone servers. ... > integrte them into a single secure Active Directory Domain. ... > member servers to communicate this way, looking through the MS tech. support ...
    (microsoft.public.win2000.security)
  • Re: How the #$%& can it be possible!
    ... They should have had secured servers and controlled all the log ins and any ... who is doing what no matter how "secure" your servers are. ... pebbles about Tor being "not really secure" because of it. ... some incredibly HUGE factor the tune changes, doesn't it weasel? ...
    (alt.privacy)
  • RE: Limiting system and filesystem access
    ... There is no supported and secure method of chroot'ing a user using ... any number of open source FTP servers will ... the file systems for our external customers. ...
    (RedHat)
  • Re: network security suggestion needed
    ... >>> The 2 DC's are used as File, Print, and Name servers to ... >>> secure configuration that I can. ... Is it the rest of your network they need ... I'd suggest isolating the finance information into as few ...
    (microsoft.public.security)