当前位置:网站首页>6-24 exploit-vnc password cracking
6-24 exploit-vnc password cracking
2022-08-02 01:37:00 【Mountain Rabbit 1】

Introduction to VNC
VNC (Virtual Network Console) is the abbreviation of Virtual Network Console.It is an excellent remote control tool software developed by the famous AT&T European research laboratory.It is mainly used for visual control, similar to the remote desktop. The ssh and rlogin we have contacted before are the control terminals of the command line, but VNC is a little different from the remote desktop. The remote desktop is open to 3389, while the VNC server is open.By default it runs on port 5900
nmap 192.168.1.105
Port 5900 is usually open to the VNC server
Detect target VNC
Use nmap -sV -p 5900 IP address to probe the target VNC version information.
nmap -sV -p 5900 192.168.1.105
msf crack VNC password
See if there is a weak password to log in. After logging in, we can visually operate our system through the channel connecting the VNC client to the server
The vnc_login module can be used to crack the VNC server authentication username and password under msf

msfconsoleuse auxiliary/scanner/vnc/vnc_loginshow options
set rhosts 192.168.42.137run
Crack result: username is empty, password is password
vnc client login
Under windows, install the vnc viewer client software to connect to the VNC server. There is also a corresponding version under linux. You can download the vnc viewer on the Internet

After we log in with VNC, we are a user with root privileges, and we can perform arbitrary operations here
If VNC is so simple to be cracked, VNC will be used by more people, making it simple to execute commands, perform visual operations, and operate on our server, which is very dangerous and has security risksYes, in order to prevent this from happening, we can set the password verification corresponding to VNC. Its password is very complicated. At this time, we cannot crack it and monitor it in real time
Limit the number of logins and the threshold to make VNC more secure. At the same time, you can also set up a firewall to prevent other IPs from logging in. VNC can only log in with a fixed IP, which ensures VNC to a large extent.Service security, and server security
边栏推荐
猜你喜欢

HSDC和独立生成树相关

S/4中究竟有多少个模块,你对这些模块了解多少

Can't connect to MySQL server on 'localhost3306' (10061) Simple and clear solution

力扣 1161. 最大层内元素和

datagrip连接mysql数据库

Interview: Briefly describe a project you are involved in

Redis和MySQL数据一致性问题,有没有好的解决方案?

go mode tidy出现报错go warning “all“ matched no packages

【刷题篇】打家劫舍

记录一次数组转集合出现错误的坑点,尽量使用包装类型数组进行转换
随机推荐
Go 1.18 的那些事——工作区、模糊测试、泛型
datagrip连接mysql数据库
传统企业数字化转型需要经过几个阶段?
flowable工作流所有业务概念
MInIO入门-03 秒传+大文件分片上传
3 Month Tester Readme: 4 Important Skills That Impacted My Career
Kubernetes — Calico
接口(第九天)
Flink_CDC construction and simple use
canal realizes mysql data synchronization
管理基础知识10
Flex布局详解
H5页面调用微信授权获取code
C语言:打印整数二进制的奇数位和偶数位
C语言实验九 函数(一)
hash table
飞桨助力航天宏图PIE-Engine地球科学引擎构建
Detailed explanation of fastjson
Oracle data to mysql FlinkSQL CDC to achieve synchronization
typescript37-class的构造函数实例方法继承(extends)