|
|||||||||||
|
Re: VNC game
From: Philip Rowlands <phr(at)doc.ic.ac.uk>
Date: Sun Dec 01 2002 - 20:40:11 EST On Fri, 29 Nov 2002 rsmc@tid.es wrote: >In it, we got to fake entries in the DNS server of the machines
You haven't really bypassed it - you're acting as a passive man-in-the-middle. It's not a trojan. > /* we must send VNC version number (from protocol) */
No, you have the challenge DES-encrypted by the password. Not the password DES-encrypted by the challenge. See section 5.1.2 of http://www.realvnc.com/docs/rfbproto.pdf. > /* we send the encrypted password to the VNC server */
I claim no particular expertise in crypto code, but I don't think there's anything here which helps you learn the password. Of course, you've hijacked the data stream, so you could read keystrokes, make screengrabs etc. The VNC site contains a page on wrapping up VNC inside SSH, for proper secure tunnelling. Cheers, Phil Received on Mon Dec 2 03:03:14 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT |
||||||||||
|
|||||||||||