Live data from Hacker News

World of VNC

worldofvnc.net

31–40 of 40 posts

Re: World of VNC

#31
i think it is obligatory to mention that Intel CPUs (which have vPro enabled, ie. Xeons and some others) have VNC server built-in on the chip.

Re: World of VNC

#33
post #13

Geezus he included the hostnames and IPs? This is so insanely irresponsible.

I'd argue it's responsible. Security through obscurity is no security at all.

Avoiding security through obscurity is a topic for people in the crypto industry. Random people with misconfigured VNC servers most likely aren't computer experts, and revealing their addresses is pointless and irresponsible. Yes, maybe making this information public will cause them to fix their configuration. More likely, they will just be attacked.

Re: World of VNC

#34
I'm interested to see that they only found 3567 open servers, whereas a scan I have from a couple years ago shows 7573 entries.

Now is it just a difference in scanned ports or a genuine improvement in security, I can't tell, but I can only hope.

Re: World of VNC

#38
post #3

>> I found 3567 servers that were unprotected. That's pretty low for scanning the whole internet. Either VNC isn't used that much or I was simply expecting 10 times as many servers.

It is low, Shodan has found more than 10,000 VNC that have disabled authentication:

https://www.shodan.io/search?query=rfb+authentication+disabl...

And there are roughly 550,000 VNC servers on the Internet:

https://www.shodan.io/search?query=rfb

Re: World of VNC

#39
post #34

I'm interested to see that they only found 3567 open servers, whereas a scan I have from a couple years ago shows 7573 entries. Now is it just a difference in scanned ports or a genuine improvement in security, I can't tell, but I can only hope.

Their numbers are too low. Shodan has found closer to 12,000 servers that have disabled authentication.
Post reply on HN