Metasploit mailing list archives

VNC Payload


From: hdm at metasploit.com (H D Moore)
Date: Tue, 28 Sep 2004 18:17:28 -0500

Due to the way that the VNC service is injected, the server has to run in 
"poll" mode, where it refreshes the entire screen once every 250ms. This 
can result in a sluggish session when exploiting systems on a slow link. 
If you are used to standard VNC, the VNC payload will always seem less 
responsive. A standard VNC installation uses "hooks" to capture screen 
updates as they happen, however this mode does not work well with DLL 
injection. If you would like to take a whack at improving it, the source 
code and VS solution files are in the "src" subdirectory of the Framework 
installation :)

-HD

On Tuesday 28 September 2004 17:48, eip wrote:
I have been using the VNC payload against a Win2K server (no patches)
in VMWare. The VNC session is very sluggish. I checked the CPU and it
is almost idle. Is anyone else having this problem?


eip



Current thread: