Penetration Testing mailing list archives

Re: [PEN-TEST] Decrypting VNC passwords - Tool required


From: "Batten, Gerald" <GBatten () EXOCOM COM>
Date: Tue, 22 Aug 2000 11:00:09 -0400

There's a tool called vnccrack.  You can find a copy of it here:
http://www.phenoelit.de/  If you give it the encrypted password, it will
decrypt it for you as well.  I find this usefull when customers ask me if
VNC is safe to use as an administration tool.

Gerald Batten
Security Consultant
EXOCOM

*Note: views expressed in this communication are not those of my employer's.

*Note2: They're not necessarily mine either.

-----Original Message-----
From: erica bernt [mailto:erica_bbb () YAHOO COM]
Sent: Monday, August 21, 2000 5:37 AM
To: PEN-TEST () SECURITYFOCUS COM
Subject: Decrypting VNC passwords - Tool required


Hi Everyone,

I was doing an audit of some systems and managed to
penetrate into the NT domain. I see that VNC is
installed and so I picked up the DES encrypted
password from the registry. As per :

http://www.securiteam.com/securitynews/VNC_3_3_2_R6_uses_a_wea
k_password_protection_mechanism.html

My specific questions to you is what tool would you
recommend to decrypt this password ? and are there any
other ways to attack VNC ?

On a more general level, what are the most formidable
remote management tools that are out there that you
have most difficulty to detect and penetrate ?

regards Erica


__________________________________________________
Do You Yahoo!?
Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/



Current thread: