RealVNC serious security issue with proof of concept

·


VNC is the abbreviation of: Virtual Network Computing if you didn’t know it.
There are many types of VNC such as TightVNC, RealVNC, UltraVNC and etc…

RealVNC
RealVNC is a remote control software which allows you to view and interact with one computer (the server) using a simple program (the viewer) on another computer anywhere on the Internet. The two computers don’t even have to be the same type. You can use RealVNC to view an office Linux machine on your Windows PC at home or help friends who are living far away without driving lots of miles.

Recently, there is a big security issue in RealVNC v4.1.1 discovered by Steve Wiseman.


It actually allows you to connect to any computer without password! Usually after vnc server installation, it will advice you to set a new password so not to allow any unauthorized user with VNC Viewer to remote control.
Just by modifying a few lines of code in the viewer, and the viewer is turned into a universal hacked viewer which can simply connect to any vnc server v4.1.1 without password.
Imagine what a person can do when there is a VNC Null Authentication Vulnerability Scanner!
He can scan the whole world of computers to find for VNC Server v4.1.1 and then use the hacked VNC viewer to connect to it. He will have 100% access to the computer.

If you are using RealVNC v4.1.1, PLEASE download the latest version v4.2.5 immediately because any minute a hacker can be viewing your VNC servers without knowing the password.

[ Download latest RealVNC v4.2.5 ]

Note: The below information is ONLY for educational purposes only.
You can download a copy of old RealVNC v4.1.1 from this link.
You can then use an already hacked version of VNC viewer that is able to connect to any RealVNC v4.1.1 servers without password.
RealVNC 4.1.0 – 4.1.1 (VNC Null Authentication) Vulnerability Scanners is also available here. It allows you to scan for computers that has RealVNC v4.1.1 servers installed.