Hello forum !
We very thankfully use Ultra VNC SC, using an unique rc4Key as well as the MSRC4Plugin.dsm.
A Customer/friend asking for support can download the SC-executable from our website using a simple http Link anytime. That way help is easily accessible for the ones needing it.
However:
As the executable SC file is openly accessible by anyone who knows or finds the Download Link, my question:
1. Is this dangerous and a security issue ?
2. Can someone who downloads the SC executable (where the rc4 key is integrated) intercept an ongoing connection between me and a client ?
3. And if it makes the connections interceptable, what simple alternative would you propose ?
Thank you,
.
Celebrating the 22th anniversary of the UltraVNC: https://forum.uvnc.com/viewtopic.php?t=38031
Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: https://forum.uvnc.com/viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Bluesky/AT Protocol: https://bsky.app/profile/ultravnc.bsky.social
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: https://forum.uvnc.com/viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864
Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Bluesky/AT Protocol: https://bsky.app/profile/ultravnc.bsky.social
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc
Security issue with downloadable U-VNC SC executable
Security issue with downloadable U-VNC SC executable
Last edited by grog on 2008-11-18 09:55, edited 4 times in total.
Re: Security issue with downloadable U-VNC SC executable
Hey, hows it hanging ?
Do not tell me nobody knows an answer ??
Do not tell me nobody knows an answer ??
Re: Security issue with downloadable U-VNC SC executable
erm once you download once and browser/download page closed no one can find that link unless hacked your computer and vieweing history/cache
not sure if link stays live forever I dont think so but I may be wrong.
not sure if link stays live forever I dont think so but I may be wrong.