Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: https://forum.uvnc.com/viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864

Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc

General security question for SC using port forwarding

Single Click discussions / bugs
Post Reply
dghundt
8
8
Posts: 14
Joined: 2009-04-11 21:01

General security question for SC using port forwarding

Post by dghundt »

I am using port forwarding for my viewer which is listening to outside requests from SC.
Since I will leave this port open on my computer, what security issues do I need to worry about? what general security steps do I need to take to prevent hacks into my computer via this port? Thank you.
nobody
20
20
Posts: 37
Joined: 2009-04-03 11:13

Re: General security question for SC using port forwarding

Post by nobody »

in port forwarding biggest risk is someone else capturing your secreat data so i would recommend using dsm plugins

of recent there have been various security risks in the viewer running in listing mode ( see up just below the address bar, even now you can see Please update your viewer to 1.0.5.4! Read on about the found vulnerability. that is what i mean, never keep the viewer running in a listening state unless you are using a vpn and a firewall.


also open ports are not security risks.

how are you connected to the internet ? using a router and a nat ? that should provide some protection.

however if you are directly connected to the internet then use some security software. i would recommend comodo ( its free, has all : antivirus firewall and hips )
http://www.personalfirewall.comodo.com/ ... ewall.html however this software is for technical users or power users or people who understand what is happening in their pc ..

or use any security software that you are comfortable with on both the sides of the ultravnc ie on the client and server side
dghundt
8
8
Posts: 14
Joined: 2009-04-11 21:01

Re: General security question for SC using port forwarding

Post by dghundt »

Thanks. A few answers to your questions

I am using the dsm plugin.

I have a standard dlink gamer router with all the default settings (except for passwords!) connected to cable internet. The listening pc is behind the router and has a commercial software firewall.

I do not have vpn. Is this essential?

The main concern I wanted to understand and avoid was the risk of someone using the port I have opened and forwarded to take control of the listening pc.
nobody
20
20
Posts: 37
Joined: 2009-04-03 11:13

Re: General security question for SC using port forwarding

Post by nobody »

I do not have vpn. Is this essential?

The main concern I wanted to understand and avoid was the risk of someone using the port I have opened and forwarded to take control of the listening pc.
not a problem - since you are using dsmplugins - VPN was for added security since you are using dsmplugins no need for vpn

to prevent someone from taking control of your pc without your authorization use a key file + strong password and your will be very much secure - nothing to worry about for a tutorial about how to generate a secure password go to http://www.diceware.com



and if what you told in the above post it would seem that you are secure enough.
Last edited by nobody on 2009-04-13 02:36, edited 2 times in total.
dghundt
8
8
Posts: 14
Joined: 2009-04-11 21:01

Re: General security question for SC using port forwarding

Post by dghundt »

Thanks.
By key file, I assume you mean the ultravnc key file. I was not aware of one with windows.
By password I assume you mean the windows pc users passwords (SC does not have password access as well?)
nobody
20
20
Posts: 37
Joined: 2009-04-03 11:13

Re: General security question for SC using port forwarding

Post by nobody »

.
By key file, I assume you mean the ultravnc key file. I was not aware of one with windows.
Correct
By password I assume you mean the windows pc users passwords (SC does not have password access as well?)
yes, i normally use the MSLOGIN2 which makes windows and ultravnc password the same and this can be even same as the Active dir - almost one password everywhere
User avatar
JDaus
Friend of UVNC
Friend of UVNC
Posts: 537
Joined: 2007-03-17 11:00
Location: Sydney, Australia
Contact:

Re: General security question for SC using port forwarding

Post by JDaus »

dghundt wrote:I am using port forwarding for my viewer which is listening to outside requests from SC.
Since I will leave this port open on my computer, what security issues do I need to worry about? what general security steps do I need to take to prevent hacks into my computer via this port? Thank you.
there is minimal risk having an application like the viewer listening on your computer.

if your concerned about it, simply close the app when not needed, then any connection attempt on that port simple goes no-where ...

there would be only a few people in the world that MAY know how to get somewhere using this forwarded (but not listening) port, and i doubt they are interested in small fries like us ... :P

its good to be asking questions about security, but in this regard, the risk is minimal (in my opinion anyway)

relax and enjoy
ask a silly question and remain a fool for 5 minutes...
don't ask, and remain a fool for life - JDaus 2003

without imperfections, neither you nor i would exist - Steven Hawkins
__
JD
SCPrompt - OpenSource Free Remote Screen\Desktop Sharing Solution
SecureTech.com.au
Post Reply