Update: UltraVNC 1.4.3.6 and UltraVNC SC 1.4.3.6: https://forum.uvnc.com/viewtopic.php?t=37885
Important: Please update to latest version before to create a reply, a topic or an issue: https://forum.uvnc.com/viewtopic.php?t=37864

Join us on social networks and share our announcements:
- Website: https://uvnc.com/
- GitHub: https://github.com/ultravnc
- Mastodon: https://mastodon.social/@ultravnc
- Facebook: https://www.facebook.com/ultravnc1
- X/Twitter: https://x.com/ultravnc1
- Reddit community: https://www.reddit.com/r/ultravnc
- OpenHub: https://openhub.net/p/ultravnc

UltraVNC server password

Post Reply
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

UltraVNC server password

Post by Mr Wolf »

Hi to all!

Am I wrong... or the UltraVNC server password is stored in clear in the registry???
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

no
encrypted DES 56bit key

http://www.vidarholen.net/contents/junk/vnc.html

there a lot of software for read decrypt¦write encrypt vnc password
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

Re: UltraVNC server password

Post by Mr Wolf »

Ok... to be clear, I tried this utility:
http://www.nirsoft.net/utils/vnc_password.html
and I could read in clear my password...! AZZZ!!!
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

yes, it simply decrypt the DES 56bit of the vnc password located in the ultravnc.ini or registry
any user have access to ultravnc.ini can read and quickly find the password and decrypt it.

is main reason for switch to RFB 3.8 where the password is encrypted more strong and still open source.
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

Re: UltraVNC server password

Post by Mr Wolf »

Thanks for your answer!

But... how could it be so fast to decrypt password???

Btw... sorry for my ignorance, what is it RBF?
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

vnc password is low level encryption, is why so fast decrypted in seconds.

RFB = Remote Frame Buffer, the protocol of VNC
wiki is your friend
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

Re: UltraVNC server password

Post by Mr Wolf »

Ok!
But RFB is not supported by UltraVNC, right?
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

wrong

ultravnc use rfb protocol, otherwise, can't use the name VNC in the ultravnc name.

SingleClick use some function are not compatible RFB !
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

Re: UltraVNC server password

Post by Mr Wolf »

Ok... stupid question: how do I "activate" RFB with UltraVNC???
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

you can't activate ! is always activ, ultravnc use RFB protocol 3.3

some function of SC are not compatible with the RFB protocol standard.
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
User avatar
Mr Wolf
8
8
Posts: 26
Joined: 2008-09-09 21:07

Re: UltraVNC server password

Post by Mr Wolf »

Ok... now it's clear... sorry, I just USE UltraVNC, never interested about protocols!

So... UltraVNC uses RBF 3.3 (which uses a weak password encryption) and should pass to RBF 3.8?
Last edited by Mr Wolf on 2010-01-10 10:58, edited 1 time in total.
I'm Winston Wolf. I solve problems.
redge
1000
1000
Posts: 6797
Joined: 2004-07-03 17:05
Location: Switzerland - Geneva

Re: UltraVNC server password

Post by redge »

> RFB 3.8 is still backward compatible with RFB 3.3 password

yes
RFB use more strong password en

feature request for ultravnc use RFB 3.8 and backward compatible 3.3 for supporting older VNC including ultravnc.
wikipedia wrote:By default, VNC is not a secure protocol. While passwords are not sent in plain-text (as in telnet), brute-force cracking could prove successful if both the encryption key and encoded password are sniffed from a network. For this reason it is recommended that a password of at least 8 characters be used. On the other hand, there is also an 8-character limit on some versions of VNC; if a password is sent exceeding 8 characters, the excess characters are removed and the truncated string is compared to the password.
UltraVNC 1.0.9.6.1 (built 20110518)
OS Win: xp home + vista business + 7 home
only experienced user, not developer
Post Reply