Re: UltraVNC have vulnerability as RealVNC (US-CERT VU#117929)

[email protected] Thu, 18 May 2006 11:35:26 -0700
Newsgroups gmane.network.vnc.ultravnc.general
Message-ID <OFF6574B96.FC217A60-ON88257172.00657DC9-88257172.00661F5D@2roads.com>
For feature requests and bug reports RC15 RC16. Please use the forum at http://forum.ultravnc.net/

This is a multipart message in MIME format.
--=_alternative 00661F5888257172_=
Content-Type: text/plain; charset="US-ASCII"

Hi Scott,

Apparently this list is not being used much anymore -- at least not as 
much as the UltraVNC forums. This topic has been discussed in the forum in 
a couple of different threads, and the unofficial answer is that UltraVNC 
is not affected (maybe there is an official answer by now; I'm not sure). 
In fact, only one particular version of RealVNC appears to be vulnerable.

Anyway, go to http://forum.ultravnc.net and search or browse for this 
topic. It was posted to the "Bugs Rel 1.00" forum, but might be in others 
as well.

-- Mark





Scott Copus <[email protected]> 
Sent by: [email protected]
05/18/2006 10:21 AM

Please respond to
[email protected]


To
[email protected]
cc

Subject
[Ultravnc-list] UltraVNC have vulnerability as RealVNC (US-CERT VU#117929)






For feature requests and bug reports RC15 RC16. Please use the forum at 
http://forum.ultravnc.net/

Does anyone know if UltraVNC has the same vulnerability as US-CERT 
advises for RealVNC?  see link below.

US-CERT VU#117929:
RealVNC Server does not validate client authentication method
http://www.kb.cert.org/vuls/id/117929

Does anyone have proof of concept code for me to test vulnerability on 
my systems with UltraVNC installed?

thanks,
Scott



-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job 
easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642

ForwardSourceID:NT000D1926 

--=_alternative 00661F5888257172_=
Content-Type: text/html; charset="US-ASCII"


<br><font size=2 face="sans-serif">Hi Scott,</font>
<br>
<br><font size=2 face="sans-serif">Apparently this list is not being used
much anymore -- at least not as much as the UltraVNC forums. This topic
has been discussed in the forum in a couple of different threads, and the
unofficial answer is that UltraVNC is not affected (maybe there is an official
answer by now; I'm not sure). In fact, only one particular version of RealVNC
appears to be vulnerable.</font>
<br>
<br><font size=2 face="sans-serif">Anyway, go to </font><a href="218.209.0.0 - 218.209.255.255"><font size=2 color=blue face="sans-serif">http://forum.ultravnc.net</font></a><font size=2 face="sans-serif">
and search or browse for this topic. It was posted to the &quot;Bugs Rel
1.00&quot; forum, but might be in others as well.</font>
<br>
<br><font size=2 face="sans-serif">-- Mark</font>
<br>
<br>
<br>
<br>
<br>
<table width=100%>
<tr valign=top>
<td width=40%><font size=1 face="sans-serif"><b>Scott Copus &lt;[email protected]&gt;</b>
</font>
<br><font size=1 face="sans-serif">Sent by: [email protected]</font>
<p><font size=1 face="sans-serif">05/18/2006 10:21 AM</font>
<br>
<table border>
<tr valign=top>
<td bgcolor=white>
<div align=center><font size=1 face="sans-serif">Please respond to<br>
[email protected]</font></div></table>
<br>
<td width=59%>
<table width=100%>
<tr>
<td>
<div align=right><font size=1 face="sans-serif">To</font></div>
<td valign=top><font size=1 face="sans-serif">[email protected]</font>
<tr>
<td>
<div align=right><font size=1 face="sans-serif">cc</font></div>
<td valign=top>
<tr>
<td>
<div align=right><font size=1 face="sans-serif">Subject</font></div>
<td valign=top><font size=1 face="sans-serif">[Ultravnc-list] UltraVNC
have vulnerability as RealVNC (US-CERT VU#117929)</font></table>
<br>
<table>
<tr valign=top>
<td>
<td></table>
<br></table>
<br>
<br>
<br><font size=2><tt>For feature requests and bug reports RC15 RC16. Please
use the forum at http://forum.ultravnc.net/<br>
<br>
Does anyone know if UltraVNC has the same vulnerability as US-CERT <br>
advises for RealVNC? &nbsp;see link below.<br>
<br>
US-CERT VU#117929:<br>
RealVNC Server does not validate client authentication method<br>
http://www.kb.cert.org/vuls/id/117929<br>
<br>
Does anyone have proof of concept code for me to test vulnerability on
<br>
my systems with UltraVNC installed?<br>
<br>
thanks,<br>
Scott<br>
<br>
<br>
<br>
-------------------------------------------------------<br>
Using Tomcat but need to do more? Need to support web services, security?<br>
Get stuff done quickly with pre-integrated technology to make your job
easier<br>
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo<br>
http://sel.as-us.falkag.net/sel?cmd=lnk&amp;kid=120709&amp;bid=263057&amp;dat=121642<br>
</tt></font>
<br><font size=2 color=white face="sans-serif">ForwardSourceID:NT000D1926
&nbsp; &nbsp;</font>
<br>
--=_alternative 00661F5888257172_=--


-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642