Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Late to the party and a noob. Can someone explain a bit about what this is all about?


VNC Server is an application that allows you to have remote access to my PC. Once installed you can use any other PC (or a phone/tablet) that has the client VNC software installed to connect to it and remotely login as if you were sitting in front of it. VNCRoulette is a site that is scanning for these servers on the Internet, logging in, and taking a screenshot of the desktop. VNC can be secure with an extra logon password, but a lot of systems and users don't bother. It's this vulnerabiltiy that VNCroulette is exploiting. Most of the PCs it's connecting to are 'read only' so the remote access can only see the desktop and not interact with it, but a good many are read/write with no restrictions.


Whoa! Thanks! Shouldn't these also be notified of the vulnerability? Some of the screen shots look sensitive information.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: