344
Real VNC Server Detection
HTTP
2007/07/24
Po Naing Lin
ponainglin at gmail dot com
http://www.popularmyanmar.com
poplarmyanmar.com
4.1
tcp
5800
open|send HEAD / HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/1.[0-1] ### *Server: RealVNC*
10
This plugin was written with the ATK Attack Editor.
Real VNC servers
All other web server implementations
Configuration
An attacker who is able to get a direct connection to the port can identify the banner of this server as REAL VNC. By this knowledge further enumerations and attacks are possible.
Use Password Authentication
1 hour
Yes
Yes
Yes
Low
9
8
5
4
39
Most scanners (e.g. N-Stealth, Whisker, Nikto) and security scanners (e.g. Nessus) are able to detect the used server.