daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-vnc.md (3139B)


      1 ---
      2 title: "5800,5801,5900,5901 - Pentesting VNC"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-vnc.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-vnc.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 5800,5801,5900,5901 - Pentesting VNC
     14 
     15 ## Basic Information
     16 
     17 **Virtual Network Computing (VNC)** uses the Remote Framebuffer (RFB) protocol to display and control a remote graphical interface. The client receives framebuffer updates and sends keyboard and pointer events to the server.<sup>[[1]](#references)</sup>
     18 
     19 RFB is registered on TCP port **5900**.<sup>[[1]](#references)</sup> VNC deployments commonly map displays to `5900 + display_number` and optional web viewers to `5800 + display_number`, so ports 5800, 5801, 5900, and 5901 are useful enumeration targets.<sup>[[2]](#references)</sup>
     20 
     21 ```text
     22 PORT    STATE SERVICE
     23 5900/tcp open  vnc
     24 ```
     25 
     26 ## Enumeration
     27 
     28 Nmap can collect RFB protocol and desktop-title information, and Metasploit can check whether a server accepts the `None` authentication type.<sup>[[4]](#references)[[5]](#references)</sup>
     29 
     30 ```bash
     31 nmap -sV --script vnc-info,realvnc-auth-bypass,vnc-title -p <PORT> <IP>
     32 msf> use auxiliary/scanner/vnc/vnc_none_auth
     33 ```
     34 
     35 ### [**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#vnc)
     36 
     37 ## Connect with a VNC viewer
     38 
     39 ```bash
     40 vncviewer [-passwd passwd.txt] <IP>::5901
     41 ```
     42 
     43 ## Recovering stored VNC passwords
     44 
     45 Some VNC implementations store a password in `~/.vnc/passwd`.<sup>[[3]](#references)</sup>
     46 
     47 The legacy VNC password-file format uses DES with a fixed, publicly known key and truncates passwords to eight characters. The `vncpwd` utility can recover the plaintext from this format.<sup>[[1]](#references)[[3]](#references)</sup>
     48 
     49 ```bash
     50 make
     51 vncpwd <vnc password file>
     52 ```
     53 
     54 An archived Windows-compatible copy is attached here for convenience. It includes `vncpwd.exe` and the C source. The program accepts either a `.vnc` file or an encrypted password in raw or hexadecimal form, and the Windows build can also enumerate supported stored passwords from the registry:<sup>[[3]](#references)</sup>
     55 
     56 ```batch
     57 vncpwd.exe <file.vnc-or-encrypted-password>
     58 ```
     59 
     60 [Vncpwd.Zip](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/vncpwd.zip)
     61 
     62 ## Shodan
     63 
     64 - `port:5900 RFB`
     65 
     66 ## References
     67 
     68 - [1] [RFC 6143: The Remote Framebuffer Protocol](https://www.rfc-editor.org/rfc/rfc6143)
     69 - [2] [Wireshark Wiki: VNC](https://wiki.wireshark.org/VNC)
     70 - [3] [jeroennijhof/vncpwd: VNC password-file decryption tool](https://github.com/jeroennijhof/vncpwd)
     71 - [4] [Nmap NSE documentation: `vnc-info`](https://nmap.org/nsedoc/scripts/vnc-info.html)
     72 - [5] [Rapid7: VNC authentication-none scanner](https://www.rapid7.com/db/modules/auxiliary/scanner/vnc/vnc_none_auth/)