pentesting-vnc.md (3139B)
1 --- 2 title: "5800,5801,5900,5901 - Pentesting VNC" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-vnc.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-vnc.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 5800,5801,5900,5901 - Pentesting VNC 14 15 ## Basic Information 16 17 **Virtual Network Computing (VNC)** uses the Remote Framebuffer (RFB) protocol to display and control a remote graphical interface. The client receives framebuffer updates and sends keyboard and pointer events to the server.<sup>[[1]](#references)</sup> 18 19 RFB is registered on TCP port **5900**.<sup>[[1]](#references)</sup> VNC deployments commonly map displays to `5900 + display_number` and optional web viewers to `5800 + display_number`, so ports 5800, 5801, 5900, and 5901 are useful enumeration targets.<sup>[[2]](#references)</sup> 20 21 ```text 22 PORT STATE SERVICE 23 5900/tcp open vnc 24 ``` 25 26 ## Enumeration 27 28 Nmap can collect RFB protocol and desktop-title information, and Metasploit can check whether a server accepts the `None` authentication type.<sup>[[4]](#references)[[5]](#references)</sup> 29 30 ```bash 31 nmap -sV --script vnc-info,realvnc-auth-bypass,vnc-title -p <PORT> <IP> 32 msf> use auxiliary/scanner/vnc/vnc_none_auth 33 ``` 34 35 ### [**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#vnc) 36 37 ## Connect with a VNC viewer 38 39 ```bash 40 vncviewer [-passwd passwd.txt] <IP>::5901 41 ``` 42 43 ## Recovering stored VNC passwords 44 45 Some VNC implementations store a password in `~/.vnc/passwd`.<sup>[[3]](#references)</sup> 46 47 The legacy VNC password-file format uses DES with a fixed, publicly known key and truncates passwords to eight characters. The `vncpwd` utility can recover the plaintext from this format.<sup>[[1]](#references)[[3]](#references)</sup> 48 49 ```bash 50 make 51 vncpwd <vnc password file> 52 ``` 53 54 An archived Windows-compatible copy is attached here for convenience. It includes `vncpwd.exe` and the C source. The program accepts either a `.vnc` file or an encrypted password in raw or hexadecimal form, and the Windows build can also enumerate supported stored passwords from the registry:<sup>[[3]](#references)</sup> 55 56 ```batch 57 vncpwd.exe <file.vnc-or-encrypted-password> 58 ``` 59 60 [Vncpwd.Zip](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/vncpwd.zip) 61 62 ## Shodan 63 64 - `port:5900 RFB` 65 66 ## References 67 68 - [1] [RFC 6143: The Remote Framebuffer Protocol](https://www.rfc-editor.org/rfc/rfc6143) 69 - [2] [Wireshark Wiki: VNC](https://wiki.wireshark.org/VNC) 70 - [3] [jeroennijhof/vncpwd: VNC password-file decryption tool](https://github.com/jeroennijhof/vncpwd) 71 - [4] [Nmap NSE documentation: `vnc-info`](https://nmap.org/nsedoc/scripts/vnc-info.html) 72 - [5] [Rapid7: VNC authentication-none scanner](https://www.rapid7.com/db/modules/auxiliary/scanner/vnc/vnc_none_auth/)