HN user

supersheep

11 karma
Posts0
Comments4
View on HN
No posts found.
VNC Roulette 12 years ago

Shodan has existed for years and does practically the same thing (enumerates services, etc), but to a far greater extent.

Good point. But it's not laser-focused on a single thing and making that thing as easy as possible (I can just click on an image and be connected to the server!)

How?

For some hosts it will be impossible. For others, it may be obvious or at least feasible; the company's name may be in the FQDN, the server may give a name in the VNC response that could be used, and if you're feeling grey-hat you could poke around and see what it does and who may own it.

The argument that a site like this should not exist because someone may exploit it just doesn't hold up

I didn't say it shouldn't exist - just that some minimum form of self-censorship is the ethical course of action.

Someone will do it...

Of course. But not everyone will make it this easy and accessible.

And I can appreciate the spirit in which this is done, if the "Hail Eris!" text on the page didn't make it obvious :) Being able to flag stuff is the concession, assuming it really does remove it from rotation.

VNC Roulette 12 years ago

The site operator has done nothing that has not already been done before, and it's little more than a basic nmap scan for services (which anyone can do).

I realise this. Which is why I carefully phrased the objection as "easy-to-exploit". You and I may think the phrase "basic nmap scan" is simple, but it opens the door to lots of people who don't know what that sentence means but can easily click a link in their browser and be directly connected to an exploitable host (I don't like the phrase 'script kiddie' but I think that conveys what I mean).

It might be considered unethical that a PLC system is using VNC with no password.

It might. It might also be more properly called incompetence. But that's orthogonal to providing an easy way to exploit such a system and not notifying the operator, which I feel is "more unethical" if such a concept exists.

There are ways to do this if the intent was to highlight how many people run open VNC server (as I'm guessing is implied by calling the site Srsly?)

1) Don't publish the server's hostname and port.

2) Attempt to notify the operator.

3) Publish screenshots only.

By publishing the connection details, this turned something that could have been interesting and done some public good into something that I feel is dangerous and fairly exploitative.

VNC Roulette 12 years ago

This feels unethical to me.

I've just seen a VNC session on a machine running some PLC software (I've flagged it). There could be god knows what running open VNC sessions in here, and it feels unethical to expose this in an easy-to-exploit way without making a best-efforts attempt to contact the operator.

I've seen a few VNC desktops that now have Paint open (or similar) with messages informing people that they have an open VNC server, but altruism is unlikely to be the norm.

It's a cool idea and it's really well done, but I do wish it was anonymised - no display of the host or port the VNC server is running on, just the screen. (I realise this might be useless in some cases where the screenshot lists the server's FQDN.)

The reason we say "Ubuntu" is that it's all we've had time to test against. I'm pretty sure the way we're presenting the repository metadata will work against Debian et. al., but I haven't tried it.

The goal is to support as many distributions as we can.