I'm using the free vnc server version 4.1.2

This is NOT a real vulnerability, as the user has to be logged on the server. (But there are some stupid users, and some malententioned ones)

Here is how this "bug" happens :
log onto a windows vnc server. run "cmd".
now press "ALT + enter" so the cmd will turn to full screen mode.

windows quit the graphical mode and turns into text mode, so vnc is not really "guilty". But, this way, you loose the vnc connection, and can't establish a new one until you physically go to the server and press "ALT + enter" again to exit the text mode...

what could be done :
- more explicit error message in the vnc-viewer
- some kind of hook that prevents windows from switching to text mode when an user is logged - some kind of hook that automatically switch windows to graphic mode when an user is connecting.
_______________________________________________
VNC-List mailing list
VNC-List@realvnc.com
To remove yourself from the list visit:
http://www.realvnc.com/mailman/listinfo/vnc-list

Reply via email to