In a message dated 1/8/2003 8:33:19 AM Eastern Standard Time, [EMAIL PROTECTED] writes:
> > > when on one is logged on or Admin is logged on. Is there a work around > > for security issues like this? Mike > > I've tried CACLing the registry section, but without read permissions - you can't > log into the remote box. I think this is as the user read the password when you > attempt to log in remotely. On another note, I don't know how this affects a > user sending their screen to you (as no password is involved then). > > Ideally, you'd want the System account to make the check rather than via a > user account. That way you could deny all users read on the password section, > but still use VNC. > > This is where NTLM authentication would be very useful, however not all VNC > flavours support it. I can think of Tridia Pro (which is paid for), an old VNC 3.3.2 > NTLM release and Ultra (although Ultra is in beta and 1.4 - I think - always has > to have a VNC password set even if you plan to use NTLM). > > Any developers listening?? :-) > > Out of curiosity - how does linux handle authentication? Is it just an ini file > buried somewhere or can you use PAM too? > > Later, > Richard > > --------------------------------- > Richard Harris > Environment IT, NCC > Ext 4509 > --------------------------------- > > "Service, price , quality: pick any two." > > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager via NCC Help Desk (0115) 9772010. > > This footnote also confirms that this email message has > been swept > for the presence of computer viruses. > > Nottinghamshire County Council Legal Disclaimer > _______________________________________________ > VNC-List mailing list > [EMAIL PROTECTED] > http://www.realvnc.com/mailman/listinfo/vnc-list > > > This question is Not about changing the Registry values, but just seeing the value of HKEY_USERS\VNC values. There is a VNC Hack called X4.exe that will crack the password once you have the hex value of it. Hence a user can now VNC into another p/c by using the password. I'm tring to have the user Not be able to see the HKEY_USERS\Software\VNC values. But if they can Not see the values, you can Not VNC into their p/c with them logged on.I already have the users locked out of KKEY_LM. Mike _______________________________________________ VNC-List mailing list [EMAIL PROTECTED] http://www.realvnc.com/mailman/listinfo/vnc-list
