In a message dated 1/8/2003 8:33:19 AM Eastern Standard Time, 
[EMAIL PROTECTED] writes:

> 
> > when on one is logged on or Admin is logged on. Is there a work around
> > for security issues like this? Mike
> 
> I've tried CACLing the registry section, but without read permissions - you can't
> log into the remote box. I think this is as the user read the password when you
> attempt to log in remotely.  On another note, I don't know how this affects a
> user sending their screen to you (as no password is involved then).
> 
> Ideally, you'd want the System account to make the check rather than via a
> user account. That way you could deny all users read on the password section,
> but still use VNC.
> 
> This is where NTLM authentication would be very useful, however not all VNC
> flavours support it. I can think of Tridia Pro (which is paid for), an old VNC 3.3.2
> NTLM release and Ultra (although Ultra is in beta and 1.4 - I think - always has
> to have a VNC password set even if you plan to use NTLM).
> 
> Any developers listening?? :-)
> 
> Out of curiosity - how does linux handle authentication? Is it just an ini file
> buried somewhere or can you use PAM too?
> 
> Later,
> Richard
> 
> ---------------------------------
> Richard Harris
> Environment IT, NCC
> Ext 4509
> ---------------------------------
> 
> "Service, price , quality: pick any two."
> 
> 
> This email and any files transmitted with it are confidential and
> intended solely for the use of the individual or entity to whom they
> are addressed. If you have received this email in error please notify
> the system manager via NCC Help Desk (0115) 9772010.
> 
> This footnote also confirms that this email message has 
> been swept
> for the presence of computer viruses.
> 
> Nottinghamshire County Council Legal Disclaimer
> _______________________________________________
> VNC-List mailing list
> [EMAIL PROTECTED]
> http://www.realvnc.com/mailman/listinfo/vnc-list
> 
> 
>
This question is Not about changing the Registry values, but just seeing the value of 
HKEY_USERS\VNC values. There is a VNC Hack called X4.exe that will crack the password 
once you have the hex value of it. Hence a user can now VNC into another p/c by using 
the password. I'm tring to have the user Not be able to see the 
HKEY_USERS\Software\VNC values. But if they can Not see the values, you can Not VNC 
into their p/c with them logged on.I already have the users locked out of KKEY_LM.
Mike
_______________________________________________
VNC-List mailing list
[EMAIL PROTECTED]
http://www.realvnc.com/mailman/listinfo/vnc-list

Reply via email to