How secure is it running a VNC service?

Soldato
Joined
14 Aug 2018
Posts
3,393
I've run a VNC service for years but recently hadn't done so due to issues with Win10 working with the TigerVNC variant I used. I thought I'd try the original TightVNC that I used to use and it worked great.

During my initial setup and test phase I configured the service with just a simple one letter lower case character to make it quick and easy to test. Before I could configure it with my normal 14 character (with symbols numbers etc) somebody hacked into my computer and took control. I wasn't too surprised and found it quite interesting, as I've read about this before, so watched to see what they would do. They opened a browser and went to Paypal.com, no doubt to do a transfer to an account. I then shut them down, though my Paypal password is never stored (or any other bank/money details).

It got me thinking whether my normal 14 character password would prove too much for current hacking tools. If you google "VNC Hacked" you see pages that blatantly offer several tools to hack VNC logins.
 
Last edited:
Soldato
OP
Joined
14 Aug 2018
Posts
3,393
Use a VPN. Don't leave things like that open to the world.
As far as I know a VPN won't allow me to control my computer from my phone, which is what I currently do via VNC. I could use Remote Desktop though that did not work well with multiple monitors and I'm running 4.
I have a VPN server running on my Asus AC68U router.
 
Soldato
OP
Joined
14 Aug 2018
Posts
3,393
You load a VPN client on your phone (Android had them built in) and only VNC after that. Leaving VNC on the live internet is asking for attack attempts.
Ok, I have a VPN client on my phone that I normally just use to connect back to my network when I'm abroad so I can watch IPlayer or I'm on an unsecure WiFi etc.

So do I configure VNC so that it can only be accessed from my network?
 
Soldato
OP
Joined
14 Aug 2018
Posts
3,393
Own a Synology? Setup OpenVPN on it and forward a port for VPN to the Synology.

Own a Pi? Install pivpn
I own neither. ;)
My Virginmedia SH3 is in modem only mode.
I have an Asus AC68U with Merlin firmware running an OpenVPN server.
My Win10 PC is running TightVNC 2.8.11 64-bit

I normally control my PC from my phone using Jump Desktop v7.1.4. I do this to run some software on the PC and need more than just access to files.
 
Back
Top Bottom