TCP Port 5900
Common Use
Virtual Network Computer (VNC).
Inbound Scan
Currently inbound scans are likely looking for either VNC computers with weak
password or trying to exploit buffer oveflow vulnerability within UltraVNC (
http://www.kb.cert.org/vuls/id/721460 ) or a vulnerability where RealVNC
Server fails to properly authenticate clients (
http://www.kb.cert.org/vuls/id/117929 ).
Outbound Scan
Outbound scans if occurring in volume should be considered an indication of a
possible worm infection on the source computer and should be investigated or a
remote connection to a VNC enabled system.
Additional Information
http://isc.sans.org/port.html?port=5900
Page last updated on
November 29, 2008
|