IGNORE: RFB Authentication

2001-10-26 Thread Chris Hare, CISSP, CISA
o many? Thanks //chris -- Chris Hare, CISSP, CISA [EMAIL PROTECTED] - To unsubscribe, mail [EMAIL PROTECTED] with the line: 'unsubscribe vnc-list' in the message BODY See also: http://www.uk.research.att.com/vnc/intouch.html -

RFB Authentication

2001-10-26 Thread Chris Hare, CISSP, CISA
missing something. the protocol spec also says the server can decided if there have been too many authentication failures. What is too many? Thanks //chris -- Chris Hare, CISSP, CISA [EMAIL PROTECTED] - To unsubscribe, mail [EMAIL

VNC Protocol trace

2001-10-26 Thread Chris Hare, CISSP, CISA
es in the trace, that would be very useful to the exercise I am undertaking. Thanks. Chris - -- Chris Hare, CISSP, CISA [EMAIL PROTECTED] -BEGIN PGP SIGNATURE- Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.c

DES or 3DES

2001-10-26 Thread Chris Hare, CISSP, CISA
I am seen conflicting information regarding the encryption method used to encrypt the response to the challenge. is it DES or 3DES, and if it is 3DES, is it EDE with two keys or EEE with 3 or what? -- Chris Hare, CISSP, CISA [EMAIL PROTECTED

CORE SDI Advisory - man in the middle attack

2001-10-27 Thread Chris Hare, CISSP, CISA
There is a CORE SDI advisory about the VNC authentication protocol and how it is vulnerable to a man in the middle attack. This advisory was for 3.3.3. Has it been corrected in the current implementations? thanks -- Chris Hare, CISSP, CISA [EMAIL PROTECTED

Re: DES or 3DES

2001-10-27 Thread Chris Hare, CISSP, CISA
sed to >encrypt the response to the challenge. is it DES or 3DES, and if it is >3DES, is it EDE with two keys or EEE with 3 or what? > > >-- >Chris Hare, CISSP, CISA >[EMAIL PROTECTED] >- >To unsubscrib