VNC Roulette
srsly.de
srsly.de
I've just seen a VNC session on a machine running some PLC software (I've flagged it). There could be god knows what running open VNC sessions in here, and it feels unethical to expose this in an easy-to-exploit way without making a best-efforts attempt to contact the operator.
I've seen a few VNC desktops that now have Paint open (or similar) with messages informing people that they have an open VNC server, but altruism is unlikely to be the norm.
It's a cool idea and it's really well done, but I do wish it was anonymised - no display of the host or port the VNC server is running on, just the screen. (I realise this might be useless in some cases where the screenshot lists the server's FQDN.)
E.g. We should tell people that guns are dangerous, but we shouldn't highlight this by giving guns to children -- someone is going to get to hurt.
Not really. The site operator has done nothing that has not already been done before, and it's little more than a basic nmap scan for services (which anyone can do).
It might be considered unethical that a PLC system is using VNC with no password.
There's also an awful lot of CirrOS systems in there, which tell you the default username and password, alongside a kind note saying the default user has full sudo privileges and you can just sudo into full root. The particularly bad thing about CirrOS is they are almost all running on OpenStack and other cloud providers, whom should know better.
I realise this. Which is why I carefully phrased the objection as "easy-to-exploit". You and I may think the phrase "basic nmap scan" is simple, but it opens the door to lots of people who don't know what that sentence means but can easily click a link in their browser and be directly connected to an exploitable host (I don't like the phrase 'script kiddie' but I think that conveys what I mean).
> It might be considered unethical that a PLC system is using VNC with no password.
It might. It might also be more properly called incompetence. But that's orthogonal to providing an easy way to exploit such a system and not notifying the operator, which I feel is "more unethical" if such a concept exists.
There are ways to do this if the intent was to highlight how many people run open VNC server (as I'm guessing is implied by calling the site Srsly?)
1) Don't publish the server's hostname and port.
2) Attempt to notify the operator.
3) Publish screenshots only.
By publishing the connection details, this turned something that could have been interesting and done some public good into something that I feel is dangerous and fairly exploitative.
This year at Defcon there was a great talk about masscan and scanning the entire internet (they enumerated a lot of open VNC's right onstage during the talk).
> Attempt to notify the operator.
How? If it's just some IP address, there's little you can do other than login and leave a text file open telling them they have an open VNC (that would surely get my attention).
The argument that a site like this should not exist because someone may exploit it just doesn't hold up. It's like saying we shouldn't post the IP addresses online of open mail relays, or open dns resolvers... which we (the "white-hat" community) did not... until it was discovered they were already posted online. Someone will do it...
If a vendor is so incompetent as-to put an important PLC on the internet, let alone with a completely open VNC, that vendor should be shamed. If we build a list like this site has done, perhaps we can strongly encourage folks to not do this anymore.
Heck, I'd love a search feature to be implemented on the site so I can double check I have no open VNC's on any of my IP's...
Good point. But it's not laser-focused on a single thing and making that thing as easy as possible (I can just click on an image and be connected to the server!)
> How?
For some hosts it will be impossible. For others, it may be obvious or at least feasible; the company's name may be in the FQDN, the server may give a name in the VNC response that could be used, and if you're feeling grey-hat you could poke around and see what it does and who may own it.
> The argument that a site like this should not exist because someone may exploit it just doesn't hold up
I didn't say it shouldn't exist - just that some minimum form of self-censorship is the ethical course of action.
> Someone will do it...
Of course. But not everyone will make it this easy and accessible.
And I can appreciate the spirit in which this is done, if the "Hail Eris!" text on the page didn't make it obvious :) Being able to flag stuff is the concession, assuming it really does remove it from rotation.
Merely because something is easy, or common, does not make it ethical. In fact, I think those factors should be entirety unrelated to ethics.
Theft has been done before. Theft is easy to do. Therefore, it's ethical to steal. This seems to be the logic you're following... Correct me if I'm wrong?
[1] http://lists.nongnu.org/archive/html/qemu-devel/2014-12/msg0...
[0] http://wetten.overheid.nl/BWBR0001854/TweedeBoek/TitelV/Arti...
The web client uses our machine to proxy the websocket connection the client uses to the VNC server and we don't collect user data, especially not who used the VNC client to connect to which server.
What was that thing Warren Buffett wrote recently, with regard to moral decisions? "If anyone gives this explanation, tell them to try using it with a reporter or a judge and see how far it gets them."
Edit: a word
They appear to be automated viewbots. I would have thought that there were more efficient ways of generating views.
[edit] I don't have anything like VNC set-up, but maybe we (I) can learn something from this.
You could also use a non-standard port or configure some sort of port knocking system, or just close the VNC port to the outside world and allow connections over VPN or SSH tunnels only.
Switch to NX instead.
http://adamwalling.com/SecureVNC/
https://www.realvnc.com/products/vnc/documentation/5.0/guide...
To actually be secure: Bind only to localhost, tunnel over SSH, OpenVPN, etc.
- First of all, I think the title of this submission might want to imply that it could be NSFW (see some comments below re: porn), and that it could be in a strange grey-area legally (especially if you actually connect to these machines)
- On one hand, there's nothing revelatory about this project. VNC, RDP, web cams, etc. are frequently found on the Internet because sysadmins don't secure them correctly. See something like Shodan, for example, to get a really realistic view of this.
On the other hand, though, bringing attention to it is a great way to get people to stop being idiots in this way.
Unfortunately, I doubt that the sysadmins in question will actually see this site.
Adresses that have at least one of these open then get passed to a Python script that attempts to connect to those machines and take a screenshot.
The web frontend is built using Go httpd by the way.
Edit: We are able to do this because we're at the 31c3 with an enormeously fast internet connection. The machine this is running on has a 1Gbps connection to the internet.
$ while true; do curl -sk https://srsly.de | html2text | awk '/Address/ {print $2}' | tee -a vnsservers; done
$ sort -u vncservers | wc -l
3128Here's an `asn_country_code`-based aggregation of countries:
{
"took" : 2,
"timed_out" : false,
"_shards" : {
"total" : 5,
"successful" : 5,
"failed" : 0
},
"hits" : {
"total" : 7612,
"max_score" : 0.0,
"hits" : [ ]
},
"aggregations" : {
"countries" : {
"doc_count_error_upper_bound" : 5,
"sum_other_doc_count" : 1894,
"buckets" : [ {
"key" : "cn",
"doc_count" : 1891
}, {
"key" : "us",
"doc_count" : 1155
}, {
"key" : "de",
"doc_count" : 894
}, {
"key" : "kr",
"doc_count" : 457
}, {
"key" : "ch",
"doc_count" : 398
}, {
"key" : "mx",
"doc_count" : 244
}, {
"key" : "ru",
"doc_count" : 178
}, {
"key" : "ca",
"doc_count" : 171
}, {
"key" : "it",
"doc_count" : 167
}, {
"key" : "gb",
"doc_count" : 163
} ]
}
}
}RDP works a lot better in general, because you aren't limited to the screen resolution of the server system.
p(windows|vnc)=p(vnc|windows) * p(windows) / ( p(vnc|windows) * p(windows) + p(vnc|non-windows) * p(non-windows) )
Edit: I've also seen several now with the root prompt already open. Now I know how so many botnets are formed.
If you must run VNC for legacy reasons, please run it in an SSH tunnel without an open port to the world.
With things like RDP, NX/nomachine, xwindows forwarding in an ssh tunnel, etc, there's really no excuse to keep using it. For all the shit Windows gets, at least it doesn't allowed password-free RDP connections. I think the world of cheap Linux VPS have opened up a pandora's box of bad security practices. There's no shortage of forums out there that tell the uninitiated to "just apt-get" VNC and be done with it. Running ssh tunneled nomachine is just as easy to configure, has better performance, and loads better security.
Also this looks like an applet that runs a js vnc client locally and connects you directly various open VNC servers. Its your IP address in those logs and depending on your jurisdiction or policies, may get you in trouble just for visiting the site. Took me a second to realize this. May want a warning here for those at work.
Not quite. The VNC client is noVNC, with a websocket proxy on the same machine http://srsly.de runs on. The connections you make with the web interface will go to our server, be translated from websockets to regular sockets, and then forwarded to the real VNC server. The address they see in their logs is ours.
We don't log access to the VNC client, by the way.