Vnc-roulette – Randomly connects to open VNC servers
allsprk.koding.io
allsprk.koding.io
If you knowingly tinker with a system you're not supposed to have access to --- that is, you either VNC into a system that isn't yours and see things that a reasonable person would react to as an indication that they weren't welcome, or that a prosecutor can claim a reasonable person would react that way to --- you're violating the CFAA.
All current indications are that scanning the whole Internet for open VNC systems is, if not lawful, then at least so close to the line that nobody's going to make an issue of it.
But logging into a VNC server and poking around crosses a bright line. Arguments about the implied welcome given by lack of a login screen will probably not persuade a jury, let alone a prosecutor.
The idea of hooking open VNC servers up to a "roulette" game seems beyond stupid. Maybe someone's thought about this more carefully than I have and can explain why I'm wrong?
Not that that doesn't make it fun, but still.
A reasonable person would assume that a server with no password, intentionally has no password.
I do not support malice or vandalism, but there is no indication that a system is misconfigured merely because it does not have password protection. Users should not be expected to know the intricacies and technical details of every program they use. The responsibility for ensuring that servers are not publicly accessible is on the person running the server. Not requiring a password to access a system on a public network, when you require that only certain people are allowed access to that system, is negligence at best. I'd argue gross negligence.
And there is no indication it's not a misconfiguration. Look, I completely agree with what you're saying, but judges won't (and don't).
This is the difference between a storefront being left unlocked, versus a private home being left unlocked. An unlocked storefront is likely to be open for business, so entering is reasonable. An unlocked house is a security mistake, and entering is trespassing.
But you're right. You may never be convicted. Go ahead and try your luck.
Similarly you will find that trespassing on a system you do not have authorized use of (and no login is not implicit authorized use) is going to get you in trouble pretty much everywhere.
It's like if my grand-mother with alzheimer accidentally entered the wrong apartment room or house where the door was unlocked. It's not like she should go to jail or get shot by the owner pretending she was a threat.
I haven't seen the website, but if they made it really easy to enter remote systems then someone could defend himself saying he didn't know what it was all about.
One could probably argue that some Popcorn Time users would enter this gray zone.
However, the providers of those kind of services are mostly aware of the illegality of their users behaviour, so they are infringing the law clearly.
Welcome to foo.example.com
Have something like: foo.example.com
For authorized use only.I'm taking a wild guess the host (koding.io) shut this one down, I can't imagine is takes too long to get an abuse request from an app like this..
That said - If this does what I think it does, awesome :) Maybe people will stop exposing systems over the internet like this after 5 or 10 more of these sites/apps?
(Or more likely - completely legal unless it affects the government or a big enough US corporation)
This always becomes the main subject by lawyers in courts.
It is trivial to scan the whole ipv4 address space. I think the guys in this video did it in 40mins or so while presenting.