Add authentication to VNC?
Posted: Wed Jan 24, 2024 4:30 pm
I've recently set up EveNG in our lab environment and its working well. However, it appears our SIEM team have detected that there are VNC servers listening with no authentication required. As such, I'd like to add a simple auth mechanism in front of the VNC's. Even just requiring a password would be sufficient.
Is that something thats possible to do? I've not seen anything in the documentation, but would be happy to be corrected if I've missed it.
Edit- on a re-read, I realise the above is not all that clear. To clarify: I am referring to nodes with VNC as the console type. As long as that node is online, there will be an open port that will accept a VNC connection without any authentication required (Obviously the node it connects to may then require auth, but the VNC connection itself is open). The SIEM team are then detecting these nodes as an 'open' VNC and flagging them.
Is that something thats possible to do? I've not seen anything in the documentation, but would be happy to be corrected if I've missed it.
Edit- on a re-read, I realise the above is not all that clear. To clarify: I am referring to nodes with VNC as the console type. As long as that node is online, there will be an open port that will accept a VNC connection without any authentication required (Obviously the node it connects to may then require auth, but the VNC connection itself is open). The SIEM team are then detecting these nodes as an 'open' VNC and flagging them.