LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-20-2005, 05:50 AM   #1
JamesCoggan
LQ Newbie
 
Registered: Apr 2005
Posts: 2

Rep: Reputation: 0
Firewall with snorf, guardian,acid squid but all that goes down the drain using vnc


Firewall with snorf, guardian,acid squid but all that goes down the drain using vnc

Greatings!

I have just finished a firewall with snorf, guardian,acid,squid,md5checksum,high secure firewall script and etc.
But here is the thing, the Presidente of the company uses VNC to access his windows computer, and the vice-president uses VNC on linux, but vnc does not have encryption. There are other vnc alternatives with low encryption, but still unsafe. I know that you can use ssh to tunel the vnc conection. But it there how to make the firewall redirect this conection to a windows machine?
And even so, to use this ssh tunel, I have to leave the vnc port open in the firewall.
I'm open to sugetions on other kind of remote conections, I'm really open to any kind of sugestions since all my work will be lost if the hacker tries to conect on the vnc port.

Thanks everyone.
 
Old 04-20-2005, 11:19 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
VNC over ssh works by establishing an ssh connection between the two machines and then transmitting the VNC data through the tunnel. Once the data reaches the end-point, it's redirected locally to the VNC port. So you actually don't need to have VNC ports open on the external firewall, just the ssh ports. In most cases you will need to modify the windows ssh client settings in order to establish the ssh tunnel, but I'd imagine you could create a batch script to launch the tunnel on startup so that it would be pretty much transparent to the client.
 
Old 05-04-2005, 04:17 PM   #3
JamesCoggan
LQ Newbie
 
Registered: Apr 2005
Posts: 2

Original Poster
Rep: Reputation: 0
But how would I make the vnc client point to the network machine with the vncserver?
Because windows does not have a ssh server...
Correct?

Help me out on this one guys
Its very important

Thanks
 
Old 05-04-2005, 05:57 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
But how would I make the vnc client point to the network machine with the vncserver?
You don't. VNC listens on localhost (meaning it's listening for local traffic), ssh then forwards the VNC traffic to the VNC ports on localhost. The only thing connecting machine A to machine B is the ssh tunnel.

Because windows does not have a ssh server...
You don't need an ssh server on windows to do this, just an ssh client. I've done this with the ssh client software from ssh.com, but I'd imagine PuTTY can do this too. The windows client then establishes a secure tunnel to the ssh server on the linux box. The VNC traffic gets piped through the tunnel and then ssh forwards the traffic locally to the VNC viewer (so you can think of VNC as being connected to the local ssh software rather than to a remote machine).

Take a look at this guide. The hardest part is figuring out which ports and display numbers to use. I'd also recommend starting out by getting VNC working by itself first and then adding in the ssh tunnel.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Troubleshooting Acid (why Is Acid Console Displayed In Html Text??) njugs79 Linux - Newbie 4 03-30-2005 09:31 AM
VNC through firewall paicolman Linux - Networking 13 11-18-2004 12:35 AM
Fedora firewall and VNC TSloth Fedora 2 01-20-2004 08:43 PM
Combined firewall Guardian tarquin Linux - Networking 1 07-17-2003 10:03 AM
ssh, vnc, firewall hstang Linux - Security 3 01-03-2003 02:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration