[Gloucs] VNC Apps?

Mark gloucs at mailman.lug.org.uk
Fri Aug 29 11:44:01 2003


On 29 Aug 2003, Matthew Macdonald-Wallace wrote:

> All,
> 
> A new semester is beckoning for me at university, and I'd quite like to
> be able to use my computer from uni.  I've got dynDNS setup on my
> firewall, I'm just wondering what the best VNC app is in peoples view. 

*shudder*

> I was using tightvnc over a lan, but obviously if this is gonna be going
> over the net, it needs to be v. secure.  Also, a webfront end via JAVA
> would be nice, coz the uni firewall is so 
> strict.
 

If you REALLY have to do the above.

I would suggest that you tunnel the vnc connection over ssh.

create a locally bound listening ssh session which has bound to your vnc 
server. (man ssh and it's the -L option)

so then you will be able to connect to "localhost" with the vnclient of 
your choice which will then be redirected to the remote box via ssh.

this enables you to not have to leave the worrying application which is 
vnc open to the world. just have iptables deny access to it from anyone 
but localhost. as when you are connected using ssh you will be localhost 
as far as iptables is concerned.

Ofcourse you may also want to change the default sshd port.

thats my 2p worth.


-- 
	       		   Mark
         	   www.wwjh.net/~mark
 "If you know yourself, knowing the enemy does not matter."