LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-02-2014, 11:10 PM   #1
Toonses82
Member
 
Registered: Sep 2004
Location: Calhoun, TN, USA
Distribution: openSUSE
Posts: 131

Rep: Reputation: 15
Should I tunnel x11vnc through SSH?


I'm setting up a Linux Mint XFCE 16 computer for my grandmother and I need to be able to support her remotely. My original plan was to set up a SSH tunnel and then run VNC through that. However, as I was doing some reading on x11vnc, I see that you can set it to use SSL to encrypt the traffic.

Would I be better off just using x11vnc with the SSL, or should I skip that and rely on my SSH tunnel for securely running VNC? The SSL option is easier, but I want to make sure I'm using the most secure method.
 
Old 01-03-2014, 03:37 AM   #2
rhoekstra
Member
 
Registered: Aug 2004
Location: The Netherlands
Distribution: RedHat 2, 3, 4, 5, Fedora, SuSE, Gentoo
Posts: 372

Rep: Reputation: 42
Both are secure, although, when exposing the vnc port, it could be vulnerable for hacking and the vnc service is affected directly.

If ssh is exposed, it should be hacked first before they would have to reach the vnc.. it's like some sort of stepping stone to get to vnc (and any other service needed).

IMHO the ssh+tunnel would be the better choice, but SSL itself is also a good choice (if encrypting in-transit data is your goal).
 
1 members found this post helpful.
Old 01-03-2014, 03:38 AM   #3
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Id' VERY strongly suggest you do neither and use the free client available at nomachine.org. It naturally tunnels over ssh by default, and starts up via ssh on demand, so no extra services need to always run other than ssh itself.
 
Old 01-03-2014, 09:20 AM   #4
Toonses82
Member
 
Registered: Sep 2004
Location: Calhoun, TN, USA
Distribution: openSUSE
Posts: 131

Original Poster
Rep: Reputation: 15
rhoekstra, I want to make sure the in-transit data is encrypted, but I also want to do the best I can to lock down her computer so nobody but me can get into VNC. Maybe I should stick with SSH.

acid_kewpie, are there benefits to using the nomachine.org client besides convenience? I've already got SSH working with private/public keys and VNC is working too. I have to have this done by Saturday, so is it worth throwing all that out and starting over with nomachine?
 
Old 01-06-2014, 04:13 AM   #5
rhoekstra
Member
 
Registered: Aug 2004
Location: The Netherlands
Distribution: RedHat 2, 3, 4, 5, Fedora, SuSE, Gentoo
Posts: 372

Rep: Reputation: 42
Toonses82,

I hope you've found a proper solution to this already, as it is Monday now...

In my opinion, SSH + [any protocol] tunneled is a very safe method. If you use Fail2ban to limit the amount of failed logon attempts before an IP gets a temporary ban, you're quite on the safe side, while very flexible. you don't have to open up additional ports besides SSH (single point of entrance) and have a proper way of deterring scriptkiddies.

While nomachines.org seems a very smooth and nice solution, it's not installed that easy once you are familiar with SSH, VNC, and port forwarding, IMHO. It's worth checking out though.
 
1 members found this post helpful.
  


Reply

Tags
encryption, ssh, ssl, vnc, x11vnc



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Initiate ssh tunnel to connect to ssh? brianmcgee Linux - Security 2 09-07-2011 10:07 AM
SSH tunnel over SSH tunnel vockleya Linux - Networking 6 01-22-2010 06:25 PM
How to tunnel everything over ssh iamacup Linux - Networking 1 06-30-2009 04:33 PM
setting up an ssh soxy or local ssh tunnel from within an ssh soxy Mangenius Linux - Networking 0 03-05-2007 03:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration