Bug#637386: vnc4server: blacklists wrong IP: 0.0.0.0, can lead to DoS

2016-06-09 Thread Mitch Deoudes
On 6/9/2016 5:36 PM, Ola Lundqvist wrote: Hi Mitch I'm not fully sure whether the remote IP address is available through the socket. If it is, then we could probably fetch it in some way. A possible workaround would be to avoid banning 0.0.0.0. Patches are welcome. I'm a bit confused...

Bug#637386: vnc4server: blacklists wrong IP: 0.0.0.0, can lead to DoS

2016-06-09 Thread Mitch Deoudes
Apparently, this is still an issue as of Xvnc 4.1.1. (Up to date on Linux Mint / Ubuntu.) Last week, I started getting vnc password attempts from an unknown IP, resulting in the "blacklisted: 0.0.0.0" messages in the log, and the server refusing all connections. I would prefer not to disabl