Return-Path: X-Original-To: apmail-cloudstack-users-archive@www.apache.org Delivered-To: apmail-cloudstack-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 42A06D330 for ; Tue, 21 May 2013 09:03:37 +0000 (UTC) Received: (qmail 49520 invoked by uid 500); 21 May 2013 09:03:37 -0000 Delivered-To: apmail-cloudstack-users-archive@cloudstack.apache.org Received: (qmail 49357 invoked by uid 500); 21 May 2013 09:03:36 -0000 Mailing-List: contact users-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: users@cloudstack.apache.org Delivered-To: mailing list users@cloudstack.apache.org Received: (qmail 49338 invoked by uid 99); 21 May 2013 09:03:35 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 21 May 2013 09:03:35 +0000 X-ASF-Spam-Status: No, hits=2.2 required=5.0 tests=HTML_MESSAGE,RCVD_IN_DNSWL_NONE X-Spam-Check-By: apache.org Received-SPF: error (nike.apache.org: local policy) Received: from [203.188.201.72] (HELO nm9-vm6.bullet.mail.tp2.yahoo.com) (203.188.201.72) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 21 May 2013 09:03:28 +0000 Received: from [203.188.200.143] by nm9.bullet.mail.tp2.yahoo.com with NNFMP; 21 May 2013 09:02:44 -0000 Received: from [119.42.242.156] by tm5.bullet.mail.tp2.yahoo.com with NNFMP; 21 May 2013 09:02:44 -0000 Received: from [127.0.0.1] by omp1003.mail.cnh.yahoo.com with NNFMP; 21 May 2013 09:02:43 -0000 X-Yahoo-Newman-Property: ymail-3 X-Yahoo-Newman-Id: 998801.42483.bm@omp1003.mail.cnh.yahoo.com Received: (qmail 88967 invoked by uid 60001); 21 May 2013 09:02:43 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.cn; s=s1024; t=1369126963; bh=TjR4wgjc8KpeGyBOJE4iJvVc7l7IuUhwqUcLtBXnnD4=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=yBmSlEFgsmgPE0Pg2/6rqWf/juNLn0dqbdU8Mbb8KGXR9+ouOu3CmeExrfUL7SaI49rZVt4jPI3Y/RhUfSJ19drBsyGa2Xn3X5+mNP4aPMazI3j/qgzXuWI+V3zHcbQhigFrN1x/imQmd7ub7P7CT2qZv3ytDW/59XZvCSFGj2o= DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.cn; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=ozzYLebMFJK/rl/Geto2lz7SqPxV/2unT1+oX/SFSZ2AQojVnT1cnUveYCr10htjv+ZrmW5LPKQX8IhnzfoqueEDmaF/uCEVaGLBOAJKCWE4P7Xh8E4yTxw2cn7jYe5UQR4PEk57uclBxSXL2N3KC/4skPHOmZyUYBX1TdmhlDM=; X-YMail-OSG: cBAgBrgVM1nB3eLLPPSMpecNK45Ia6Hg15vWaze8tdT21qQ 4DNlLO0pBlo.KJQ.EN2Elj1Tf0j76c8CLGs.wxA58UhFuYaEFHairMj7ABS3 gkzSY0pWbel33lTvP92btXsBEQII1nVmld9Zqn9hyxNYLUkLIoBWw5drc8FS .JYpH6bSISyItF6VQtFz1EYHVkecy7wsVwqkIlLeX.VDSUW8BYKZCJhp4LtX 6P7Cv7.NdkXjJ6XHzbLHyK1DkajPcvOrPcRK0ECS4JX3i6xyQx2DQPB5ddTC zpPSrOp74nVZ6WPrPrA5JiBPmjRwi3H6pTAU9GAY1cPLiYLbyLWZRBsurkmN UpqQ_XyHFEZ5bLFkUP4ThN6edYIGpBOJfeW_oP26zlL36Kt0- Received: from [222.44.86.44] by web92412.mail.cnh.yahoo.com via HTTP; Tue, 21 May 2013 17:02:43 CST X-Rocket-MIMEInfo: 002.001,SGkgOgrCoMKgwqDCoCBJIGRlcGxveSBDbG91ZFN0YWNrIDQuMC4yIGZvbGxvd2luZyB0aGUgaW5zdGFsbCBndWlkZSwgYW5kIHVzZSBLVk0gYXMgdGhlIGh5cGVydmlzb3IsIHJlY2VudGx5IEkgZ2V0IHRoZSBzZWNyaXR5IHJlcG9ydCB3aGljaCBwcmVzZW50IHRoZSBSZW1vdGUgYXV0aGVudGljYXRpb24gdnVsbmVyYWJpbGl0eSBvbiBteSBrdm0gaG9zdC4gSSB0aGluayB0aGF0IG1heSBxZW11IGJ1aWxkLWluIHZuYyBzZXJ2ZXIsIEkgZG9uJ3Qga25vdyBob3cgdG8gZml4IHRoaXMgcHJvYmxlbSwgZG9lcyABMAEBAQE- X-Mailer: YahooMailWebService/0.8.142.542 Message-ID: <1369126963.77322.YahooMailNeo@web92412.mail.cnh.yahoo.com> Date: Tue, 21 May 2013 17:02:43 +0800 (CST) From: Aslan Lin Reply-To: Aslan Lin Subject: VNC Security---Remote Authentication Vulnerability To: cloudstackEnglish MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="-1296320791-779655471-1369126963=:77322" X-Virus-Checked: Checked by ClamAV on apache.org ---1296320791-779655471-1369126963=:77322 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Hi :=0A=A0=A0=A0=A0 I deploy CloudStack 4.0.2 following the install guide, = and use KVM as the hypervisor, recently I get the secrity report which pres= ent the Remote authentication vulnerability on my kvm host. I think that ma= y qemu build-in vnc server, I don't know how to fix this problem, does any = one meet this, thanks for your help.=0A=0A=A0=A0=A0 Sorry for my pool Engli= sh.=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0= =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Best wishes=0A ---1296320791-779655471-1369126963=:77322--