One of the staff at Lillifoot gave me a call yesterday – the iMac was doing strange things, and browsing websites all by itself. Was I remotely controlling it? No, but I immediately knew what had happened. Last month I had set up the Vine VNC Server to test out remote support. As an experiment, I had started up the server, and tried to connect a VNC viewer via a ssh tunnel. There was some problem (I can’t remember what), so I temporarily disabled the security. And then completely forgot about it. Until the phone call yesterday. Anyway, I now know the answer to “How long does it take for someone to find an unprotected VNC server?” (about 6-7 weeks)
Luckily, the curious visitor was only able to connect through a locked down user account, and the staff member was watching when it happened. The logs show no other activity has taken place (though I still did a full scan of the system).