DEV Community

StarkMan
StarkMan

Posted on

11010 RDP and 176914 VNC Results: Two Remote-Access Protocols With Different Histories

11010 RDP and 176914 VNC Results: Two Remote-Access Protocols With Different Histories

Remote desktop protocols are the most consistently exploited initial access vector, and the two most common ones produce very different exposure profiles. A ZoomEye query set collected on 22 September 2026 returned:

Query Total results
port:5900 (VNC) 176,914
port:3389 (RDP) 11,010
port:23 (Telnet) see note below

The VNC count is more than sixteen times the RDP count in this dataset. That difference is not a statement about which protocol is more dangerous. It reflects how each protocol is deployed, how each responds to a probe, and how each is indexed.

Why VNC indexes so much higher

VNC is a remote framebuffer protocol. It is implemented in a very large number of products: standalone servers, remote support tools, virtualisation consoles, kiosk software, and embedded devices. Many of those implementations ship with VNC enabled by default or enable it with a single checkbox.

Two properties make VNC easy to index. First, the protocol begins with a server-to-client handshake that identifies the protocol version in plaintext, which allows a scanner to confirm the service without authenticating. Second, VNC historically supported authentication types with no password at all, and even where a password is required, the handshake proceeds far enough to identify the service.

A VNC service on a public address is a remote control session for whatever is on that screen. In a virtualisation or industrial context, that screen may be a management console.

Why the RDP count is lower

The RDP count in this dataset is 11,010. RDP is present on essentially every Windows server and workstation, so the population of RDP services is far larger than the population of VNC services. The indexed count is lower because of how the protocol responds and how it is protected.

RDP performs a TLS handshake before the protocol negotiation completes. A scanner that does not complete the handshake may not obtain a positive identification, and RDP services behind a gateway or a VPN concentrator are not directly reachable at all. The count therefore reflects directly reachable RDP endpoints, which is a subset of installed RDP services.

That distinction matters for interpretation. A low RDP count does not mean RDP is rare. It means directly reachable RDP is less common than directly reachable VNC in this index.

The exposure that matters is the one you own

The relevant measurement is not the global total. It is whether your own address space appears in either result set. Three checks are worth running:

  1. Query your own netblocks for 3389 and 5900. Any result is a finding that needs an explanation.
  2. Distinguish the device type. RDP on a Windows server is a different risk from VNC on a building management controller. The remediation paths differ.
  3. Check for a gateway. RDP published through a gateway or a VPN is a different architecture from RDP exposed directly. The gateway is the control point and should be reviewed as such.

Controls that change the outcome

For RDP, the effective controls are network placement and authentication strength. RDP should not be directly reachable from the internet; access should be through a VPN or a zero-trust access broker. Where it is reachable, Network Level Authentication should be required, and account lockout and MFA should apply.

For VNC, the effective control is usually removal. VNC is frequently enabled for a temporary purpose and left running. Where it is required, it should be bound to a management interface, restricted by network policy, and configured with a strong password rather than the default.

For both, the control that catches the cases nobody planned is continuous monitoring of your own address space. A single scan establishes a baseline; a recurring query detects the new exposure introduced by a change.

What these numbers do not say

Indexed results are not vulnerable hosts. A service that responds to a probe is a reachable service. Whether it accepts a weak credential or has an exploitable flaw is a separate question.

The counts are not comparable across protocols. VNC and RDP have different probe behaviour, different default configurations and different network placement conventions. Comparing the two counts directly describes the index, not the risk.

A snapshot is not a trend. These figures were collected on 22 September 2026. The useful comparison is the same query run later, against your own address space.

References

Top comments (0)