Wednesday, April 08, 2009

How to VNC from an Android phone to a Linux Computer Securely with an encrypted ssh tunnel.

I know I have not posted anything in forever, but this is just so nerdy I had to post it. I got my full Ubuntu Linux desktop on my T-Mobile G1, and I did it very securely. Here is how you can do it too (provided of course you have an Android powered handset, Linux at home and a desire to show off to nerds everywhere).

To create a secure SSH tunnel to your Linux computer from an android phone;

This guide assumes a few things; that you have an ssh server and VNC server running on your home system, and that you have your home router setup to forward ssh traffic to your home computer. Every router is slightly different so I cannot write a guide for them all, but it should be quite easy to figure out with some basic Google searching. I recommend dyndns to get your routers external facing IP updated through DNS to you can connect with less of a headache when your ISP changes your IP.

1) Download ConnectBot to your phone from the android marketplace, put in your computers IP or hostname information (and password of course). You may want to test this first step to make sure you can ssh in before you set up the port forward.

2) In ConnectBot click menu key on the phone.

3) Click Port Forwards on the screen.

4) Click menu on the phone.

5) Click Add port forward on the screen.

6) Enter the following settings.

Nickname: VNC

Type: Local

Source Port: 5901

Destination: 192.168.X.X:5900 (the Xs of course representing your local IP address on your home system, not the IP address of your Internet facing router. You can find your you IP with the ifconfig command)

7) Download androidVNC to your phone from the android marketplace.

8) Open androidVNC and enter the following settings.

Nickname: (leave this field blank)

Password: (The password you set up on your remote computer for VNC, check the Keep box)

Address: 127.0.0.1

Port: 5901

9) Click connect and you should be connected!

54 Comments:

Blogger fepus said...

worked like a charm! thx for the recipe. Droid meet X11. X11 meet Droid.

Too bad using vim or wmii WM is tough on the droid ;(

6:02 PM  
Anonymous Anonymous said...

Now how do I route *everything* through a tunnel for browsing on public access points?

8:45 PM  
Anonymous Anonymous said...

You sir are a God, now I have an encrypted Ubuntu Desktop on my Android. This is promethean. Thanks so much.

1:29 PM  
Anonymous jimrecht said...

Darn! I’m using an iMac and trying to connect with my rooted HTC Hero using Android-VNC and ConnectBot. I followed your excellent instructions to the letter, with one exception: for “Destination” I entered 10.0.1.144:5900 instead of 192.168.X.X:5900 (I think that’s correct, since I’m using Mac OS X). But I can’t connect!

3:32 PM  
Anonymous Anonymous said...

Yo are da man, I'ev been pissing around trying to get this to work for a week now. Part I was missing was the ConnectBot port forwarding ... Cheers.

8:39 PM  
Anonymous Anonymous said...

Is there any reason why the destination
has to be on the local network? Couldn't
it be any accessible ip address?

8:35 PM  
Blogger Unknown said...

Congrats on the new member of your family, lets raise him to be just like us Linux nerds :) Thanks for the post, it was very helpful.

8:45 AM  
Blogger Unknown said...

For the user asking why it had to be the loopback address, a quick explanation of what this is accomplishing.

First, by setting up port forwarding you are allowing your Droid to make a secure encrypted connection to the computer at home.

Then by pointing VNC to the loopback address (127.0.0.1) you are telling the VNC viewer to try to connect from the droid back to itself. ConnectBot takes that connection attempt and sends it through the encrypted connection you already made.

You can take these instructions a step further and config your computer to listen for SSH connections on port 443 in addition to the standard 22. This allows you to tunnel from behind many restricted networks (like the over-locked down one at the college campus).

5:39 AM  
Anonymous Anonymous said...

This tried for me the first time but not connectbot keeps saying the host is disconnected. I'm thinking maybe I started the ssh daemon wrong on my computer this time. I'm using sudo /etc/init.d/ssh any ideas what i'm doing wrong?

7:39 PM  
Anonymous Anonymous said...

Hi, thanks for this guide. However, I have a problem with connectbot.
The 'port forward' option seems to be greyed out with 'local' type. Am I missing something here?

6:45 PM  
Anonymous Anonymous said...

AndroidVNC doesnt seem to work when connecting to Mac OSX internal VNC server. This process does work with other VNC viewers though (tested with pocketcloud)

10:40 PM  
Anonymous Anonymous said...

Thank you so very much! It worked like a charm.

9:18 PM  
Anonymous Anonymous said...

AndroidVNC to Mac OSX seems to be picky about the default color setting of 64. Crank it up and it works. Personally, Mocha VNC lite works so much faster for me than Android VNC

9:57 PM  
Anonymous Android app developer said...

I absolutely appreciate your way of presenting this column with a excellent suggestion.I want some more about this article. So you can add some interesting information and it will easily to reach the branding.

4:05 AM  
Blogger DarwinIcesurfer said...

This comment has been removed by the author.

11:06 PM  
Blogger DarwinIcesurfer said...

This comment has been removed by the author.

11:07 PM  
Blogger DarwinIcesurfer said...

Rather than following the instruction:
Destination: 192.168.X.X:5900 (the Xs of course representing your local IP address on your home system, not the IP address of your Internet facing router...."
Use 127.0.0.1:5900 This is particularly useful if your ip address changes due to a DHCP login,

11:09 PM  
Anonymous Anonymous said...

Thanks - very useful!

8:03 AM  
Anonymous Anonymous said...

when I try to connect to home with androidVNC I get: ERROR! VNC connection failed! null

4:23 AM  
Anonymous Anonymous said...

Thank you so much for taking the time and effort to share this.This was driving me nuts.

I'm on OS X 10.6.8 and this blog along with Darwinlcesurfer's comment was the final piece of the puzzle for me.

I had to use 127.0.0.1 for BOTH the AndroidVNC setup and ConnectBot's port forward.

Another tip for OS X users get Vine Server. Its a free, open source [but is now maintained by a commercial company] VNC app that allows SSH connections. AFAIK, OS X's native VNC [a.k.a Screen Sharing] doesn't allow SSH connections.
Vine Server also allows lower color depth than OS X's native VNC which only allows 24bit color.


Also, a couple of tips for configuring Vine Server:
Trying to log into my Mac, my password kept getting refused. It turned out that Shift [and Caps] wasn't working. In Vine Server go to:
Preferences/Device set the Keyboard Layout to Unicode Hex Input.

I was also getting intermittent RFB errors. So I went to
Permissions/Advanced and set RFB Protocol to 3.7 and so far I haven't had the RFV error.

Thanks again for this blog. God bless :-)

9:20 AM  
Anonymous Anonymous said...

YESSSSS!

3:31 PM  
Anonymous Anonymous said...

Thanks for this. However, DarwinIcesurfer's is key to making it work correctly through a NAT router.

4:52 AM  
Anonymous developej said...

had to type 127.0.0.1:5901 in connectbot port forward too. 192.168.*.*** wouldn't work.

thanks for the guide though

2:56 PM  
Anonymous clipping path said...

Pretty nice post. I just stumbled upon your blog and wished to say that I have really enjoyed your blog posts.In any case I’ll be subscribing to your feed and I hope you write again soon!…clipping path

2:24 PM  
Anonymous Mark said...

After a few hours' trying to resolve an undocumented bug/'feature', it seems worth putting in a comment in case someone else has similar difficulty:

avoid use of the -localhost flag in the linux vncserver command, as for some reason it blocks even the ssh tunnel/forwarded port from accessing the vnc server

as long as the firewall for the machine that's running the server, is itself blocking vnc / vnc ports, then the ssh tunnel should be the only effective way in

8:14 AM  
Anonymous Clipping Path Service said...

Really this site is very good site and the post include a lot of resource.thanks for share with us.good bye.

11:57 AM  
Anonymous Clipping path service India said...

Thanks for the post and sharing the blog. Valuable and excellent post, as share good stuff with good ideas and concepts.
lots of great information and inspiration. I just would like to say thanks for your great efforts.
I appreciate your excellent post.

1:12 AM  
Anonymous Darlene W. French said...

Amazing post you have published with us . So much thanks for shared .

12:16 AM  
Anonymous Robert Smith said...

wonderful article! We are linking to this particularly great content on our site. Keep up the great writing.

11:33 PM  
Anonymous Anonymous said...

I tried with VNC but it is not working with Coc Lights server why? I love Clash of clans game but it is not enabled on their servers? why?

9:51 AM  
Anonymous clipping way said...

Helpful tips. As i photo editing that was very helpful for me.

10:01 AM  
Anonymous Clipping Path said...

Hey Very Nice Blog!!! Thanks For Sharing!!!!

10:53 PM  
Anonymous clipping path said...

Wonderful post.Thanks for share.
clipping path service | clipping path

11:23 PM  
Anonymous Clipping Path Associate said...

I was reading some of your posts on this internet site and I believe this web site is really instructive! Keep on putting up.

12:23 AM  
Anonymous Anonymous said...

Wonderful post.Thanks for share.
http://clippingpathindie.com/furniture.html

2:01 AM  
Blogger Tina Rose said...

A very nice website. Blogs are very helpful.Thanks for sharing this website.
Clipping Path | Color Correction | Photo Retouching | Product Photo Editing

2:46 AM  
Anonymous David Millar said...

Thank you so much for sharing these nice articles clipping path service

1:26 AM  
Blogger http://www.designercountry.com/ said...

http://www.designercountry.com/Photo-Background-Change

1:08 PM  
Anonymous Clipping path said...

Thank you so much for sharing your informative article. I appreciate it.
Photo restoration service || Best Clipping Path service || Image masking
Best Ghost Mannequin Services || Car Image editing || Photo Retouching Service || Color correction || Background removal Service || image editing service

10:18 PM  
Blogger Sazzad Khan Rubel said...

Fascinating post from you. Thanks for sharing.
Image Background Remove
Clipping Path Service
Image Masking Service

11:37 AM  
Anonymous atharveducation said...

Being a member of the Association of Indian Universities (AIU), the programs are recognized by WES. Students may verify the same from the WES platform for Canadian Immigration. NMIMS Distance Education program serves its students with highly innovative and revolutionary technology and offers every digital solution to enable faster and most tactful learning process to its students.
nmims distance fee payment
nmims distance university
nmims college distance education
nmims distance result
nmims online distance learning

DY Patil Distance Learning program is aimed towards a slick and rapid improvement in the process of education while maintaining the contemporary standards of the educational industry in the genre of Hospitality and Management. Being renowned as a sophisticated university, DY Patil has several tie-ups with some of the best international industries.
dr dy patil vidyapeeth pune distance mba
ajeenkya dy patil university distance education
dy patil distance education mumbai
dy patil university distance education
dy patil institute of distance learning admission 2020

The School of Distance Education and Learning has executed the same schooling pattern from its mother university and continues to spread its remarkable influence across Rajasthan. The students and alumni members are provided with innovative self-learning study materials. JNU Distance Learning also offers consistent and well-organized counselling programs to its JNU Distance Learning students by renowned and experienced counsellors right at their doorsteps.
jaipur national university distance education bca question paper

jaipur national university distance education contact details

jaipur national university distance education login

jaipur national university distance education ba

\jaipur national university distance education results june 2020

1:41 AM  
Blogger Clipping Path said...

Yes, it works. Thanks for sharing. clipping path

12:20 PM  
Anonymous onlinepillsmart said...



Some pain pill cannot cure your pain. Yet it can help you to get effective and temporary relief from body pain. This painkiller can work best when it is taken with rest and proper treatment.
Soma 500mg
tablet Soma 500mg
500mg Soma

2:57 AM  
Blogger Photo Retouching Services said...


This is very informative post. Thanks for sharing.






Photo Retouching Services

9:28 AM  
Anonymous Image retouching service said...

Very informative article.
Image editing service

12:36 AM  
Anonymous discoverycentre said...

Thank you so much for sharing your informative article. I appreciate it.
Really this site is a very good site and the post includes a lot of resources.
discoverycentre

11:15 PM  
Anonymous Anonymous said...

Hello, I want to have one of these piercing models, but I am unsure. Can you look at it?

Double Helix Piercing

Snug Piercing

Snake Eyes Piercing

Tragus Piercing

Corset Piercing

Tragus Piercing & Piercing

3:02 AM  
Blogger Cut Out Way said...

pretty cool tips. I really appreciate your post. I definitely visit this blog again
Background Removal Service
Clipping path Service

5:29 AM  
Anonymous clipping path Asia said...

Really a helpful post forever. I have seen and read it carefully . I really appreciate your post.
Clipping Path | Car Photo Editing | Neck joint Services

8:59 AM  
Blogger FixWill said...

Thanks for your post on How to VNC from an Android phone to a Linux Computer Securely with an encrypted ssh tunnel! Great post for tech lovers.
Fixwill

5:51 PM  
Blogger John Smith said...

OMG. you nailed it.
I’m professional Graphic Designer at Clipping Path Service . We provide high-quality clipping path service, background removal service, Image Masking Service , neck joint service, ecommerce image editing service, car image editing, photo retouching service at reasonable price. Please visit our website, check out our portfolio and give your feedback.

Thank You.

10:10 PM  
Blogger Zack Nilsson said...

image masking service out or blocking out an area of a photo, video, or other media is an excellent way to hide any unwanted content. This professional service can be used for many different reasons, such as to remove naughty parts from a photo for social media, not showing the house number on the curb in front of your house, or simply wanting to delete your ex-girlfriend from your Facebook profile picture.

4:58 AM  
Blogger Best Clipping Path Provider said...

Nice Post!! Very Helpful. We Provide

Clipping Path.

We are an offshore Clipping Path service providing company, including Photoshop Masking, Drop Shadow, Retouching, Resizing, and Image Manipulation.

9:24 AM  
Anonymous photoshop skin retouch tutorial said...

you are really good at what you are doing. keep it up.

12:55 AM  

Post a Comment

<< Home