{
  "entrypoint_kind": "tcp_peer",
  "entrypoint_detail": "Unauthenticated RFB client over localhost TCP to Xvnc launched by xrdp-sesman in Xvnc-UDS session mode",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "xrdp-sesman",
    "xrdp-sesexec",
    "TigerVNC Xvnc",
    "RFB 3.8 TCP peer"
  ],
  "proof_artifacts": [
    "logs/reproduction_steps.log",
    "logs/source_identity.log",
    "logs/security_patch.diff",
    "logs/vulnerable-attempt-1-sesman.log",
    "logs/vulnerable-attempt-1-session-launch.log",
    "logs/vulnerable-attempt-1-processes.log",
    "logs/vulnerable-attempt-1-rfb.json",
    "logs/vulnerable-attempt-2-sesman.log",
    "logs/vulnerable-attempt-2-session-launch.log",
    "logs/vulnerable-attempt-2-processes.log",
    "logs/vulnerable-attempt-2-rfb.json",
    "logs/fixed-attempt-3-sesman.log",
    "logs/fixed-attempt-3-session-launch.log",
    "logs/fixed-attempt-3-processes.log",
    "logs/fixed-attempt-3-rfb.json",
    "logs/fixed-attempt-4-sesman.log",
    "logs/fixed-attempt-4-session-launch.log",
    "logs/fixed-attempt-4-processes.log",
    "logs/fixed-attempt-4-rfb.json"
  ],
  "notes": "Confirmed twice on the vulnerable fixed-parent commit with two fixed-commit negative controls. The RFB client supplied no credentials and received ServerInit only from vulnerable Xvnc processes."
}
