I found this while surfing. I do not know if it is on here somewhere, but here goes.
"This technique/method is rather 'noobish' and will be frowned upon.
A while ago there was a problem with RealVNC 4.1.0 - 4.1.1 which aloud remote users to authenticate without the real password, aka...