Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

X forwarding is not really secure anyway if you are using it on an untrusted remote machine.

If you are an admin on a server and someone logs in with X forwarding then you can access his X server easily without any limitation (keylogger, screenshots, etc...).



Well, back in the mid-90's we had lots of fun with it in the university.

Specially since most students didn't even bothered to configure xauth and xhost properly.


Not sure i see how that can be fixed in software, if the attacker has control over the hardware (or sit closer to it than the software you are using).


The point being made here is that if I run an xterm on your machine (forwarded to the X server on my machine), then you can now access everything happening in the X server on my machine.


Noted. What puzzles me is that this has not been sorted in all the years, without doing a complete ground up recreation...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: