Re: security hole in X????

1996-06-05 Thread Mark Eichin
If you share a home directory on both machines, and you're using xdm, then the access is based on the .Xauthority file in your homedir. xauth list should show the same thing on both systems, if this is the case. (Generally this isn't much better -- it means you're still vulnerable to the magic

Re: security hole in X????

1996-06-05 Thread Lukas Nellen
CC == Carlos Carvalho [EMAIL PROTECTED] writes: CC The problem is that, with telnet, windows started on the remote CC machine open without problems in the local display, even without CC giving a xhost remote on the local machine. Is this correct? It only CC happens if you are the same user on

Re: SOLVED: security hole in X????

1996-06-05 Thread eckes
Hi, As some people suggested, the problem is that the home dir in all machines is the same (mounted via NFS from the server), so the .Xauthority file is the same. That's why no xhost is necessary. which of course means that the content of the Authority File is transfered unencrypted over your

security hole in X????

1996-06-04 Thread Carlos Carvalho
Suppose you have a window open in the local machine and you telnet to another one from that window. I discovered that telnet passes the DISPLAY variable to the remote machine, while rlogin doesn't. Up to now fine, except possibly for a bug in rlogin that doesn't pass the env var. The problem is

Re: security hole in X????

1996-06-04 Thread Stephen Early
On Tue, 4 Jun 1996, Carlos Carvalho wrote: The problem is that, with telnet, windows started on the remote machine open without problems in the local display, even without giving a xhost remote on the local machine. Is this correct? It only happens if you are the same user on both machines.