From mike.gabriel@das-netzwerkteam.de Sat Aug 17 20:42:56 2013 Received: (at control) by bugs.x2go.org; 17 Aug 2013 18:43:04 +0000 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on ymir.das-netzwerkteam.de X-Spam-Level: X-Spam-Status: No, score=0.0 required=5.0 tests=URIBL_BLOCKED autolearn=unavailable version=3.3.2 Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199]) by ymir (Postfix) with ESMTPS id EB7475DA6C; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98]) by freya.das-netzwerkteam.de (Postfix) with ESMTPS id A13FC9CF; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 94F383BB75; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de Received: from grimnir.das-netzwerkteam.de ([127.0.0.1]) by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hnPrIRDN108S; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 742803BBB0; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 5582A3BB75; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: by grimnir.das-netzwerkteam.de (Postfix, from userid 33) id 0C59C3BBB0; Sat, 17 Aug 2013 20:42:55 +0200 (CEST) Received: from 83-68-217-98.cable.dc13.debconf.org (83-68-217-98.cable.dc13.debconf.org [83.68.217.98]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP; Sat, 17 Aug 2013 20:42:55 +0200 Message-ID: <20130817204255.119582nheui8tcfj@mail.das-netzwerkteam.de> X-Priority: 3 (Normal) Date: Sat, 17 Aug 2013 20:42:55 +0200 From: Mike Gabriel To: 287@bugs.x2go.org Cc: control@bugs.x2go.org Subject: Re: [X2Go-Dev] Bug#287: x2goserver allows to connect to ALL X server sessions by default References: <520F983C.6040904@stefanbaur.de> In-Reply-To: <520F983C.6040904@stefanbaur.de> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=_7jk3unb0c2lq"; protocol="application/pgp-signature"; micalg="pgp-sha1" Content-Transfer-Encoding: 7bit User-Agent: Internet Messaging Program (IMP) H3 (4.3.4) This message is in MIME format and has been PGP signed. --=_7jk3unb0c2lq Content-Type: text/plain; charset=UTF-8; DelSp="Yes"; format="flowed" Content-Disposition: inline Content-Transfer-Encoding: 7bit title #287 Linux Mint desktops configured too insecurely for multi-user mode tag #287 confirmed tag #287 wontfix close #287 thanks Hi all, On Sa 17 Aug 2013 17:35:24 CEST Stefan Baur wrote: > Actually, this is not an x2go issue, this is a linux mint issue : by > default, there is a "xhost +" command launched at session startup for all > users. > > If you type "xhost - ", then you should see the normal behavior again : > userB will get a "no desktop found" message if he try to connect to the x2go > host. > > So, the workaround is to remove the "xhost +" command in the Control Panel > > Startup Applications for each user, > > or completely remove the /etc/xdg/autostart/mint-xhost-plus.desktop > (but this could come back if the package ubuntu-system-adjustments is > updated) > > or change this file to: > > [Desktop Entry] > Encoding=UTF-8 > Version=1.0 > Name=Xhost + > Exec=xhost + > Terminal=false > Type=Application > StartupNotify=false > Terminal=false > X-MATE-Autostart-enabled=false > Hidden=true We (David and I) just figured out the same... (what a race condition...). Thanks! What a security leakage if people start using Linux Mint in multi-user operation mode (like with X2Go or locally or with LTSP). With xhost + for every user you can launch applications on other people's desktops and also read out their clipboards' contents. /me rarely has to puke at other people's work, but this time... Well, yes. > note to x2go packages maintainers: > Maybe this should be an option to check/disable when the x2goserver package > is installed? No! We won't work around such grave issues in distributions or in other packages. This needs to be immediately fixed in Linux Mint upstream. > Or maybe a warning should be issued if "xhost" is set to + when a user > connect? Nope! In default setups no other distro evokes xhost + on session startup. This is just insane!!! So we ignore this issue in X2Go upstream completely. Stay away from Linux Mint with X2Go (or actually at all) till this has been fixed in Mint. light+love, Mike PS: quote me freely if needed... -- DAS-NETZWERKTEAM mike gabriel, herweg 7, 24357 fleckeby fon: +49 (1520) 1976 148 GnuPG Key ID 0x25771B31 mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de freeBusy: https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb --=_7jk3unb0c2lq Content-Type: application/pgp-signature Content-Description: Digitale PGP-Unterschrift Content-Disposition: inline Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAABAgAGBQJSD8QuAAoJEJr0azAldxsxoU0P/09lTB405vMfOtTwfnovq9HB yObD8YQBnvkFE2ONY5jE/yS/f1bp7R6ET+8HVP0uPrgf7Cao+dXlsHsQzFFVGwCA 7++z8U3aShdzVpqQ8nBjE4vewuTfNSbBzKMZQlNzFRHQ6TIOPF07XfCekQcDszTw aWFpt4Lv0vZNrNoYKABO+chOTrHLG8bpEe3hllxe9jmsEeOliYmiEzrjLzvT7gVA nRl9Yr5+bAybWQbl3H4ogDeOi2nAB1dlHhyD2Gltu8Sday22Whr8YNxAVu4x0Upt WC8+YQ7F/+Y5GTqiGu5c+HbQuVPgN9k5LkRg/d3urMODxlthPRD0rZKqE4UinnXh 4oV4VugOGQEBL+jT3xtrSkyrE+ztM8Tx2siIimlA02gWtaBp3xv0YDJHqQiyjPxK u3VfyQ3qzdip6PZoWsgB5fk0qx/Y+LrEEer5Hn/c4gbp+zxK1sYl8oCQzuL9d5Zo ieEXsmAtMZPf99wtk+oq4+9HGoRKaXoqQQF7Qjw3WmEZrDflX/7SqfhKudHtwl6o B1H9D5vj9WNWnUkuoOwl3Phtc6Iq7DS4PcpsbDllo6QPnqRtW0Ju/xeT6YJJkyXr JqXvH3FuW0EUaJgjDfjD8pIOX+y2VlRGNX6w2vonVIbFRDqC6YS1/mveSXr1ct1/ /repF12lv6Ihr46LxY3T =v0Ad -----END PGP SIGNATURE----- --=_7jk3unb0c2lq--