X2Go Bug report logs - #287
Linux Mint desktops configured too insecurely for multi-user mode

version graph

Package: x2goserver; Maintainer for x2goserver is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goserver is src:x2goserver.

Reported by: David Fuhrmann <fuhrmann_mail@web.de>

Date: Wed, 7 Aug 2013 05:48:02 UTC

Severity: critical

Tags: confirmed, moreinfo, wontfix

Found in version 4.0.1.6

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #70 received at 287@bugs.x2go.org (full text, mbox, reply):

Received: (at 287) by bugs.x2go.org; 17 Aug 2013 15:47:37 +0000
From newsgroups.mail2@stefanbaur.de  Sat Aug 17 17:47:36 2013
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=0.0 required=5.0 tests=SPF_HELO_PASS,URIBL_BLOCKED
	autolearn=ham version=3.3.2
X-Greylist: delayed 759 seconds by postgrey-1.34 at ymir; Sat, 17 Aug 2013 17:47:35 CEST
Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.17.9])
	by ymir (Postfix) with ESMTP id E52623BDED
	for <287@bugs.x2go.org>; Sat, 17 Aug 2013 17:47:35 +0200 (CEST)
Received: from [192.168.0.3] (HSI-KBW-149-172-200-27.hsi13.kabel-badenwuerttemberg.de [149.172.200.27])
	by mrelayeu.kundenserver.de (node=mrbap3) with ESMTP (Nemesis)
	id 0LuLSB-1W8MWF0tfT-011nEQ; Sat, 17 Aug 2013 17:34:56 +0200
Message-ID: <520F981D.1050903@stefanbaur.de>
Date: Sat, 17 Aug 2013 17:34:53 +0200
From: Stefan Baur <newsgroups.mail2@stefanbaur.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:17.0) Gecko/20130801 Thunderbird/17.0.8
MIME-Version: 1.0
To: 287@bugs.x2go.org, x2go@edhil.net
Subject: Fwd: Re: [X2Go-Dev] Bug#287: Bug#287: x2goserver allows to connect
 to ALL X server sessions by default
References: <loom.20130816T153533-237@post.gmane.org>
In-Reply-To: <loom.20130816T153533-237@post.gmane.org>
X-Forwarded-Message-Id: <loom.20130816T153533-237@post.gmane.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Provags-ID: V02:K0:Ttftb6FMabn+tvo9IWU91As9t0q/lrp7NAEd3nrZUZV
 Dun1Z20oDhOSt5OF60WlynK3nCJ4qWm+jOKc1zhMRz5e5eDrD4
 BVEhOxzHn+WmZxVzr8TfIBZxkbEM70M4YoDaXyc2qDcobxOo3R
 ltMG/7j2K/dYmvMO1EVpH4IbaBuGPxwVElRc8zJ6hXOzQrct8c
 yCDI5NSIIL4g+5eSryJ3BuhJh6f9e8hYyRN/+VznCPoe8o7Gxs
 RrfV9EWNc84t5ZpVxR1PeyTld8KnBLsZqlgCJ4CKv2P15UjyGn
 vvSv52mkmijcqJIeK5FAsVOKxR3X2HXpMzSC+CfUFLtCEfRwfi
 IuUuH8bv6YAqIiPaxHuOk8QrbsEIhfUZrUqXfFrGN
Looks like this info wasn't sent to the bugtracker, forwarding manually.


-------- Original-Nachricht --------
Betreff: 	Re: [X2Go-Dev] Bug#287: Bug#287: x2goserver allows to connect 
to ALL X server sessions by default
Datum: 	Fri, 16 Aug 2013 13:41:34 +0000 (UTC)
Von: 	Fred Her. <x2go@edhil.net>
Antwort an: 	x2go-dev@lists.berlios.de
An: 	x2go-dev@lists.berlios.de



David Fuhrmann <fuhrmann_mail <at> web.de> writes:

>
> Hi,
>
> To rule out some specific configuration issue in our current system, I
installed a fresh linux mint inside a
> virtual machine and was able to confirm the issues.
>
> You should be able to reproduce it easily by doing the same. Choose Linux
Mint debian edition, 64 Bit, Mate
> package and install x2goserver following your instructions for debian 7.

I performed the test on the same configuration, and can confirm this issue:

On a fresh linux mint issue, Ubuntu edition, 64bits, MATE package.

x2go package installed :


ii  x2goserver                          4.0.1.6-0~712~raring1  amd64
ii  x2goserver-extensions               4.0.1.6-0~712~raring1  all
ii  x2goserver-xsession                 4.0.1.6-0~712~raring1  all

userA creates a session with a custom desktop (x-session-manager) and
connect. Then close the session window (but do not disconnect)

UserB creates a session with "connect to Local Desktop" and log in using his
own login and ssh password

UserB can connect to UserA desktop with full access.


As a workaround, ss there any x2goserver.conf parameters that could be used
to disable the Local Desktop access?






_______________________________________________
X2Go-Dev mailing list
X2Go-Dev@lists.berlios.de
https://lists.berlios.de/mailman/listinfo/x2go-dev




Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Wed Dec 4 13:06:57 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.