X2Go Bug report logs - #31
X2Go Clients Gr-Tunnel (client-side endpoint) listens on all TCP/IP address (probably should be: loopback only)

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Mon, 17 Sep 2012 14:48:02 UTC

Severity: normal

Tags: pending

Found in version 3.99.3.0-prerelease

Fixed in version 4.1.1.0

Done: X2Go Release Manager X2Go Release Manager <git-admin@x2go.org>

Bug is archived. No further changes may be made.

Full log


🔗 View this message in rfc822 format

X-Loop: owner@bugs.x2go.org
Subject: Bug#31: (no subject)
Reply-To: Guillaume Castagnino <gcastagnino@denyall.com>, 31@bugs.x2go.org
Resent-From: Guillaume Castagnino <gcastagnino@denyall.com>
Resent-To: x2go-dev@lists.x2go.org
Resent-CC: X2Go Developers <x2go-dev@lists.x2go.org>
X-Loop: owner@bugs.x2go.org
Resent-Date: Thu, 16 Apr 2015 13:35:02 +0000
Resent-Message-ID: <handler.31.B31.14291912759987@bugs.x2go.org>
Resent-Sender: owner@bugs.x2go.org
X-X2Go-PR-Message: followup 31
X-X2Go-PR-Package: x2goclient
X-X2Go-PR-Keywords: 
Received: via spool by 31-submit@bugs.x2go.org id=B31.14291912759987
          (code B ref 31); Thu, 16 Apr 2015 13:35:02 +0000
Received: (at 31) by bugs.x2go.org; 16 Apr 2015 13:34:35 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: **
X-Spam-Status: No, score=2.6 required=5.0 tests=BAYES_50,MISSING_SUBJECT
	autolearn=no version=3.3.2
X-Greylist: delayed 528 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Thu, 16 Apr 2015 15:34:34 CEST
Received: from fb1.mail.completel.net (fb1.mail.completel.net [213.245.2.47])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id DF6D45DAA3
	for <31@bugs.x2go.org>; Thu, 16 Apr 2015 15:34:34 +0200 (CEST)
Received: from smtp4.mail.completel.net (smtp4.cptl.sdv.fr [10.0.32.58])
	by fb1.mail.completel.net (Postfix) with ESMTP id A8B853CCEA
	for <31@bugs.x2go.org>; Thu, 16 Apr 2015 15:25:46 +0200 (CEST)
Received: from daex2010.denyall.local (mail.denyall.com [46.218.4.206])
	by smtp4.mail.completel.net (Postfix) with ESMTP id 0C56E3C01D
	for <31@bugs.x2go.org>; Thu, 16 Apr 2015 15:25:45 +0200 (CEST)
Received: from bespin.localnet (10.1.1.32) by DAEX2010.DenyAll.local
 (10.1.1.5) with Microsoft SMTP Server (TLS) id 14.2.347.0; Thu, 16 Apr 2015
 15:22:26 +0200
From: Guillaume Castagnino <gcastagnino@denyall.com>
To: <31@bugs.x2go.org>
Date: Thu, 16 Apr 2015 15:25:45 +0200
Message-ID: <2019231.JGKveepc01@bespin>
Organization: DenyAll
User-Agent: KMail/4.14.6 (Linux/4.0.0-gentoo; KDE/4.14.6; x86_64; ; )
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="windows-1252"
X-Originating-IP: [10.1.1.32]
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 10
X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrfeektddrgeejgdeigecutefuodetggdotefrucfrrhhofhhilhgvmecupfgfoffgtffkveetuefngfenuceurghilhhouhhtmecufedttdenucfgmhhpthihuchsuhgsjhgvtghtucdluddtmdenucfjughrpefhvfffkfhofggggfgtihesthhqredttdeiheenucfhrhhomhepifhuihhllhgruhhmvgcuvegrshhtrghgnhhinhhouceoghgtrghsthgrghhnihhnohesuggvnhihrghllhdrtghomheq
Hi,

Incidentally, I discovered that sending garbage on that port make the 
client crash and disconnect. So you can remotely disconnect any client 
using x2go client. Kind of DOS isn’t it ?

I discovered it simply doing this:
nmap  -v -n --open -Pn -sSV --version-intensity 0 -p T:1-65535 
192.168.56.0/24
crashing all x2goclients on the subnet!

Definitely, the proxy should NOT listen on INADDR_ANY but only on 
localhost in SshProcess::tunnelLoop.

Thanks

-- 
Guillaume Castagnino

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Nov 21 18:31:02 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.