From unknown Mon Apr 27 20:24:45 2026
MIME-Version: 1.0
X-Mailer: MIME-tools 5.507 (Entity 5.507)
X-Loop: owner@bugs.x2go.org
From: owner@bugs.x2go.org (X2Go Bug Tracking System)
Subject: Bug#773 closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
 (Re: [X2Go-Dev] Bug#773: xfreerdp 2 also XXXXes the password)
Message-ID: <handler.773.b773.155360636119526.notifdone@bugs.x2go.org>
References: <20190326131906.Horde.BkvbGtzjzEB4n_92NerAY5k@mail.das-netzwerkteam.de>
X-X2go-PR-Message: they-closed 773
X-X2go-PR-Package: x2goclient
X-X2go-PR-Source: x2goclient
Date: Tue, 26 Mar 2019 13:20:03 +0000
Content-Type: multipart/mixed; boundary="----------=_1553606403-19785-0"

This is a multi-part message in MIME format...

------------=_1553606403-19785-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset=utf-8

This is an automatic notification regarding your Bug report
which was filed against the x2goclient package:

#773: DirectRDP: X2Go Client reveals user password in process list if xfree=
rdp is used

It has been closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>.

Their explanation is attached below along with your original report.
If this explanation is unsatisfactory and you have not received a
better one in a separate message then please contact Mike Gabriel <mike.gab=
riel@das-netzwerkteam.de> by
replying to this email.


--=20
773: http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=3D773
X2Go Bug Tracking System
Contact owner@bugs.x2go.org with problems

------------=_1553606403-19785-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 773) by bugs.x2go.org; 26 Mar 2019 13:19:21 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=3.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham autolearn_force=no version=3.4.2
Received: from localhost (localhost [127.0.0.1])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 9BAF35DAE9
	for <773@bugs.x2go.org>; Tue, 26 Mar 2019 14:19:20 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at ymir.das-netzwerkteam.de
Received: from ymir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (ymir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id Zr1PvNx_A4NN for <773@bugs.x2go.org>;
	Tue, 26 Mar 2019 14:19:12 +0100 (CET)
Received: from fregna.das-netzwerkteam.de (fregna.das-netzwerkteam.de [148.251.53.130])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id AC42D5DACB
	for <773@bugs.x2go.org>; Tue, 26 Mar 2019 14:19:12 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [IPv6:2a01:4f8:202:1381::105])
	by fregna.das-netzwerkteam.de (Postfix) with ESMTPS id 8D48260559;
	Tue, 26 Mar 2019 13:19:12 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 83314C421A;
	Tue, 26 Mar 2019 14:19:12 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id gs2Y8jmdqQBo; Tue, 26 Mar 2019 14:19:06 +0100 (CET)
Received: from das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 9053CC4215;
	Tue, 26 Mar 2019 14:19:06 +0100 (CET)
Received: from bifrost.das-netzwerkteam.de (bifrost.das-netzwerkteam.de
 [178.62.101.154]) by mail.das-netzwerkteam.de (Horde Framework) with HTTPS;
 Tue, 26 Mar 2019 13:19:06 +0000
Date: Tue, 26 Mar 2019 13:19:06 +0000
Message-ID: <20190326131906.Horde.BkvbGtzjzEB4n_92NerAY5k@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: uli42@gmx.de, 773@bugs.x2go.org
Subject: Re: [X2Go-Dev] Bug#773: xfreerdp 2 also XXXXes the password
In-Reply-To: <CANVnVYLZx8hZw_QnuK1boqLqyQEB03AYX+Vrcv1ygpciVqZCMw@mail.gmail.com>
User-Agent: Horde Application Framework 5
Accept-Language: de,en
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 178.62.101.154
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101
 Firefox/60.0
Content-Type: multipart/signed; boundary="=_qdMgE7NIAy7TZAUKKIDn5-i";
 protocol="application/pgp-signature"; micalg=pgp-sha256
MIME-Version: 1.0

This message is in MIME format and has been PGP signed.

--=_qdMgE7NIAy7TZAUKKIDn5-i
Content-Type: text/plain; charset=utf-8; format=flowed; DelSp=Yes
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Control: close -1

On  Fr 22 M=C3=A4r 2019 23:08:00 CET, Ulrich Sibiller wrote:

> xfreerdp 2 also XXXXes the password
>
> So with a current version this is a non-issueand can be closed.

Thus, closing...
Mike
--=20

DAS-NETZWERKTEAM
c\o=20Technik- und =C3=96kologiezentrum Eckernf=C3=B6rde
Mike Gabriel, Marienthaler str. 17, 24340 Eckernf=C3=B6rde
mobile: +49 (1520) 1976 148
landline: +49 (4354) 8390 139

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de


--=_qdMgE7NIAy7TZAUKKIDn5-i
Content-Type: application/pgp-signature
Content-Description: Digitale PGP-Signatur
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIzBAABCAAdFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAlyaJsoACgkQmvRrMCV3
GzF/8hAAmCRXopedJVdB3dCA2ByPJlApPu17Xjw7gUg17iiZ+QsPe3BTVvHa1Do0
tdKRly3b8pkfHows8W5zQ1LlVQ+f0Ho1tBTWzhRjuVnQP4Lkg+6FwxwhC9aS+Jvs
gFk02vtYzi8bXbCwwenrQD2rwltMiqSo2mhNXqnKlHqgRZVxbNVaZ/eGXU368q/M
RLcK2CDDAssbhqaYLDLQ5x99gHb+Zx2o0cxOc1grlBp9zkmuarsrlujFb30wJEdf
xNQscChbvBu4XaFThOwDyDJhEiB7mMZu3rNYGrdA68jF8LfGyhUAeVfhPptHBtA2
qVCEKohXMhW7xjz5J+/Jecz49HXeVxBASTkv7J/vxS+e+IatdAJY8koDPzAKmVyP
MB21dsJsC4k8s+7oSRV/o2mRVgk4OpYNcmW7BYrCM8fN1Pl9GiNDx1wo7v6rjSe+
LBmLUah7WXkhlJSq56HuB58ALZGyA9T5TrSy2hLz3E27fcQgLEMddkDy2yeHWzwT
gUfbg4oI3NGglYI6D9IJrNpBVpQpjpWC0H8n2/NsvG1q63iwsHITWbrAs6eUrbhu
KeM4Xry7AGGgzY+5/JOQ/WKvtX8RtWv3bKU5OopJQ488iVC5SitunShg1QKFV+2W
2n6aEI0ZVvHOq3LahGlJYe2Pipt6SD0nG528smSc4bEbeTNL7Ok=
=FTfo
-----END PGP SIGNATURE-----

--=_qdMgE7NIAy7TZAUKKIDn5-i--


------------=_1553606403-19785-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.x2go.org; 29 Jan 2015 12:10:57 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id BBD193BC72
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 6D51A2FC
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 3EC7B3C095
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id XhNWDTtlCQMv for <submit@bugs.x2go.org>;
	Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id DEC7D3C051
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:54 +0100 (CET)
Received: from bifrost.das-netzwerkteam.de (bifrost.das-netzwerkteam.de
 [178.62.101.154]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Thu, 29 Jan 2015 12:10:54 +0000
Date: Thu, 29 Jan 2015 12:10:54 +0000
Message-ID: <20150129121054.Horde.CM1lx2L_ybSEiqc7NkNzhw3@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: submit@bugs.x2go.org
Subject: DirectRDP: X2Go Client reveals user password in process list if
 xfreerdp is used
User-Agent: Internet Messaging Program (IMP) H5 (6.2.2)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 178.62.101.154
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101
 Firefox/32.0 Iceweasel/32.0
Content-Type: multipart/signed; boundary="=_t6l2H1my2ZI_HcAZEwv1kQ1";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0

This message is in MIME format and has been PGP signed.

--=_t6l2H1my2ZI_HcAZEwv1kQ1
Content-Type: text/plain; charset=UTF-8; format=flowed; DelSp=Yes
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Package: x2goclient
Severity: grave

When a users uses X2Go Client for directly accessing an RDP Server,=20=20
then=20one can use the DirectRDP feature.

The DirectRDP features allows wrapping around the rdesktop command or=20=20
the=20xfreerdp command.

With both wrapper modes, the password is given to the RDP client=20=20
application=20on the command line.

With rdesktop, the command line ($@) gets rewritten for the process=20=20
list=20and the password is replaced by XXXXXXXX.

With xfreerdp, the command line stays as is and reveals the RDP user's=20=
=20
password=20on the process list of the machine that X2Go Client runs on.

The FreeRDP people have added a command line option --from-stdin to=20=20
xfreerdp=201.0.x for this purpose, that may be an option using in X2Go=20=
=20
Client.=20However, I am not sure, if this option survived in xfreerdp=20=20
1.1.x=20or later (it is not on the xfreerdp man page for=20=20
1.1.0~git<sometime-in-2014>=20as shipped with Debian jessie.

Mike



--=20

DAS-NETZWERKTEAM
mike=20gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x=
fb

--=_t6l2H1my2ZI_HcAZEwv1kQ1
Content-Type: application/pgp-signature
Content-Description: Digitale PGP-Signatur
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAABAgAGBQJUyiNOAAoJEJr0azAldxsxFxsQAJmfru7NVvZ9N70rYx69NjSP
9IazEIVAsG/fQTdR8LKU/p4p4f/XP2cFOoi11zc733EtgSHTOKkGpp2mWP+BEbeV
yCicbccMH54eaawSdbAXIqhZh/KfCLwc6RbLrWt33zxmX6yj7tKkhjNpmS36quGs
RLGnNndWEAUMGtV6CJy5vmQ8PCrEn8x057m47l7CwKsHSZg8qzETLKePv98Vao19
/6lLALbPVpL3wocR+yHo6nGXoj4qFogVMJb4rniAEM0td/155uCvMYBSZES4uaHD
2qOYBIpVkgX5Cft0xh0CAUT/o6uyyfQ8XO89vRv7YPW+BUc6xlOzBgvm5F0EWllI
JpExHf1nXnKvI7jJ1quEbWrCzaXN4nE/eEZNDas6iGqct/r6NcDpFJZHkpCap+Ct
CUcrMMM8ADibYUMGKmrjCWvwXTj2RVQEDDsDoPu+WKWC9xOJ+9aC26brIR1KkNM3
pMFxPmcJixRm0Uw5k0xaeBMZ7tGnUIio0dvdIm/EVzxgG9EKeRJ7xTy9IZZ/J9rv
NPw3w0Kys+kHneaflQ2V9zPD42c5gGzvoV84t+JPjzGAqrCylc/tDZe6/xE8O23f
C0dhOT6nS3D2xa3Ls7eLyTCC9wbTaAHyuF6FMqJGpsB3b4ZjhR5pcMju0DZhFSyj
em+p6UE5fEf2wb80aHJ0
=LNR4
-----END PGP SIGNATURE-----

--=_t6l2H1my2ZI_HcAZEwv1kQ1--

------------=_1553606403-19785-0--
