X2Go Bug report logs - #773
DirectRDP: X2Go Client reveals user password in process list if xfreerdp is used

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Thu, 29 Jan 2015 12:15:01 UTC

Severity: grave

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #24 received at 773@bugs.x2go.org (full text, mbox, reply):

Received: (at 773) by bugs.x2go.org; 26 Mar 2019 14:02:28 +0000
From X2Go-ML-1@baur-itcs.de  Tue Mar 26 15:02:25 2019
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=3.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham autolearn_force=no version=3.4.2
Received: from localhost (localhost [127.0.0.1])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id E25CA5DAE9;
	Tue, 26 Mar 2019 15:02:24 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at ymir.das-netzwerkteam.de
Received: from ymir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (ymir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id PSXOwwBTMWZG; Tue, 26 Mar 2019 15:02:17 +0100 (CET)
X-Greylist: delayed 301 seconds by postgrey-1.35 at ymir.das-netzwerkteam.de; Tue, 26 Mar 2019 15:02:17 CET
Received: from mout.kundenserver.de (mout.kundenserver.de [212.227.126.133])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 662A35DACB;
	Tue, 26 Mar 2019 15:02:17 +0100 (CET)
Received: from [192.168.0.15] ([109.193.81.67]) by mrelayeu.kundenserver.de
 (mreue011 [212.227.15.129]) with ESMTPSA (Nemesis) id
 1MhlbM-1gVL5P3L9c-00dpJu; Tue, 26 Mar 2019 14:57:15 +0100
Subject: Re: [X2Go-Dev] Bug#773: Bug#773: xfreerdp 2 also XXXXes the password
To: x2go-dev@lists.x2go.org, 773@bugs.x2go.org
References: <20190326131906.Horde.BkvbGtzjzEB4n_92NerAY5k@mail.das-netzwerkteam.de>
From: Stefan Baur <X2Go-ML-1@baur-itcs.de>
Openpgp: preference=signencrypt
Autocrypt: addr=X2Go-ML-1@baur-itcs.de; prefer-encrypt=mutual; keydata=
 xsBNBFLfOiwBCACzIiDVwWVRvuMzgSAvXRFRaPaZOSB8s84PG1oGLfmqhwzF44vj1Xv4tcKD
 mvu0TsLTksOkvop8WwGYeeU8lDaxEG1zyN8SOu1WU/FPEKw2jITRox8yIrSkUsMkWYuxdjv/
 9XcAh9qaPsHP7E1jD6/wVZuYZkuX6W41Nxt06VsvDGCfrbQh4ya7w1IiSnoQeIHNNQVN9f3j
 xcHLj5S5YriSCThtbFCdr3AJXfF5iMolu8kLgAXM0bH1C7PxAjM/pQjWmdMVN/Y+uXXzcMO8
 8aQ0f0q3QeGWxCAP2xwBapUfP6LHDRPp/tV7P7ji8wKlabrSGdv0M9Qd9pn/YCYQE0ZdABEB
 AAHNJlN0ZWZhbiBCYXVyIDxwb3N0bWFzdGVyQHN0ZWZhbmJhdXIuZGU+wsCCBBMBAgAsAhsj
 BwsJCAcDAgEGFQgCCQoLBBYCAwECHgECF4ACGQEFAlwtWmgFCRK0IbcACgkQbt30GM2+URkj
 nwgAixhVoMxijCsh9jxxCUYBj7lC5HYhJmlAB+bZOfl1XI8xqMLw8YGECfu0VSe++FlaOAuc
 gArofqu79E2+wKxPaqW2lC94eKR1+kgkDOJyqckYj2Xmyi+vDfrOWjbyawIwiq5FUW2CB6zv
 nkTr68ZQ43mAVC1zz2tpAikn2Af4/OdHwUBzSAOpUt4rDbXDe93WW34XuyG2RDma6kE1Cr0u
 ilqvzKOz5SYp5ASmCyaA0wCzs7fjTy2KuMlOCSFRzwPJpzddr8rS9ZiTLdia/BZvShBEjOq4
 MZHWYv+RGK5RB4eDzw0KbPszXRJBUdXiZIcI0jqbC57Ht64ok3lXquXp987ATQRS3zosAQgA
 4KPXmGU1XE8CTRJ/4m/f8MTri3JfEvGJTerWwC2hBuXHGWrSBmmRNAdJHzNTvq5IoR9tQ6Cb
 Nrqxf6alr/v34Vr2bUg0s+jlK9TWOkVLAFoz6zytm/2BrRBIZ5So6Ymfc6efwsScsHOI++wi
 pzqELkpluqtXysb13RsBVLxBdp5TZCVPjCc9pLWjudfjEagQt2oJgtO2WndasrKvoZYkfRi6
 oSCK9B84YjNJoRF00LdK3n7K3SBvj4UPSl+ygzLVaD+3ZdIlbhX+bfn/Vp/10xdJ+/U8Fr7l
 7umrBKr17D8eO3mRYMGY9w1qc+pfNGOR76GIbPWj2tPVaBD9nmUaowARAQABwsBlBBgBAgAP
 AhsMBQJcLVqtBQkStCH9AAoJEG7d9BjNvlEZInkIAIcchwZxurIpwJJR8qMMXD+RSvj7mY55
 VIXOKUX0uAUTEoJTzFcqbdGkzcJB9y0NlUo9dv4chPT21M61y0bjJjhaDUshCLa1+YyFSSWp
 GBOKrLIsWusqC9zVwgf7TtjVmXt23jZwoDWjXoMlg9eQONMi5Z4u+lDOyPKD+lGJAcjJkQsI
 zL9hha3vuhmUclxgdALTJWzQBp+Y7u9QDub4uqf/TyuDpYASiP0winBRfTug+XjP5YZjU//P
 07H9WhiUCsHp6L9j3QzvrovVy2zz0j7JhyhW3e957vHz2skkSVv3QGtHMswcgK3XaQ9YdgWO
 ELHmBhevaIcJIxDvTBl3pYQ=
Message-ID: <88d90ba4-264d-6560-8a12-42cde6ed122c@baur-itcs.de>
Date: Tue, 26 Mar 2019 14:57:11 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101
 Thunderbird/60.5.1
MIME-Version: 1.0
In-Reply-To: <20190326131906.Horde.BkvbGtzjzEB4n_92NerAY5k@mail.das-netzwerkteam.de>
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="M8kzOMZSvX8bcVF8e8YoyrRXijFYXC6mh"
X-Provags-ID: V03:K1:mswfKWXDdflHDJSOf1f0Q+K0lS+Do/1delsUP7axB/nc6izz+mA
 wrfC2sqdRxWo858l9XKVguVavPOtncNsEpnRuQpDWe3WAn4WqTkAjXFd665KiUljyzzLSk9
 cWLYFAdKSZhw4Epre91KNrxU6jyFGERSXFukoVbqsGp5mhUFUKmueHqFE8dqdL5r3LUTcnZ
 PT4TKLJzgpt6pbFBbx4YQ==
X-UI-Out-Filterresults: notjunk:1;V03:K0:i9LA5Izc9BA=:DuCPH9FN/hpGbgTUTXSGf8
 pxX7p1ecYZcA4xxvwu05e9QDJcym3STh4SKvKADLRQ8/MlzrkEm0Tvt118KsVC4OJcrenilvu
 SJDlswtQWqrDKAspl6OVXV7Wo0TY96dEyeA9OYlKFI99Q4GmD4Qw3bwyMhuGVA1DumIHeHCxJ
 LyL3BXgWJQvZ3S8T43pWiRaltaYB1mIcVcZnpn4NrodVlv706iSELG8pNIcGeYCPsypO+cC/h
 ZIspUfHLzxq9Z2Yb/qihyQuQbAby7nFe6sKWb5b0OcBlJ8uul7Bm6KMnqpXbnR2OYL151cRlT
 yWDSp0+2WsC5UEfoCb9tQ3SvjbcbpEq2OOuYmTgVPPSpsmJgwRNZotmWFewDCqUEQk7FMQBVK
 7dT6gXMNK7sXZ4PnDJCZZhilp56UUb5e/pbsO5qaNJ4A3yHqzyMFtGGAroOHmXNt4ukA3KXEX
 2y+6WwVAf3ytazlMVKmPLUGE+AEmvzrqJJQ8KPfPsSRIKh+peV6TFocbafpaVGnz8W7CBiJ9c
 r8xg1La+IQBLZSatjVA2n934+2Yq8zis/VjoCstIN+3/I8k/i8IE0Mv3gW9tXMaJQ2nQc85Gb
 oD57vszddZlPnOTcyqic/an++huicfQrbFh0eri81mkbspNRXRk3hLJKd248HwqS31tRRYP4p
 JKARz4F93Kyq/cLfwVTF/gZ0QQiBTORz4Mr0KhBcFL3+/o5clD91kykhKAhnE/gcf9Q3/q9Pe
 suQvJgwGYU+LwmxoGsibTI0sRvHZow2oYSnvto8Ham1nkT4nUw9Ho9VT5ZY=
[Message part 1 (text/plain, inline)]
Uh, wait a minute.  We're still shipping X2GoClient for distributions
that have an older xfreerdp version in their repository.

Thus, this should not be closed until all supported distros have made
the switch to xfreerdp2.

-Stefan

Am 26.03.19 um 14:19 schrieb Mike Gabriel:
> Control: close -1
> 
> On  Fr 22 Mär 2019 23:08:00 CET, Ulrich Sibiller wrote:
> 
>> xfreerdp 2 also XXXXes the password
>>
>> So with a current version this is a non-issueand can be closed.
> 
> Thus, closing...
> Mike
> 
> _______________________________________________
> x2go-dev mailing list
> x2go-dev@lists.x2go.org
> https://lists.x2go.org/listinfo/x2go-dev
> 


-- 
BAUR-ITCS UG (haftungsbeschränkt)
Geschäftsführer: Stefan Baur
Eichenäckerweg 10, 89081 Ulm | Registergericht Ulm, HRB 724364
Fon/Fax 0731 40 34 66-36/-35 | USt-IdNr.: DE268653243

[signature.asc (application/pgp-signature, attachment)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Nov 21 17:23:57 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.