X2Go Bug report logs - #773
DirectRDP: X2Go Client reveals user password in process list if xfreerdp is used

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Thu, 29 Jan 2015 12:15:01 UTC

Severity: grave

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #5 received at submit@bugs.x2go.org (full text, mbox, reply):

Received: (at submit) by bugs.x2go.org; 29 Jan 2015 12:10:57 +0000
From mike.gabriel@das-netzwerkteam.de  Thu Jan 29 13:10:55 2015
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id BBD193BC72
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id 6D51A2FC
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 3EC7B3C095
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:55 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id XhNWDTtlCQMv for <submit@bugs.x2go.org>;
	Thu, 29 Jan 2015 13:10:55 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id DEC7D3C051
	for <submit@bugs.x2go.org>; Thu, 29 Jan 2015 13:10:54 +0100 (CET)
Received: from bifrost.das-netzwerkteam.de (bifrost.das-netzwerkteam.de
 [178.62.101.154]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Thu, 29 Jan 2015 12:10:54 +0000
Date: Thu, 29 Jan 2015 12:10:54 +0000
Message-ID: <20150129121054.Horde.CM1lx2L_ybSEiqc7NkNzhw3@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: submit@bugs.x2go.org
Subject: DirectRDP: X2Go Client reveals user password in process list if
 xfreerdp is used
User-Agent: Internet Messaging Program (IMP) H5 (6.2.2)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 178.62.101.154
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101
 Firefox/32.0 Iceweasel/32.0
Content-Type: multipart/signed; boundary="=_t6l2H1my2ZI_HcAZEwv1kQ1";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
Package: x2goclient
Severity: grave

When a users uses X2Go Client for directly accessing an RDP Server,  
then one can use the DirectRDP feature.

The DirectRDP features allows wrapping around the rdesktop command or  
the xfreerdp command.

With both wrapper modes, the password is given to the RDP client  
application on the command line.

With rdesktop, the command line ($@) gets rewritten for the process  
list and the password is replaced by XXXXXXXX.

With xfreerdp, the command line stays as is and reveals the RDP user's  
password on the process list of the machine that X2Go Client runs on.

The FreeRDP people have added a command line option --from-stdin to  
xfreerdp 1.0.x for this purpose, that may be an option using in X2Go  
Client. However, I am not sure, if this option survived in xfreerdp  
1.1.x or later (it is not on the xfreerdp man page for  
1.1.0~git<sometime-in-2014> as shipped with Debian jessie.

Mike



-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Fri Apr 26 15:19:04 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.