X2Go Bug report logs - #819
X2Go Client exposes all (network and local) drives on client-side folder sharing

version graph

Package: x2goclient; Maintainer for x2goclient is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goclient is src:x2goclient.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Mon, 16 Mar 2015 13:15:02 UTC

Severity: grave

Tags: build-win32

Found in version 4.0.3.2

Full log


Message #5 received at submit@bugs.x2go.org (full text, mbox, reply):

Received: (at submit) by bugs.x2go.org; 16 Mar 2015 13:13:32 +0000
From mike.gabriel@das-netzwerkteam.de  Mon Mar 16 14:13:30 2015
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 212F35E188
	for <submit@bugs.x2go.org>; Mon, 16 Mar 2015 14:13:30 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id C193A10
	for <submit@bugs.x2go.org>; Mon, 16 Mar 2015 14:13:29 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id A12793BD8D
	for <submit@bugs.x2go.org>; Mon, 16 Mar 2015 14:13:29 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id RcYAcSwWZd2A for <submit@bugs.x2go.org>;
	Mon, 16 Mar 2015 14:13:29 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id 2A09F3BB21
	for <submit@bugs.x2go.org>; Mon, 16 Mar 2015 14:13:29 +0100 (CET)
Received: from m-097.informatik.uni-kiel.de (m-097.informatik.uni-kiel.de
 [134.245.254.97]) by mail.das-netzwerkteam.de (Horde Framework) with HTTP;
 Mon, 16 Mar 2015 13:13:28 +0000
Date: Mon, 16 Mar 2015 13:13:28 +0000
Message-ID: <20150316131328.Horde.OmAEBtvMbmg3dIKaMec6tw1@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: submit@bugs.x2go.org
Subject: X2Go Client exposes all (network and local) drives on client-side
 folder sharing
User-Agent: Internet Messaging Program (IMP) H5 (6.2.2)
Accept-Language: de,en
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 134.245.254.97
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:32.0) Gecko/20100101
 Firefox/32.0 Iceweasel/32.0
Content-Type: multipart/signed; boundary="=_XPcxs22AIqzS_aFuGx0New2";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
Package: x2goclient
Version: 4.0.3.2
Tags: build-win32
Severity: grave

Hi all,

I am not sure if this bug is X2Go Client or X2Go Server related,  
because I have no extended access to the site where the below issue  
just occurred.

  Client:
    X2Go Client for Windows (4.0.3.2-20150301)
    on Windows 8.1 64bit

  Server:
    X2Go Server 4.0.1.19
    running on Ubuntu 10.04

Session Type: GNOMEv2 desktop session

The windows machine is hooked into a network, i.e. the Windows's users  
%HOMEDRIVE% is on a server-side share, there are also several other  
network drives available. (as drive letters).

The user (a customer of mine) tried to directly share the "Documents"  
folder with the running X2Go session and then this SSHFS mount  
appeared on the X2Go Server's side:

  ~user/media/disk/_cygdrive_

This "_cygdrive_" folder contained letters (one drive letter per  
available network drive).

From there on you could browse all drive letters and sub-directories  
available on the client-side MS Windows machine. Thus, exposing all  
sorts of drive letters and their subfolders to the X2Go session.


!!! This must be considered as a severe data security breach. !!!


minor side issue: Furthermore, client-side shared folders hosted on  
network drives appeared in the X2Go session, but were not accessible  
by the user running the X2Go session (marked by a read cross and a  
padlock).

Greets,
Mike



-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Wed Apr 24 02:09:23 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.