X2Go Bug report logs - #509
Document NX/X11 security issue: clipboard sniffing

Package: wiki.x2go.org; Maintainer for wiki.x2go.org is x2go-dev@lists.x2go.org;

Reported by: Christoph Anton Mitterer <calestyo@scientia.net>

Date: Mon, 1 Jul 2013 02:48:02 UTC

Severity: grave

Tags: security

Full log


Message #60 received at 258@bugs.x2go.org (full text, mbox, reply):

Received: (at 258) by bugs.x2go.org; 28 Jan 2014 15:49:12 +0000
From mike.gabriel@das-netzwerkteam.de  Tue Jan 28 16:49:11 2014
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00 autolearn=ham
	version=3.3.2
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir (Postfix) with ESMTPS id 87B575DB13
	for <258@bugs.x2go.org>; Tue, 28 Jan 2014 16:49:11 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [78.46.204.98])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id F3494ADC;
	Tue, 28 Jan 2014 16:49:10 +0100 (CET)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id C9C433C737;
	Tue, 28 Jan 2014 16:49:10 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id ip4Pu142FKAz; Tue, 28 Jan 2014 16:49:10 +0100 (CET)
Received: from grimnir.das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPSA id 9F6D03C324;
	Tue, 28 Jan 2014 16:49:10 +0100 (CET)
Received: from 195.244.234.222 ([195.244.234.222]) by
 mail.das-netzwerkteam.de (Horde Framework) with HTTP; Tue, 28 Jan 2014
 15:49:10 +0000
Date: Tue, 28 Jan 2014 15:49:10 +0000
Message-ID: <20140128154910.Horde.bz7_7CdkDRplg9xdW4kZbg2@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: x2go-user@lists.berlios.de
Cc: 258@bugs.x2go.org
Subject: Re: [X2Go-User] Limiting clipboard sharing
References: <52E69B93.8010904@sourcecap.ch>
In-Reply-To: <52E69B93.8010904@sourcecap.ch>
User-Agent: Internet Messaging Program (IMP) H5 (6.1.4)
Accept-Language: en,de
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 195.244.234.222
X-Remote-Browser: Mozilla/5.0 (X11; Linux x86_64; rv:26.0) Gecko/20100101
 Firefox/26.0 Iceweasel/26.0
Content-Type: multipart/signed; boundary="=_07l0yBSoJq8RBmtev9FzKA7";
 protocol="application/pgp-signature"; micalg=pgp-sha1
MIME-Version: 1.0
[Message part 1 (text/plain, inline)]
Hi Kris,

On  Mo 27 Jan 2014 18:46:59 CET, Kris Ilowiecki wrote:

> Hello,
>
> I am quite new to X2Go, and really impressed by it. I'd like to  
> switch from opennx to X2Go, but I can't find a way to limit  
> clipboard sharing.
>
> Opennx, as well as other NX forks, has the options to enable clipboard
> sharing both ways, one-way, or disable it completely. So far I have  
> failed to find a setting to limit this in X2Go.
>
> I'd need clipboard sharing to work only in the client->server
> direction, or at least to disable it completely.
>
> I have searched for it for quite a while, but the best I have  
> managed to find is a bug report
> http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=258
> and a mailing list question without a single reply.
>
> Is there some way to configure it?
> If not, is it going to be hard to write a patch that would turn
> this off at compilation time?
> I've also been thinking of using some external programs to achieve  
> the effect, e.g. putting X2Go inside Xephyr, or the other way round...
>
> Any hints most welcome
>
> Many thanks,
> Kris

There should be two approaches...

 1) disable clipboard server-side for all users
 2) disable clipboard in X2Go Client / PyHoca-GUI on the client-side

The first is easy. Please look at /usr/bin/x2gostartagent of  
x2goserver package and make clipboard configurable via  
/etc/x2go/x2goserver.conf. Send a patch to our BTS [1].

The second approach is for us devs, I guess...

The workaround provided by Mike#2 is a fine approach, but not a real  
solution to this problem.

Mike#1

[1] http://wiki.x2go.org/doku.php/wiki:bugs
-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Thu Mar 28 13:19:29 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.