Re: X Window over SSH

From: Sebastien Berube (sberube@zeroknowledge.com)
Date: 08/10/01


Date: Fri, 10 Aug 2001 15:21:01 -0400 (EDT)
From: Sebastien Berube <sberube@zeroknowledge.com>
To: <cjclark@alum.mit.edu>
Subject: Re: X Window over SSH
Message-ID: <Pine.LNX.4.33.0108101518040.6591-100000@sberube.nsa.zks.net>


Crist's right, the only way you'll be able to avoid X traffic to be
tunneled through ssh is to set the X11Forwarding to off in your
server-side config file and THEN block port 6000 with your firewall.
That

-S
SysAdmin
sberube@zks.net

"Send urgent email ALL IN UPPERCASE. The mail server picks it up and flags it as a rush delivery."

On Thu, 9 Aug 2001, Crist J. Clark wrote:

> On Wed, Aug 08, 2001 at 03:18:38PM -0400, Greg Saoutine wrote:
> > My colleague came across the following within one of Sun's Newsgroups:
> >
> > [snip]
> > Xsun currently provides no way to disable listening for TCP connections.
> > If you need to worry about keeping people from connecting to the port,
> > you will need to use some sort of firewall software to block them.
> > [snip]
> >
> > Does it mean that the only way to *effectively* pipe X via SSH port 22 is to
> > set up a FW in front of the Sun box blocking port 6000? Any other
> > ideas/solutions?
>
> Huh? Putting a firewall in front of a box to block port 6000 has no
> impact on tunneling X through SSH.
> --
> Crist J. Clark cjclark@alum.mit.edu
>



Relevant Pages

  • Re: [fw-wiz] Is NAT in OpenBSD PF UPnP enabled or Non UPnP?
    ... >> I start by not giving logins and SSH access to users I don't trust. ... a network topology which goes around the ... >> firewall and thus is a serious hole to network security. ... >> have access via UPnP to, well, anything that device might happen to ...
    (Firewall-Wizards)
  • Re: ssh attempts
    ... the excellent iptables firewall you probably already have on your system. ... consider changing the port SSH listens on. ... Login to account webmaster not allowed or account non-existent. ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: RE: Telnet/SSL v SSH
    ... nearly the same robustness as SSH from the perspective of Authentication, ... and secure design. ... Disadvantages: Poor authentication system. ... When I was talking about elaborating on tunneling I was ...
    (Security-Basics)
  • Re: mpich and iptables firewall?
    ... to me it seems a very weird setup to have a firewall running ... on the cluster nodes. ... Using SGE you could disable rsh and ssh completely ... Chain FORWARD ...
    (comp.parallel.mpi)
  • Re: Problems with ipfw and ssh
    ... I get this error when updating my firewall rules via ssh. ... ${addcmd} 50 allow all from any to any via lo0 ... debug1: PAM: cleanup ...
    (freebsd-questions)