Re: X11 forwarding setup correctly?

From: Shing-Fat Fred Ma (fma@doe.carleton.ca)
Date: 11/24/02


From: Shing-Fat Fred Ma <fma@doe.carleton.ca>
Date: 24 Nov 2002 05:02:35 GMT

those who know me have no need of my name wrote:

>>I will ask my sys admin if he can change them to
>>"yes". There doesn't seem to be any point in ssh'ing to a machine, then
>>have the xterms unencrypted.
>>
>>
>
>correct.
>

Hi,

I just want to be sure I know what I'm talking about
before I go asking my sys admin to change ssh
settings. From the man pages, enabling X11
forwarding poses a risk because someone who
can access my Xauthority file on the remote
(ssh server machine) can monitor my local (client)
X11 display, as well as see my keystrokes.

It seems kind of self defeating to disable X11
forwarding because this gives users no choice
but to open xterms outside the the ssh channel.
This is in fact what will happen. Why would this
be the default?

Also, who but me can access my Xauthority?
If they have access to my Xauthority, they pretty
well have to be me (or root), so my whole
account is vulnerable anyway. It doesn't matter
that they can see me typing my little matlab
program. Is this an overly naive way to look at it?

Fred

-- 
Fred Ma, fma@doe.carleton.ca
Carleton University, Dept. of Electronics
1125 Colonel By Drive, Ottawa, Ontario
Canada, K1S 5B6


Relevant Pages

  • Re: Suns mess up with ssh - any solution for me?
    ... > If you're forwarding X11 through ssh, you don't want to do this. ... patch 118305-04, which I installed by the downloading the reccomended ...
    (comp.unix.solaris)
  • Re: Suns mess up with ssh - any solution for me?
    ... > If you're forwarding X11 through ssh, you don't want to do this. ... patch 118305-04, which I installed by the downloading the reccomended ...
    (comp.sys.sun.admin)
  • Re: Remote access to Unix desktop
    ... PC, I use the VNC client, which works fine. ... X11 is an optional install from the installation DVD. ... First use a terminal emulator and ssh to the Unix system for any ...
    (comp.sys.mac.system)
  • SUMMARY: Tunnelling X11 via ssh
    ... Last week I posted to sunmanagers about a problem tunnelling X11 through ... ssh; I did ... So, the solution is/was to install X headers, cpp, ... If you compiled ssh with tcpwrappers support, ...
    (SunManagers)
  • Re: Documentation on "iptables -m policy"
    ... unsicherer als ssh -X. ... Man will X11 Umleitung durch SSH tunnels sowieso nicht ohne LBX proxy. ... verwendeten XAuth/MIT-cookie authentifikation schon mal als PoC ... Automagisches X11 forwarding in ssh eignet sich hervorragend fuer ...
    (de.comp.security.firewall)