Re: x11 apps traffic not encrypted

From: Darren Dunham (ddunham@redwood.taos.com)
Date: 02/27/03


From: Darren Dunham <ddunham@redwood.taos.com>
Date: Thu, 27 Feb 2003 17:00:21 GMT

Richard E. Silverman <slade@shore.net> wrote:
>>>>>> "DD" == Darren Dunham <ddunham@redwood.taos.com> writes:

> DD> If it's on port 6000, then no it's not encrypted (or otherwise
> DD> being handled by ssh).

> He doesn't say on what side (client/server) he's doing the sniffing, or
> what interface he's looking at; however, as a blanket statement, this is
> false. If he's sniffing on the client side in such a way as to see
> traffic on the loopback, then he would see the plaintext X traffic between
> the SSH client and the X server.

Good point. I wasn't considering that when I wrote the response. It
won't happen on solaris though. You can't snoop loopback traffic.

-- 
Darren Dunham                                           ddunham@taos.com
Unix System Administrator                    Taos - The SysAdmin Company
Got some Dr Pepper?                           San Francisco, CA bay area
         < This line left intentionally blank to confuse you. >


Relevant Pages

  • Multiple issues with Mac OS X AFP client
    ... Multiple issues with Mac OS X AFP client ... connections to an Apple file server over SSH - a commendable effort to ... .GlobalPreferences.plist (the AFP client does not follow Apple's ...
    (Bugtraq)
  • [Full-Disclosure] Multiple issues with Mac OS X AFP client
    ... Multiple issues with Mac OS X AFP client ... connections to an Apple file server over SSH - a commendable effort to ... .GlobalPreferences.plist (the AFP client does not follow Apple's ...
    (Full-Disclosure)
  • Multiple issues with Mac OS X AFP client
    ... Multiple issues with Mac OS X AFP client ... connections to an Apple file server over SSH - a commendable effort to ... .GlobalPreferences.plist (the AFP client does not follow Apple's ...
    (Full-Disclosure)
  • Re: Explanation of SSH
    ... I am still unclear on how SSH works exactly. ... Client issues SSH command and names server ... "Shopper" says "server sends back its public host and server keys ... Surely there is only one public key it sends ...
    (comp.security.ssh)
  • Re: Remote X over rsh
    ... all I'm doing is running X and ssh. ... the weak machine is the one where on he wishes to display, ... Possibly the "my client" confused the issue; ... just use X without ssh forwarding. ...
    (comp.os.linux.x)