Re: ssh X-forwarding not working aix

From: Darren Tucker (dtucker_at_dodgy.net.au)
Date: 04/28/04


Date: Wed, 28 Apr 2004 03:21:15 +0000 (UTC)

In article <z3vjc.56893$CU5.37843@newssvr25.news.prodigy.com>,
Darren Dunham <ddunham@redwood.taos.com> wrote:
>The channel between the two ssh machines is encrypted. That does
>nothing to prevent some third party from communicating (unencrypted)
>with the forwared port.

True, but the lack of the xauth cookie should stop them from doing
anything. Try this experiment: log in to a host with X forwarding on,
then log in from another window as another user and copy $DISPLAY.

$ ssh -X user1@localhost
user1$ echo $DISPLAY
localhost:15.0

[in another window]
$ ssh -x user2@localhost
user2$ DISPLAY=localhost:15.0 xterm

You should get an error in window 1 something like "X11 connection
rejected because of wrong authentication" and no xterm.

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


Relevant Pages

  • Re: some attack to fedora machine .
    ... will compromise the BIOS, these will be cross platform, they will affect ... F8 installation last December. ... Each and every time the invader came in through ssh. ... Window$ maybe Window$, and *nix *nix, but because window ...
    (Fedora)
  • Re: Remote login, graphically?
    ... I can already login via SSH and fix things with a text editor. ... Now, I'd like to start several X programs on her machine, but have the user interface on my machine. ... However, when I start "firefox", I get the following error after some time waiting: ... The program 'firefox-bin' received an X Window System error. ...
    (Ubuntu)
  • Re: [Full-Disclosure] SSH Exploit Request
    ... *your* ssh can still go away if something else does a runaway and runs ... What use is an open SSH window, Mr Anderson, if you have no character echo? ... in a failure cascade - when one sysadmin is installing software during a 2AM ... test window and he's tired and cranky because instead of getting some sleep, ...
    (Full-Disclosure)
  • Re: Setting Column and Row Size
    ... I've been coding an SSH client for fun and learning, and I've noticed that my server sends "\r" characters after every 80 characters of output. ... How can I have my client set the row and column size? ... I would like to do this dynamically when the window is resized as well. ...
    (comp.terminals)
  • Re: persistent emacs a la screen?
    ... I solved this problem using something called tightVNC. ... should be a lot easier to install in the future. ... with tightVNC you run an X desktop (with a window ... from outside through SSH using a viewer. ...
    (comp.emacs)