xhost + problems

Erik Bågfors zindar at gmail.com
Thu May 12 10:53:24 UTC 2005


On 5/12/05, Tony Arnold <tony.arnold at manchester.ac.uk> wrote:
> On Thu, 2005-05-12 at 08:34 +0200, Niels L. Ellegaard wrote:
> > Dear masters
> >
> > I have a laptop with hoary and I cannot use xhost + for telnet on my
> > local network. I get the following error
> 
> Note that this is a serious security risk running this command. It measn
> that anyone can connect to your X server and listen for keybord events
> and log usernames and passwords! If both client and server machine are
> behind a firewall that prevents incoming connections on ports 6000
> through 6063, then you are only at risk from machines inside your
> firewall.

Acctually, since the X server in hoary by default runs with the
"nolisten tcp" flag.  It will not mean that anyone can connect to your
X server :)

But, normally you are right.
 
> > login: niels
> > Password:
> > Last login: Thu May 12 11:45:09 from niels.intranet.xxx.ac.in
> > [lpc2~]$ setenv display niels:0.0
> 
> Doesn't the DISPLAY variable have to be in upper case? In bash shell, I
> tend to use the following:

correct.

To avoid security problems, learn to use ssh instead.

/Erik




More information about the ubuntu-users mailing list