Re: XDM Insecurity revisited

From: Alan Cox (alanat_private)
Date: Thu Aug 19 1999 - 06:36:38 PDT

  • Next message: David LeBlanc: "Re: Win32 File Naming (again)"

    > Digital Unix 4.0E, SuSE Linux 6.1 and Red Hat Linux 6.0 are still
    > (1.5 years later) shipped with this default Xaccess file. It is somehow
    > ironic that e.g. SuSE now uses tcpwrappers by default on most TCP
    > services in it's distribution and describes the use of tcpwrappers in
    > the manual in a special chapter about security, but fails to close (or
    > even mention) that way to circumvent login restrictions.
    
    Even more fun, just open 1024 xdcmp sessions with a remote xdm on a low
    spec box. Xdm doesnt like this. Gdm at least does damage limitation in
    this case.
    
    On the Red Hat side, for a standard Red Hat 6 using gdm not xdm, edit
    /etc/X11/gdm.conf and set it to
    
    [xdcmp]
    Enable=0
    
    and life is happier.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:57:20 PDT