OpenSSH
[Top] [All Lists]

X11 forwarding over SSH - yet another loop-hole ?

To: openssh-unix-dev@mindrot.org
Subject: X11 forwarding over SSH - yet another loop-hole ?
From: "Anand Srinivasan" <anandhsrini@gmail.com>
Date: Mon, 12 Feb 2007 12:44:10 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: openssh-unix-dev-list1@securepoint.com
Delivered-to: openssh-unix-dev-tmda@mindrot.org
Delivered-to: tmda@mindrot.org
List-archive: <http://lists.mindrot.org/pipermail/openssh-unix-dev>
List-help: <mailto:openssh-unix-dev-request@mindrot.org?subject=help>
List-id: Development of portable OpenSSH <openssh-unix-dev.mindrot.org>
List-post: <mailto:openssh-unix-dev@mindrot.org>
List-subscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=subscribe>
List-unsubscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=unsubscribe>
Old-delivered-to: openssh-unix-dev@mindrot.org
Reply-to: sriniva@muohio.edu
Sender: openssh-unix-dev-bounces+openssh-unix-dev-list1=securepoint.com@mindrot.org
Hi,

I'm not sure if this is the right place to post this but I recently noticed
something strange with X11 forwarding over SSH. I was running X11 on my Mac
(OS X Server 10.4.8) and had two separate SSH sessions open to two different
Linux boxes (I used the -Y flag). I started Firefox on the first box and
then subsequently started Firefox on the second box. But instead of starting
a new process on the second box a new process was spawned on the first box -
I ran top to verify this and there was no Firefox process running on the
second box, while there were two on the first ! I tried this a bunch of
times and still the same thing happened. I believe this is a security
loop-hole in the X11 forwarding over SSH. I've also tested this on a Windows
box using putty and Xming(or any other  X windows client) and still the same
result. I would like to know if this problem has been addressed before and
if so what is the solution to this. I have also tried connecting to the
Linux boxes using the SSH -X flag and still the same result. Does this mean
that -X is not really that secure when compared to -Y ?

If this not the right place to post this do let me know and I'll send this
question else where.

Thanks,

Anand
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

<Prev in Thread] Current Thread [Next in Thread>