Nessus Plugin #15897

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Open X Server

Family:
Misc.
Category:
infos
Copyright:
This script is Copyright (C) 2004 Michel Arboi
Summary:
An open X Window System Server is present
Version:
$Revision: 1.1 $
Cve_id:
CVE-1999-0526
Bugtraq_id:
-
Xrefs:
-
Description:

An improperly configured X server will accept connections from clients from
anywhere. This allows an attacker to make a client connect to the X server to
record the keystrokes of the user, which may contain sensitive information,
such as account passwords.

To solve this problem, use xauth or MIT cookies.

Solution : Use xhost, MIT cookies, and filter incoming TCP connections to this
port.

Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.