1825739 Members
2698 Online
109687 Solutions
New Discussion

Re: xhost and Exceed

 
Verónica Muñoz Segovia
Frequent Advisor

xhost and Exceed

Good afternoon,

Weeks ago we had an internal auditory and they put us as high risk the use of any xterminal software, I'm attaching you the document. Anybody knows these kind of security vulnerabilities?

Best Regards,

Veronica Munoz
Always is important to know the opinion of other people with or without experience
1 REPLY 1
Mike McKinlay
Honored Contributor

Re: xhost and Exceed

Part of the problem with xhost+ is that pretty much anyone can run an application at your desktop without your permission, including a spoofed version of an application you trust, like OpenView.

Whether this is a true "security hole" or simply something requiring human engineering, I'm not at all certain. What I'd like to know is whether the audit comes with recommendations to resolve the supposed "security holes". If it doesn't, then your company didn't get much for its money. A good consultant should tell you she can solve all the problems she's just told you about.
"Hope springs eternal."