Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.10407
Categoría:Service detection
Título:X Server Detection
Resumen:This plugin detects X Window servers.;; X11 is a client - server protocol. Basically, the server is in charge of the; screen, and the clients connect to it and send several requests like drawing; a window or a menu, and the server sends events back to the clients, such as; mouse clicks, key strokes, and so on...;; An improperly configured X server will accept connections from clients from; anywhere. This allows an attacker to make a client connect to the X server to; record the keystrokes of the user, which may contain sensitive information,; such as account passwords.; This can be prevented by using xauth, MIT cookies, or preventing; the X server from listening on TCP (a Unix sock is used for local; connections)
Descripción:Summary:
This plugin detects X Window servers.

X11 is a client - server protocol. Basically, the server is in charge of the
screen, and the clients connect to it and send several requests like drawing
a window or a menu, and the server sends events back to the clients, such as
mouse clicks, key strokes, and so on...

An improperly configured X server will accept connections from clients from
anywhere. This allows an attacker to make a client connect to the X server to
record the keystrokes of the user, which may contain sensitive information,
such as account passwords.
This can be prevented by using xauth, MIT cookies, or preventing
the X server from listening on TCP (a Unix sock is used for local
connections)

CVSS Score:
0.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:N

CopyrightCopyright (C) 2005 John Jackson

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.