![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.10407 |
Category: | Service detection |
Title: | X Server Detection |
Summary: | This plugin detects X Window servers.;; X11 is a client - server protocol. Basically, the server is in charge of the; screen, and the clients connect to it and send several requests like drawing; a window or a menu, and the server sends events back to the clients, such as; mouse clicks, key strokes, and so on...;; An improperly configured X server will accept connections from clients from; anywhere. This allows an attacker to make a client connect to the X server to; record the keystrokes of the user, which may contain sensitive information,; such as account passwords.; This can be prevented by using xauth, MIT cookies, or preventing; the X server from listening on TCP (a Unix sock is used for local; connections) |
Description: | Summary: This plugin detects X Window servers. X11 is a client - server protocol. Basically, the server is in charge of the screen, and the clients connect to it and send several requests like drawing a window or a menu, and the server sends events back to the clients, such as mouse clicks, key strokes, and so on... An improperly configured X server will accept connections from clients from anywhere. This allows an attacker to make a client connect to the X server to record the keystrokes of the user, which may contain sensitive information, such as account passwords. This can be prevented by using xauth, MIT cookies, or preventing the X server from listening on TCP (a Unix sock is used for local connections) CVSS Score: 0.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:N |
Copyright | Copyright (C) 2005 John Jackson |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |