OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Vincent Danen (vdanenmandrakesoft.com)
Date: Tue Jan 29 2002 - 12:16:09 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Tue Jan 29, 2002 at 04:24:11PM +0100, James Ossi wrote:

    > Not really a brand new thing, but with all the MDK releases
    > I tried (and I remember with Red Hat also..),
    > the XFree port 6000 is open and listening.
    > There are indirect security risks with this policy
    > (DoS, X server freeze), so wouldn't be better to keep
    > that port closed by default?
    > Joe User -and Mike PowerUser as well ;-) - don't need
    > an X server listening.
    > A "-nolisten tcp" parsed to DEFAULTCLIENTARGS and
    > DEFAULTSERVERARGS within startx would be enough.

    I agree. I've forwarded the message and hopefully we can get this
    fixed by the XFree86 maintainer.

    -- 
    MandrakeSoft Security, OpenPGP key available on www.keyserver.net
    1024D/FE6F2AFD   88D8 0D23 8D4B 3407 5BD7  66F9 2043 D0E5 FE6F 2AFD
    

    Current Linux kernel 2.4.8-34.1mdk uptime: 6 days 16 hours 13 minutes.

    -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org

    iD8DBQE8VubpIEPQ5f5vKv0RAqCKAJ0bPZ6Kt8rYpYQNBJA6rm0DgXdcRQCgvPxB uUO1Ae3Q2SKFoTudYfc96NA= =fInF -----END PGP SIGNATURE-----