OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Tzafrir Cohen (tzafrirtechnion.ac.il)
Date: Tue Jan 29 2002 - 12:24:30 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Tue, 29 Jan 2002, Vincent Danen wrote:

    > On Tue Jan 29, 2002 at 04:24:11PM +0100, James Ossi wrote:
    >
    > > Not really a brand new thing, but with all the MDK releases
    > > I tried (and I remember with Red Hat also..),
    > > the XFree port 6000 is open and listening.
    > > There are indirect security risks with this policy
    > > (DoS, X server freeze), so wouldn't be better to keep
    > > that port closed by default?
    > > Joe User -and Mike PowerUser as well ;-) - don't need
    > > an X server listening.
    > > A "-nolisten tcp" parsed to DEFAULTCLIENTARGS and
    > > DEFAULTSERVERARGS within startx would be enough.
    >
    > I agree.I've forwarded the message and hopefully we can get this
    > fixed by the XFree86 maintainer.

    Just one thing:

    Make sure that Mike PowerUser can easily enable this back (and that this
    change will not get discarded with the next XFree upgrade), because
    in some places you just can't use ssh for your X connections.

    -- 
    Tzafrir Cohen                        /"\
    mailto:tzafrirtechnion.ac.il        \ /  ASCII Ribbon Campaign
    Taub 229, 972-4-829-3942,             X   Against  HTML  Mail
    http://www.technion.ac.il/~tzafrir   / \
    

    For help, email discuss-helpmandrakesecure.net; to unsubscribe send a message to discuss-unsubscribemandrakesecure.net. To visit MandrakeSecure, go to http://www.mandrakesecure.net/.