OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: X security
From: Paul B. Henson (hensonACM.ORG)
Date: Wed Jul 12 2000 - 20:47:49 CDT


at some point in the recent past, Solaris started storing X stuff in the
subdirectory /tmp/.X11-unix rather than just in /tmp. I understand this was
done for security reasons, although I don't recall off the top of my head
the various vulnerabilities involved.

The problem I am having is with users that want to run their own X servers,
such as Xnest or XVNC. these servers are unable to create the files they
need and refuse to run. The FAQ for VNC recommends to simply make
/tmp/.X11-unix world writable, but that would seem to defeat the purpose of
the subdirectory.

Does anyone have a viable solution for maintaining the security provided by
having X use a non-world writable subdirectory, yet still allow users to
run applications such as Xnest/XVNC?

Thanks...

--
Paul B. Henson  |  (909) 869-3781  |  http://www.csupomona.edu/~henson/
Operating Systems and Network Analyst  |  hensonintranet.csupomona.edu
California State Polytechnic University  |  Pomona CA 91768