I have been reading a great deal about how attackers would compromise a machine by directing one machines xterminal to his x server. But in the article , it doesn't make sense , because i tried it on my machine , and it only works if you are on the same uid number as the user running the X server in the first place.
But lets say we were on a LAN , and on one machine did
xterm -ut -display 10.0.1.1:0.0 , would it display it to 10.0.1.1 , even if it wasn't running as the same user on the terminal ?
someone want to explain this attack in greater detail , or what I might be doing wrong..
Thanks.




Reply With Quote