Re: Do consider blocking port 6000 on the next installer (Was: Re: setenv in X11)
Re: Do consider blocking port 6000 on the next installer (Was: Re: setenv in X11)
- Subject: Re: Do consider blocking port 6000 on the next installer (Was: Re: setenv in X11)
- From: email@hidden (Randal L. Schwartz)
- Date: 01 Feb 2003 14:15:30 -0800
>>>>> "Rui" == Rui Carmo <email@hidden> writes:
Rui> By the way, is there a way to force it to bind to localhost
Rui> (127.0.0.1)? I've only used X11.app on firewalled systems, but I guess
Rui> people running it on the open Internet are asking for trouble. xhost +
Rui> or no xhost, running port 6000 on the open Internet is asking for a
Rui> rehash of the Sun vulnerabilities of yore... :)
According to "man Xserver", you should be able to pass "-nolisten" to
get it to bind to only the Unix-domain socket. That's pretty secure.
--
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<email@hidden> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!
_______________________________________________
x11-users mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/x11-users
X11 for Mac OS X FAQ: http://developer.apple.com/qa/qa2001/qa1232.html
Report issues, request features, feedback: http://developer.apple.com/bugreporter
Do not post admin requests to the list. They will be ignored.