Re: Dynamically Enable Xwindows?
- From: Igor Sobrado <igor@xxxxxxxxxxxxxx>
- Date: 27 Sep 2006 19:13:53 +0200
jKILLSPAM.schipper@xxxxxxxxxx wrote:
Again, I don't know much about graphic cards, let alone very old ones.
Running X on your computer will not make *that* much of a security
difference; certainly less than running, say, Firefox [1].
Firefox, as other browsers, speaks directly to a universe of mostly
broken code that is usually unable to pass the W3 Consortium validation
(in most cases it is too far from being acceptable). Not to mention
the large amount of add-ons in the form of javascripts, flash and so on,
added to make a useless URI look pretty. I am not surprised about
the vulnerabilities related with something that is as open on its
specifications as the languages and tools used in relation with the
world-wide web.
Stopping the X11 server is not necessary to exploit the graphic card;
injecting some additional code is sufficient, and this can be done
without stopping it.
Indeed, it is the base for injection attacks. I was just thinking
on the simple example provided in the paper, that requires /dev/xf86
to be available for opening.
There are some ways to limit root's powers, noticeably securelevels, but
they tend not to work that well.
I certainly do not trust a lot on securelevels. A secure level can
be easily changed (after a reboot at most) and usually restrict the
ability of managers to monitor the servers (e.g., reading S.M.A.R.T.
reports)
[1] Which is in many ways a very good program, but it does have much
more vulnerabilities than any other program I run on a typical desktop
machine.
It seems that both Coverity and the code auditing being done
are discovering a lot of bugs in firefox right now. We have a new
release each two weeks or so fixing some important bugs. I hope
that this code auditing process will make firefox as secure as
typical desktop applications soon.
Cheers,
Igor.
.
- Follow-Ups:
- Re: Dynamically Enable Xwindows?
- From: jKILLSPAM . schipper
- Re: Dynamically Enable Xwindows?
- References:
- Dynamically Enable Xwindows?
- From: dfeustel
- Re: Dynamically Enable Xwindows?
- From: Josh Grosse
- Re: Dynamically Enable Xwindows?
- From: dfeustel
- Re: Dynamically Enable Xwindows?
- From: Josh Grosse
- Re: Dynamically Enable Xwindows?
- From: Josh Grosse
- Re: Dynamically Enable Xwindows?
- From: dfeustel
- Re: Dynamically Enable Xwindows?
- From: Igor Sobrado
- Re: Dynamically Enable Xwindows?
- From: jKILLSPAM . schipper
- Re: Dynamically Enable Xwindows?
- From: Igor Sobrado
- Re: Dynamically Enable Xwindows?
- From: jKILLSPAM . schipper
- Re: Dynamically Enable Xwindows?
- From: Igor Sobrado
- Re: Dynamically Enable Xwindows?
- From: jKILLSPAM . schipper
- Dynamically Enable Xwindows?
- Prev by Date: Re: Can you compile and run this benchmark on your 3.9 system?
- Next by Date: Re: Dynamically Enable Xwindows?
- Previous by thread: Re: Dynamically Enable Xwindows?
- Next by thread: Re: Dynamically Enable Xwindows?
- Index(es):
Relevant Pages
|