{"id":6543,"date":"2009-10-09T10:02:29","date_gmt":"2009-10-09T14:02:29","guid":{"rendered":"https:\/\/www.bu.edu\/tech\/?page_id=6543"},"modified":"2015-05-07T07:24:48","modified_gmt":"2015-05-07T11:24:48","slug":"xprobe","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/services\/security\/server\/vulnerability-management\/xprobe\/","title":{"rendered":"X-Windows Security Probe"},"content":{"rendered":"<h3>What is the X-Windows Security Probe?<\/h3>\n<p>The X Windows Security Probe (xprobe) is a vulnerability scanner that looks for a specific vulnerability in the configuration of an X-Windows Server.<\/p>\n<p>Computers connected to\u00a0 Boston University&#8217;s campus network and the Internet are frequently probed security vulnerabilities. Information Services &amp; Technology (IS&amp;T) is constantly evaluating the threats and developing methods to provide improved protection from attacks while minimizing impact on legitimate use. As part of our continuing efforts, we conduct regular probes to test for the existence of well-known vulnerabilities, with the goal of notifying system owners and administrators before these vulnerabilities can be exploited.<\/p>\n<h3>What is X-Windows?<\/h3>\n<p>X-Windows is the basis for graphical user interfaces on the UNIX and Linux platforms.\u00a0 When you use a Unix or Linux system such as SCC or ENGC to run a program such as Xterm(inal) or MatLab that wishes to display a graphical user interface on your computer, the graphical information is sent to an X-Windows server on your local computer so it may be properly displayed.<\/p>\n<p>Version 11 on the X Windows System was released in 1987 and is the only version in common use today.\u00a0 As a result, the shorthand name &#8220;X11&#8221; has become synonymous with the &#8220;X-Windows&#8221; and even &#8220;X&#8221;.\u00a0 This document may refer to &#8220;X-Windows&#8221; and &#8220;X11&#8221; interchangably.<\/p>\n<p>X11 used to be a lot more common than it is now, but there are still many uses for it.\u00a0 If you&#8217;ve never heard of it you probably aren&#8217;t using it, but if the image shown below was displayed on your computer then you absolutely are using and have a vulnerability that needs to corrected.<\/p>\n<h3>What does the X Windows Security Probe test?<\/h3>\n<p>The X Windows Security Probe (xprobe) tests to see if the X11 server is running on any system connected to our network, and if that X11 server will allow a connection to be made to the display.\u00a0 In short, we are testing to see if our probe can display information on your screen.<\/p>\n<p>If we can display information to your computer&#8217;s screen then you have failed the test.<\/p>\n<h3>How Do I Know if I Failed the Test?<\/h3>\n<p>The most obvious indication that your computer has failed the test is having the following dialogue box appear on your computer screen.<\/p>\n<p><strong>This dialogue box will appear only if the display is not properly secured. If you&#8217;ve received this dialogue box on your screen, you need to take immediate action to prevent your computer and account from compromise.<\/strong><\/p>\n<dl id=\"attachment_20519\" style=\"width: 594px;\">\n<dt><img loading=\"lazy\" src=\"\/tech\/files\/2009\/12\/xprobe.jpg\" alt=\"Sample x-probe warning message\" height=\"358\" width=\"584\" \/><\/dt>\n<\/dl>\n<p>You may also receive an email message from the Incident\u00a0 Response Team indicating that you failed the test and need to take corrective action.<\/p>\n<h3><a name=\"correct\"><\/a>Corrective Action if You Fail the Test<\/h3>\n<p>We have developed a probe to test X Windows access control on all X servers on the BU Campus. When run, this probe attempts to access each<br \/>\nIf you have received the above message on your X-Windows display you will need to take a few steps to correct the problem, in the following order:<\/p>\n<ol>\n<li><a href=\".\/secure\">Secure Your X-Windows Server<\/a> so that it cannot be abused in the future.<\/li>\n<li>Completely shutdown the X-Server.\n<ol>\n<li>When you&#8217;re done using it, single right-click the icon in the system tray and pick &#8220;Exit&#8221; to shut down the X-server.<\/li>\n<li>On Unix and Linux, or if you&#8217;re uncertain at all about your success in restarting the X-server you should reboot your computer so that anyone who is already eavesdropping on your display loses their connection to your display.<\/li>\n<\/ol>\n<\/li>\n<li>Change any passwords you&#8217;ve entered via your computer since you launched X-Windows, as they may have been compromised.\u00a0 In particular, <a href=\"https:\/\/weblogin.bu.edu\/accounts\/changepw\">change your kerberos password<\/a> if there is any chance you&#8217;ve exposed it to protect your personal data.<\/li>\n<li>Learn <a href=\".\/xauth\">How X11 Access Control Works<\/a> and engage in safe practices in the future.<\/li>\n<\/ol>\n<h3>Next Steps<\/h3>\n<ul>\n<li>Learn <a href=\".\/failure-matters\">Why Failing the Test Matters<\/a>.<\/li>\n<li><a href=\"#correct\">Take Corrective Action<\/a> if you&#8217;ve failed the test.<\/li>\n<li>Understand <a href=\".\/xauth\">How X11 Access Control Works<\/a><\/li>\n<li>Learn how to <a href=\".\/secure\">Secure Your X-Windows Server<\/a><\/li>\n<li>Learn how to<a href=\".\/firewall\"> Limit Connections to your X-server using the Microsoft Firewall<\/a>.<\/li>\n<li>Read a technical <a href=\"http:\/\/www.linfo.org\/x.html\">Introduction to X<\/a> to learn more.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>What is the X-Windows Security Probe? The X Windows Security Probe (xprobe) is a vulnerability scanner that looks for a specific vulnerability in the configuration of an X-Windows Server. Computers connected to\u00a0 Boston University&#8217;s campus network and the Internet are frequently probed security vulnerabilities. Information Services &amp; Technology (IS&amp;T) is constantly evaluating the threats and&#8230;<\/p>\n","protected":false},"author":2127,"featured_media":0,"parent":87880,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6543"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/2127"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=6543"}],"version-history":[{"count":12,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6543\/revisions"}],"predecessor-version":[{"id":85058,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/6543\/revisions\/85058"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/87880"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=6543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}