[3650] in WWW Security List Archive
-remote option
daemon@ATHENA.MIT.EDU (Andrea Di Fabio)
Sun Dec 1 18:32:59 1996
Date: Sun, 1 Dec 1996 14:45:26 -0500 (EST)
From: Andrea Di Fabio <fabio@cs.odu.edu>
To: www-security@ns2.rutgers.edu
In-Reply-To: <Pine.OSF.3.93.961119175233.6079A-100000@novice.uwaterloo.ca>
Errors-To: owner-www-security@ns2.rutgers.edu
I have recently read about the remote attack which is possible
thru the netscape -remote option, when your X server is running in
xhost + mode.
Is there anyone out there who has a list of all commands accepted by
the -remote option ?
Also, any idead on how to disable netscape from accepting remote
commands when your Xserver is insecure ?
Thanks,
fabio.