LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 04-08-2005, 05:39 AM   #1
umk
Member
 
Registered: Jan 2005
Distribution: debian (woody)
Posts: 36

Rep: Reputation: 15
"xhost +local:" in .xsession - a bad idea?


Hi,

following a good advise, I only log in as root when necessary, and I do so by using the command "su". Sometimes I would like to be able to open emacs with GUI as root, in order to make changes to certain files. However, this request is denied by the X server, since only user myname is allowed to access the X server when I'm logged in as myname. Nobody else uses this computer, so there are only two users: root and myname.

My question is this: is it a security liability to put "xhost +local:" into my .xsession file? This would allow me to access the X server as root too, rather than just as user myname. I've been reading about xhost being unsecure, but I still don't understand why.

Are there better ways of accessing the X server (e.g. opening emacs or xdvi) as root?

Thanks, umk
 
Old 04-08-2005, 12:32 PM   #2
makuyl
Senior Member
 
Registered: Dec 2004
Location: Helsinki
Distribution: Debian Sid
Posts: 1,107

Rep: Reputation: 54
I use xhost +local: as well as it only accepts local connections, but if you don't trust it try using sux instead of su to transfer the magic cookie, or if you're a KDE user use kdesu appname.
 
Old 04-08-2005, 01:35 PM   #3
umk
Member
 
Registered: Jan 2005
Distribution: debian (woody)
Posts: 36

Original Poster
Rep: Reputation: 15
Thanks, I'll try sux. umk
 
Old 04-08-2005, 09:40 PM   #4
m_yates
Senior Member
 
Registered: Aug 2003
Location: Upstate
Distribution: Debian, Mint, Mythbuntu
Posts: 1,249

Rep: Reputation: 101Reputation: 101
You can add the following line to /root/.bashrc
Code:
export XAUTHORITY=/home/name/.Xauthority
Where "name" is your username. I am quoting happytux on that one. It is what I did a long time ago to allow myself to open x programs as root, following happytux's suggestion.
 
Old 04-09-2005, 01:52 AM   #5
makuyl
Senior Member
 
Registered: Dec 2004
Location: Helsinki
Distribution: Debian Sid
Posts: 1,107

Rep: Reputation: 54
Since debian tightened security on X the export XAUTHORITY still needs a xhost +local: from the user running X.
In addition to having xhost +local: in users .profile my roots .profile has export DISPLAY=:0.0
 
Old 06-14-2005, 09:12 AM   #6
tunasashimi
Member
 
Registered: Jun 2005
Posts: 82

Rep: Reputation: 15
Hi!

I am doing xhost +
and I still cant connect from another machine

Knoppix is cool, i dont need to do anything on it...

But this sucks. Could anyone explain to me how it works, I cant seem to figure it out

The dox are lying & crap!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"bad interpreter : no such file or directory" when configure "flex" acer_peri Linux - Software 10 11-10-2010 01:19 AM
".xsession-errors" file: need some advice tigerflag Linux - General 5 08-12-2005 08:36 AM
xhost gives me "bad hostname" Rhatlinux Linux - General 8 12-16-2004 04:35 PM
difference between "Web server local URL" and "IPv4 address"? kpachopoulos Linux - General 2 09-17-2004 01:30 PM
xsession-error "baddrawable" among other things! angmaya Linux - Newbie 0 10-20-2003 01:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 05:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration