LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-25-2019, 07:54 PM   #1
lucmove
Senior Member
 
Registered: Aug 2005
Location: Brazil
Distribution: Debian
Posts: 1,433

Rep: Reputation: 110Reputation: 110
Can a web page capture the user's screen globally?


Now that increasingly fewer pages can be referred to in that way because they are rather applications not pages, is it possible for a web page to capture the user's session screen, including the desktop area or other applications outside of the browser? My dog wears a tinfoil hat and wants to know. I feel bad for not being able to answer that myself.
 
Old 09-25-2019, 08:07 PM   #2
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,727

Rep: Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211
I’m gonna say no.
 
Old 09-25-2019, 08:21 PM   #3
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,326
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
I agree with scasey.

However, if the webpage is dodgy, it could conceivably contain some malware capable of snapping a screenshot if user were to activate it.
 
Old 09-25-2019, 08:50 PM   #4
lucmove
Senior Member
 
Registered: Aug 2005
Location: Brazil
Distribution: Debian
Posts: 1,433

Original Poster
Rep: Reputation: 110Reputation: 110
Globally? Out of the browser's window? Have you seen that somewhere?
 
Old 09-25-2019, 09:05 PM   #5
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,326
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
No, I haven't heard of such a thing, but I did say "conceivably."

Malware activated by clicking a dodgy link is not necessarily restricted to the browser window. The dodgy link could drop a screenshot application (or a key logger or whatever) onto the HDD, which in turn might do its thing and phone home with the result.

Mind you, I think it's a stretch to believe that a bad guy would be interested in a screenshot; the odds of catching, say, a financial spreadsheet open to the screen would be far too small. Bad guy would much more likely be interested in grabbing a copy of said spreadsheet from the home directory.
 
Old 09-25-2019, 09:46 PM   #6
lucmove
Senior Member
 
Registered: Aug 2005
Location: Brazil
Distribution: Debian
Posts: 1,433

Original Poster
Rep: Reputation: 110Reputation: 110
I don't believe a dodgy link could drop an application without the user noticing it. The browser would prompt for a destination directory for the download. And I don't believe the application would run by itself like some kind of robot.

On the subject of interest, I wasn't thinking about an unknown looking for something like a financial spreadsheet. I thought about someone trying to spy on someone else's life, say, what we do and whom we communicate with throughout the day.
 
Old 09-25-2019, 09:52 PM   #7
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,326
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
Quote:
I don't believe a dodgy link could drop an application without the user noticing it.
Er, no.

https://www.google.com/search?client...opping+malware

Bad guys engineer bad things. That's how they become bad guys.

Last edited by frankbell; 09-25-2019 at 09:56 PM.
 
Old 09-26-2019, 02:02 AM   #8
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
I'm gonna say: they don't need to. They can get to much more, and more interesting data on your machine directly, without having to resort to taking screenshots. It's also less data (plain text vs. image files) to push through the network.
Of course I'm just speculating; I allow my browser to use javascript only very sparingly and never by default, and feel reasonably safe. Because without javascript, 99.9% of the attack surface is gone. Really.
 
Old 09-26-2019, 02:21 AM   #9
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,150

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Question

Quote:
Originally Posted by lucmove View Post
Now that increasingly fewer pages can be referred to in that way because they are rather applications not pages, is it possible for a web page to capture the user's session screen, including the desktop area or other applications outside of the browser? My dog wears a tinfoil hat and wants to know. I feel bad for not being able to answer that myself.
Well as other said, it's possible. Bad guys do bad things. I have seen one admin doing this, doing screen shot of current login user without the user noticing it and sending the capture to a network share. But it was W1nx..if it's possible in another OS why would it not be possible for Linux.
 
Old 09-26-2019, 02:27 AM   #10
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by JJJCR View Post
I have seen one admin doing this, doing screen shot of current login user without the user noticing it and sending the capture to a network share. But it was W1nx..
And was that through a web page?
Sounds more like it happened through remote access on a company's network?
 
Old 10-01-2019, 01:27 AM   #11
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,150

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Quote:
Originally Posted by ondoho View Post
And was that through a web page?
Sounds more like it happened through remote access on a company's network?
yes it was through a company's network, web page hmm..yes it's possible
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
executing linux commands from web page and outputing it back to the web page ashes_sheldon Programming 9 02-28-2015 12:07 AM
[SOLVED] Web page input executes on command line and output back to web page keif Programming 7 02-26-2014 10:25 AM
Running Xvidcap (for screen capture ) + audacity (for audio capture) simultaneously vikram_cvk Linux - Software 2 05-20-2011 03:26 AM
How do I set KDE desktop user restrictions globally? Simmo512 Linux - Software 2 12-15-2008 01:34 PM
RH & HP4050N PCL - page, pause, page, pause, page andguent Linux - Hardware 0 11-10-2003 08:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration