Announcement

Collapse
No announcement yet.

X.Org Server & XWayland Hit By Four More Security Issues

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #91
    Originally posted by rrveex View Post
    oiaohm, not only are you a asshole for calling me personally an idiot... again.

    You are also a moron. The article you linked to says
    This is what happens when a person does not read the complete thing.

    ESET researchers have discovered a piece of banking malware using a new technique to bypass dedicated browser protection measures that was used to empty accounts in Polish banks.

    Look at figure 1 and notice the "compromised gateway " bit.

    This is a multi vector malware.

    The banker is distributed through malicious email spam campaigns
    Yes that how it got into your network. The machine that you are banking and you lose you money from may not be the machine that received the email.

    Remember I said the person hit by this themselves may have done nothing wrong in there system configuration. Attacks against routers do happen.

    Originally posted by rrveex View Post
    So go fuck yourself and your vectors since 2018.
    No you are being ignorance is bliss idiot. You have said I am a moron the reality here is I am not. This backswap malware from 2018 was very different. Get into your network by email then get into your router and then use the router to get into your bank. This successfully attacks people who have their banking and email on separate computers by swapping the a few third party sites out that different banking web sites use.

    Comment


    • #92
      Originally posted by oiaohm View Post
      You have a problem with this.
      ​Does this look like I have a problem with it?

      Originally posted by mSparks View Post

      Nah man, this only affects wayland compositors not X11 server stuff people actually use, like the HTML5 based compositors for running HPC on everything from macos to TVs to android phones


      Not meaning to imply anyone actually uses wayland, because obviously there is only so much you can do watching an empty resource monitor and trying and failing to get a web browser to work gets boring quickly.

      Comment


      • #93
        Originally posted by mSparks View Post
        ​Does this look like I have a problem with it?​
        So here is mSparks who has no valid argument who just attempted a works for me argument.

        You have just not run any software yet that has a problem of mixing its encodings. There are different legacy SDL games that I know of that do in fact mix the LSB/MSB encodings. Good part is when they are told by force to stick to one encoding they do.

        Redhat developer of Xwayland in Jan of 2023 did not turn the default to byte swap off only for remote applications. Byte swap off stops badly coded local applications from using poorly coded and designed sections of the x.org X11 server.

        mSparks since this feature was disabled in XWayland for local and remote applications means showing X11 working by web browser means nothing. Are you using a x.org X11 server that is not Xwayland behind that if you are you have problem that you should be going in and altering a configuration file and you would not be needing to alter this configuration file if the X.org maintainer from Oracle was doing his job because the default would be off. Yes that Oracle mantainer will be getting to use this 4 CVE report as item to claim to his boss that he is doing is job but when people like me know what we are reading know these 4 CVE reports contain proof he is not doing his job.

        mSparks think about it you find one bit of solid evidence that someone is not doing their job what is the odds that something else they should be doing is not done. Those wanting to keep on using Xvfb and X11 bare metal should be worried about what has been show if they are not sticking there head in sand.

        This is the very problem I was worried would happen once Redhat stop maintenance Xvfb and X11 bare metal. Yes the problem that patches that should have been merged and got to end users are not getting to end users. Like it or not Redhat management of open source projects has been very high standard when it comes to these things.

        Comment


        • #94
          Originally posted by oiaohm View Post

          So here is mSparks who has no valid argument who just attempted a works for me argument.


          The argument was wayland does not work for me, it does not work for anyone: That screenshot is everything wayland is designed to make impossible, while simultaneously not living up to its claims of making things more secure.

          But I dont have a problem with that, any more than I have a problem with windows only supporting one CPU core - these things are someone elses problems.

          Comment


          • #95
            What is the impossible part?

            Comment


            • #96
              Originally posted by access View Post
              What is the impossible part?
              running (unmodified) glxgears (or anything with the same requirements) at 2000fps on an android phone inside vivaldi browser (or anything with similar capabilities).
              Last edited by mSparks; 07 April 2024, 03:52 AM.

              Comment


              • #97
                Originally posted by mSparks View Post
                running (unmodified) glxgears (or anything with the same requirements) at 2000fps on an android phone inside vivaldi browser (or anything with similar capabilities).
                Not in fact impossible.

                Phoronix, Linux Hardware Reviews, Linux hardware benchmarks, Linux server benchmarks, Linux benchmarking, Desktop Linux, Linux performance, Open Source graphics, Linux How To, Ubuntu benchmarks, Ubuntu hardware, Phoronix Test Suite


                There are many ways of doing what you just wrote with wayland. Yes Weston you have RDP backend that you can use in combination with FreeRDP-WebConnect todo exactly the same thing.

                You have gnome and KDE RDP backends.

                Then you have the wayvnc + novnc for the wlroots based.

                RDP solutions perform very well. RDP was design by Microsoft from the ground up to deal with crossing WAN this includes being able to reconnect to sessions if their has been disruptions. X11 was design for LAN.

                mSparks the reality is your demo does not have X11 crossing the network. So what real difference does it make if I am instead running weston with RDP backend enabled and local opengl/vulkan enabled with FreeRDP WebConnect going over network.

                I do notice that you example did not have Vulkan application. The gnome/KDE/weston RDP solutions support opengl and vulkan applications as well as Xwayland applications.

                X11 protocol is not designed for high latency network connections. Waypipe runs into the same basic problems. RDP is designed for the high latency network problem.

                Yes could have been using FreeRDP-WebConnect with xrdp for X11 as well.

                Its about time you give up this bogus claim mSparks.

                Something to consider here mSparks the reference implementation for Wayland supports vnc and rdp. If wayland compositors are in fact being compatible with the reference implementation they should include these features. What a wayland compositor should implement does not stop at what in the wayland protocol.
                Last edited by oiaohm; 07 April 2024, 04:31 AM.

                Comment


                • #98
                  Originally posted by oiaohm View Post


                  You have gnome and KDE RDP backends.
                  ROFL.
                  how do you run RDP on a device with no GPU or gnome or Desktop of any kind installed? (99.9999999% of (non android) linux devices)
                  Originally posted by oiaohm View Post
                  I do notice that you example did not have Vulkan application.
                  Despite
                  A new low level api has recently been proposed by Apple , It is now time to reconsider webvulkan and discuss if developing it would be the best or if there is no chance of making a vulkan version (...


                  That is still more likely to eventually end up being something people use than wayland.
                  Last edited by mSparks; 07 April 2024, 05:02 AM.

                  Comment


                  • #99
                    Originally posted by mSparks View Post
                    how do you run RDP on a device with no GPU or gnome or Desktop of any kind installed? (99.9999999% of (non android) linux devices)
                    This is normal lack of knowledge. RDP design does not mandate a GPU.

                    Yes it written in the weston rdp man page no GPU required. No connected monitor or keyboard required. Weston RDP run along side weston headless is really nice for disrupted network.

                    Phoronix, Linux Hardware Reviews, Linux hardware benchmarks, Linux server benchmarks, Linux benchmarking, Desktop Linux, Linux performance, Open Source graphics, Linux How To, Ubuntu benchmarks, Ubuntu hardware, Phoronix Test Suite


                    ASpeed to no graphical out is found in OpenBMC solutions all the time while providing RDP graphical access. Weston headless mode does not need any form of graphical output. Yes weston you can run headless and rdp backend in multi config.



                    The multi backend support of weston is for headless embedded devices. Think about it X11 applications with xpra are not designed to work with a disrupted network. Lot of cases were you are using embedded devices the networking is not great screwed up packets happen more than one would really like like in the 1000s per second of damaged packets.

                    mSparks you just pointed to area where the reference wayland compositor weston has mostly taken over due to this solution having improved stability. . Using RDP also has the advantage that there are more client devices(desktop comptuers/phones...) that support RDP out the box than what support X11 out the box.

                    Comment


                    • Originally posted by oiaohm View Post

                      This is normal lack of knowledge. RDP design does not mandate a GPU.
                      And you think that is going to get 2000fps?

                      Heck, the last wayland guy was happy to manage 30fps from glxgears in wayland on his actual desktop.

                      Comment

                      Working...
                      X