Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <87lhdh33wl.fsf@mid.deneb.enyo.de>
Date: Tue, 11 Aug 2015 23:34:50 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: oss-security@...ts.openwall.com
Subject: Re: Terminal escape sequences - the new XSS for admins?

* Steve Grubb:

> In my survey recently, Some emulators could set the window title;
> none of them supported reading the window title back to the command
> prompt. If you find one that does, it is one that is at risk.

Upstream xterm has other problematic window ops enabled by default.
Debian should disable all of them since xterm version 251-1, but this
is a downstream-specific change.  (Upstream documentation is also a
bit misleading, AFAICS.)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.