Ubuntu :: Gnome Screensaver Security Vulnerability?

Aug 26, 2010

I noticed that when typing in your password after locking the screen or a screensaver, the program focussed behind it is able to catch the input...

This sounds like a huge security risk to me, is there anyone who can test this? (Only noticed with game in wine, perhaps you need low level xorg access)

View 1 Replies


ADVERTISEMENT

OpenSUSE :: Fuse, Gnome-screensaver, Gnutils Security Updates Fail

Feb 12, 2010

I keep getting messages that I need to update fuse gnome-screensaver and gnutils security updates. However, everytime I try to update either by YAST Online Update or the toolbar icon, it fails to update. The message is that can't remove fuse, gnutls, etc.

View 4 Replies View Related

Ubuntu Security :: Thunderbird Security Vulnerability Updates

Apr 2, 2010

So yesterday I receive a copy of the SANS @RISK security vulnerability newsletter, and, lo and behold, Mozilla's Firefox and Thunderbird are on it yet again. (Yeah, I know, shocking, isn't it?)So I quickly check what versions I have installed. Yup: Vulnerable.I check whether updates are available.These are pretty serious "remote code execution" vulnerabilities and the status is "vendor confirmed, updates available." So why isn't my 9.10 desktop's update manager telling me updates are available?

View 9 Replies View Related

Ubuntu :: Install WINE Screensaver In Gnome-screensaver Possible?

May 19, 2010

There's an OSS screensaver on windows that I love called PixelCity (links:blog post, github). it's pretty cool. and it runs fine on my Ubuntu (Karmic 9.10) with wine.Is there a way I can tell the gnome-screensaver about it so I can use it as one of my screensavers? I'm still fairly new to Gnome and the whole "screensavers as themes" thing is still confusing me.I've found my themesdir and tried to create a .desktop file for it, but obviously I've gotten something wrong as it just doesn't show when I open the screensaver prefs dialog, no error, no message, it's just not there.

Installing the xscreensaver packages added the extra screensavers I was missing, and I'm a pixelcity away from perfection..Of course the perfect solution would be if someone ported the screensaver natively to linux, which shouldn't be too hard as the source is open, it already runs on openGL and tries to confine most windows stuff to a single file. But I don't know C++ or 3D code or win/linux internals so I wouldn't know where to start..

View 6 Replies View Related

Security :: BackTrack For Web Vulnerability Assessment?

Jan 13, 2011

I i've virtual machine that is running BackTrack4r2. I need to use the built-in tool Metaspolit in bt for assessing the security and vulnerability in websites The prob is that i dont have any about the Metaspolit tool.

View 10 Replies View Related

Ubuntu Security :: Vulnerability In Karmic And Intrepid Alpha2?

Feb 24, 2010

I decided to report what happened me lately so that someone more clever could find the hole in the latest ubuntu. So: I have a machine connected 24/7 on high speed network. i had karmic on it. i ran openssh and apache2 (without any mod, plain apache2) on it. In addition i ran firefox, ktorrent, and amule on it. Nothing else. The system didnt have any rule in iptables.


Recently chkrootkit signaled a SuckIT rootkit in the system. I was scared, i googled for it and i saw that on ubuntu this actually happened and it was a false positive. Ok, i kept going. Yesterday i nmapped myself and i found an open port around 64000 that i couldnt see with netstat -atpnl so i concluded i was actually infected and erased the drive and tried to install lucid alpha2 so, one day of lucid,

- with a firewall this time that let open only the port 22 and 80 from internet
- with only openssh as service (no apache2)
- ran firefox3.6 , ktorrent and amule , nothing else

chkrootkit didnt find anything
debsums reported
debsums: changed file /sbin/initctl (from upstart package)

i did an apt-get install --reinstall upstart and that file didnt warn anymore. So i concluded there must be some kind of vulnerability either in

a) firefox
b) ktorrent
c) amule

View 6 Replies View Related

Ubuntu Security :: MITM Attack - TLS Renegotiation Vulnerability

Sep 28, 2010

Using Opera 10.61 and 10.62, I find that any secure website I access, such as a bank, the lock icon in the address bar is replaced by a question mark. Clicking on it brings up a window, stating that the connection is not secure, that the server does not support TLS Renegotiation. Doing some internet searches for "opera tls renegotiation" brought me to a page at the Opera website, where they discuss this issue. The issue is generic, not limited to Opera, affecting the TLS protocol, and it potentially enables a man-in-the-middle to renegotiate a "secure" connection between a server and client, issuing own commands to the server. Opera has addressed the problem on the client end, but now servers need to be upgraded too. None of the HTTPS sites I have tried have upgraded their servers, if the information provided by the Opera browser is correct.

My questions: how feasible is such a MITM attack, what level of resources would such an attack require? What, if anything, would the attacker need to know about the client and/or server to mount the attack? Would I be better off using Firefox, or is Firefox simply oblivious of the problem and not issuing warnings for that reason?

View 4 Replies View Related

Ubuntu Security :: Free Outside Vulnerability Scan That Works With Server

Feb 11, 2010

Is there a free online vulnerability scanner where either I can give them the IP address to scan or can be initiated from the console command, tool, or text based browser. I use GRC's Shields Up when I have a GUI, but I want a scan ran on my website that runs Ubuntu 8.04 server on a hosted VPS.

View 5 Replies View Related

Ubuntu Security :: Locked-Screen Login Window Vulnerability?

May 12, 2010

I've got an HP Netbook with Jaunty installed, and I've got an older Dell laptop running Debian.A friend of mine, on several occasions, has told me that when I left my computers unattended he could do some kind of series of key-strokes, and then a window comes up and he says that he can change the password for my account.I've asked him to show me how he does it, but he never will because he doesn't want me to be able to thwart himIs he lying, or is it for real? if it's for real, how do I go about changing it so that it can't happen anymore?

View 5 Replies View Related

Ubuntu Security :: Tar Vulnerability? Leading ./ (dot Slash) Makes The --directory Option Fail?

Jun 8, 2010

I ran across this problem when I used checkinstall and then tried to extract the contents of data.tar.gz (which you can find inside any .deb).tar has an option to extract the contents of a file in a given directory.From tar's manpage:

Code:
-C, --directory DIR
change to directory DIR

[code]....

View 2 Replies View Related

Security :: Vulnerability - 1.0.x Branch Of OpenSSL That Potentially Allows SSL Servers To Compromise Clients

Aug 10, 2010

Quote: Security expert Georgi Guninski has pointed out a security issue in the 1.0 branch of OpenSSL that potentially allows SSL servers to compromise clients. Apparently the hole can be exploited simply by sending a specially crafted certificate to the client, causing deallocated memory to be accessed in the ssl3_get_key_exchange function (in ssls3_clnt.c). While this usually only causes an application to crash, it can potentially also be exploited to execute injected code.

View 1 Replies View Related

Ubuntu :: Gnome-screensaver Won't Work

Oct 17, 2010

I wanted to get a screensaver as my background so I installed xscreensaver didn't work out to the way I wanted to so I removed it apt-get remove xscreensaver then it asked for some other packages to be removed so I did apt-get autoremove xscreensaver was still there working instead of gnome-screensaver so I did a command search to find folders of xscreensaver and remove them whereis xscreensaver and it did remove them, but gnome-screensaver still doesn't start up.

I've tried this command gnome-Message: screensaver-command --activate but I get this error: Message: Screensaver is not running!

I've tried googling for a way to start gnome-screensaver in terminal but no joy, anyone know how to get this to start.

View 2 Replies View Related

Ubuntu :: Removing Gnome Screensaver

Mar 12, 2011

The Gnome Screensaver preferences window is freezing my desktop. I went into synaptic and tried to remove it (to use xscreensaver instead). But synaptic, in removing gnome-screensaver package, wanted to ADD a bunch of packages, lots of KDE stuff (which I don't want). Is there any way around this? If not, is there a way to reset the gnome-screensaver config file (whatever it is) so that it doesn't freeze on startup? This problem arose after I selected a particular screensaver in the gui window.

View 3 Replies View Related

Ubuntu :: Replace Gnome-screensaver With Xscreensaver?

May 12, 2010

Although xscreensaver is much better and liked by many users, the Ubuntu devs replaced it with gnome-screensaver simply cause -

1) It's integrates better with the gnome-desktop.
2) It follows release cycles of Gnome.

Since the devs and admins won't listen, we users have to clean their **** up and this is the howto - In Ubuntu, the gnome-screensaver is running; but xscreensaver is better, so we need to replace it. The gnome-screensaver runs as a daemon...removing this gnome-screensaver package will remove this executable also -

[Code]...

View 7 Replies View Related

Ubuntu :: Gnome Screensaver Does Not Accept Password

Dec 20, 2010

I have an Ubuntu 10.10 box authenticating Users against an LDAP server. User authentication works fine - ssh, console or Gnome.

The only place it has an issue is when the gnome-screensaver is activated and locks the computer. When I try to enter the correct password at this point I get these error in the logs;

Dec 20 14:42:23 box-ubuntu unix_chkpwd[12240]: password check failed for user (myname)
Dec 20 14:42:23 box-ubuntu gnome-screensaver-dialog: pam_unix(gnome-screensaver:auth): authentication failure; logname= uid=10038 euid=10038 tty=:0.0 r
user= rhost= user=myname
Dec 20 14:42:23 box-ubuntu gnome-screensaver-dialog: pam_ldap(gnome-screensaver:auth): Authentication failure; user=myname

[Code]....

View 1 Replies View Related

Ubuntu :: Gnome Screensaver Locks Up Display

Dec 25, 2010

Specifications:
Dell PoweEdge 1600SC
ATI Radeon HD 2400 Pro 256MB PCI graphics adaptor
Ubuntu 9.10 "Karmic Koala"
Linux 2.6.31-22-generic #69-Ubuntu SMP Wed Nov 24 08:51:08 UTC 2010 i686
ATI fglrx drivers
Set up for dual-head display using two Princeton 19" monitors
Using the Gnome desktop and screensaver

At some point, I suspect since the last kernel upgrade, I've begun experiencing a problem when the screen locks: I tap a key on the keyboard and the monitors wake up, but I get no "unlock" dialog. I can usually Ctrl-Alt-F1, login and gracefully reboot the system, but sometimes I have to hit hard reset. For now I've disabled the screensaver in "System -> Preferences -> screensaver" (I assume that'll stop the problem), but that's not an optimal solution.

View 9 Replies View Related

Ubuntu :: How To Re-Enable Gnome Screensaver As Default

Feb 6, 2011

I installed xscreensaver thinking it would be cool, and now I hate it. so I removed packages via synaptic and it hasn't done anything. I want to know how to re-enable gnome screensaver as the default.

View 2 Replies View Related

Ubuntu Security :: Screensaver Seems To Respond To Old Password?

Oct 15, 2010

I changed my password in the last few days using passwd. I still haven't gotten used to typing the new one, and entered the old one by accident to unlock the screen saver. I've been able to do this a bunch of times, and I'm quite sure it will still take the old password.This seems to be a serious security issue, and I'm not sure where I should raise this. I hope this is the right forum.I am using Ubuntu 10.04.$ uname -aLinux thunder 2.6.32-25-generic #44-Ubuntu SMP Fri Sep 17 20:26:08 UTC 2010 i686 GNU/Linux$ gnome-screensaver --versiongnome-screensaver 2.30.0

View 2 Replies View Related

Ubuntu :: Gnome-screensaver Freezes When Click Unlock?

Mar 3, 2011

I am on Ubuntu 10.04, and I think I have had this problem since I installed it.
When I type my password into gnome-screensaver and click "Unlock," all the buttons become disabled and the cursor turns into the "busy" look. I have to go into one of the virtual terminals and do "killall gnome-screensaver." This happens maybe 75% of the time when the screen locks.

Also, this last week or two there is a new problem where the gnome-screensaver covers only part of the screen and I can still see and use most of the desktop.

View 3 Replies View Related

Ubuntu :: Old Gnome Background Appears When Coming Out Of Screensaver?

May 25, 2011

Everytime I unlock my screen in KDE from the screensaver the background for the Gnome interface momentarily appears before the KDE plasma workspace returns. It only appears for a second and, sure, I can live with it but I wondered if there is a way to fix it and why it is happening in the first place? I initially installed ubuntu 10.4 then installed kubuntu through the package manager and have since upgraded to 10.10 and now 11.4. I think this problem has been here since install of kubuntu

View 8 Replies View Related

Fedora :: Gnome-screensaver Not Activating

Dec 11, 2010

I'm running Fedora 12 and the last couple days I have noticed my screensaver will not start anymore. I did a yum update a few days ago don't know if there is a connection between the two. I've just started to Google the topic. Found different culprits ranging from dbus problems to buggy code.

I'm using a x86_64 PC running kernel 2.6.32.23-170.fc12.x86_64. My Gnome version is 2.28.2. The Gnome-screensaver version is 2.28.3-1.fc12.x86_64.

View 1 Replies View Related

General :: GNOME Screensaver Widgets

Apr 10, 2010

Is there a way to add widgets to a Gnome screensaver? I think this can be done with KDE 4, but I've never liked KDE very much. I'm a programmer and comfortable with writing code if needed.

I'd like to be able to:

See the weather and forecast
Control Rhythmbox
Use a flash card widget for reviewing musical concepts

The reason I want these on the screensaver is that I have login restrictions. I would like to be able to do a very limited subset of activities without having to log in.

View 1 Replies View Related

Fedora :: VLC Doesn't Disable Gnome Screensaver?

Jun 6, 2010

I had this problem also in F12, now in F13. Is there a fix for this? It's kind of annoying.

View 9 Replies View Related

Debian :: No Screensaver With Gnome And Squeeze / Get To Show?

Dec 22, 2010

Just did a new install of squeeze using the DI beta 2 and installed the nvidia driver the debian way, then the rss-glx screensavers

when i set a screensaver i can preview it and it runs fine, but when it times out the screen just goes blank.

how do i get the glx screensavers to show?

View 3 Replies View Related

Programming :: Create PyGTK Gnome Screensaver?

Dec 15, 2010

I have created a PyGTK app (a binary clock) that I would like to turn into a screensaver. I added the .desktop file to /usr/share/applications/screensavers/ but all I get when I select it is a black screen. On the GnomeScreensaver FAQ (here) it says to use a gsthemewindow as the toplevel window, but the libraries given are in C. Is there any way to:Import this C library to get access to this toplevel window, Convert this GTK+ C library to PyGTK, or use a pygtk app as a screensaver in some other way?

View 3 Replies View Related

CentOS 5 :: Using KDE Screensaver Application In Gnome On Startup?

Feb 11, 2010

I am trying to get the KDE Media screen saver working in GNOME. Is there a way to use kde's screensaver program in gnome on startup, instead of gnome's screen saver program? Basically, I am trying to disable gnome's screensaver, and load kde's program in its place at gnome startup.

View 1 Replies View Related

Ubuntu Installation :: Wrong Configured Gnome-screensaver (black Screen)?

Feb 24, 2010

all I wanted to get was the "rss-glx"-package as additional screensavers. I am not proud of the results:So I used the Synaptic tool, and since that time the gnome-screensaver shows a black screen instead of any GL-animation in the preview-windows (the small and the big one). The simple screensavers still work (e.g. the Gnome feets).I propably made it worse when trying to uninstall gnome-screensaver and installing xscreensaverxscreensaver crashed on each preview (if the screensaver was installed) and printed an "exited abnormally" (yellow lines on a black screen).Then I was trying to get the original state back - without any "rss-glx".Still not succeeding, the GL-screensavers show nothing except a black screen (e.g. AntSpotLight).So what do I have to do to get back the original state (or to run rss-glx)

View 3 Replies View Related

Fedora :: Create Gnome Screensaver From Video File

Feb 28, 2009

I was wondering how to create a GNOME screensaver from a video file? I don't really care what video format the screensaver creator supports because I can always transcode the video with ffmpeg or mencoder. I also, don't care if the creator uses proprietary formats such as mpeg, mpeg4, avi, etc. I do however want the program to create an installable screensaver.

View 2 Replies View Related

Fedora :: Gnome - Screensaver Will Not Activate On Battery Power

Jul 20, 2009

I have gnome-screensaver on fedora 10 on an intel mac (laptop) under power, screensaver works fine. On battery, the screensaver never activates, it will eventually go to sleep though. I'm kind of new to fedora.

View 1 Replies View Related

OpenSUSE :: Gnome-Screensaver 'Timeout Has Expired' Causes Freeze?

Apr 17, 2011

When I resume my computer from suspend (or after it goes to screensaver), I am sometimes unable to log back in. The message on the lock box simply says 'Timeout has expired' or something to that effect.There is no way to get around that, all I can do is cold-boot loosing all the work I was doing (unsaved).I do not have desktop effects enabled.Running Gnome 2.32, OpenSUSE 114., n550 proc and x3150 Intel GMA

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved