SLAC Computer Security
Search SLAC

SLAC Computer Security - X Windows

Revised 28 Feb 2002

The X Window System poses a serious security risk if it is not properly secured. An X11 "display" is the X11 server running on your desktop, and includes the screen, keyboard and mouse. If your X11 display is insecure, it will allow a program running anywhere on the Internet to connect to it and the connection may be completely invisible to you. Once connected, that program has full access to your display, which means that it can:

The best defense is to prevent unwanted connections in the first place. Thus the rule:

NOTE:   SLAC blocks direct Internet access to on-site X11 displays.

This means that an X11 application that runs on an off-site host can not point its display back to your desktop at SLAC -- at least not directly. However, there are two ways that you can run offsite X11 applications in a reasonably secure manner:

For more information about the security weaknesses inherent in the X11 Window system and how to improve X11 security, see the following documents:

Owner: SLAC Computer Security
Last Updated: 02/19/2008
Feedback: Please send to
Computer Security Feedback