Every Linux screen locker bypassed with a keypress
seclists.org
seclists.org
[1] http://mailman.archlinux.org/pipermail/arch-general/2012-Jan...
"So from a superficial analysis anything since 1.10.99.902 could be vulnerable."
That's not _every_ linux screen locker. E.g. ubuntu 10.04 isn't affected.
The bug is in Xorg, if you have any screen-locker running on a version with the bug, then it can be bypassed.
heh, OT rant, ...and i get a email from pg scolding me for using factually correct superlatives in my submissions.
yum update xkeyboard-config
with the Fedora repos enabled fixes the issue now (the fixed in version is xkeyboard-config-2.3-3.fc16.noarch).Meaning that any version of any of Gnome/KDE/XFCE/etc's screen lockers will be defeated by this exploit if they are running in this version of Xorg.
As far as I can tell this is probably true, unless someone knows a locker that uses an alternative method of locking out all keyboard/mouse input?
My question is: what is the actual function/line that causes the screen lock to die? My C knowledge is close to non-existent, but the ungrab all function looks a bit suspicious. Some commentary by someone who understands what's going on here would be appreciated.
[1]: http://cgit.freedesktop.org/xorg/xserver/commit/?id=7d2543a3...
Said functionality is entirely intentional, although presumably the author didn't consider the implications outside of a debugging context.
And also the + key on the numpad works?
I was unable to get slock to crash, using a US laptop keyboard. :/
Usually the "numpad" is available via "Fn" key - so make sure that Num lock is on and press `Ctrl+Alt+Fn+*`
Set numlock will enable the numpad keys by default. If numlock is not set, then fn-numpadkey gets the numpad version of the key pressed. E.g. fn-p is *.
Fn+ScrLk is NumLk, and then Ctrl-Alt-8 (on my Lenovo) is exactly the same as Ctrl-Alt-Numpad/8 on a regular keyboard.
Edit: Actually, wait, I'm still on Natty. Still nothing though.
So yet to get the killer feature.
A regular fullscreen application (such as MPlayer, VLC, Chromium, …) does not grab the keyboard and/or pointer. However, applications like pinentry-gtk (for things like entering your GPG passphrase) or screenlockers do grab the keyboard and pointer.
So, in short: no, this doesn’t seem useful in that case. And what you are usually intended to do is use the shortcuts of your window manager to kill the window/application or switch to a different workspace/desktop with a shortcut and kill the process from there.
Regular fullscreen games do, however. If there were some way to distinguish between a lock screen and a game, it would be worthwhile to keep the feature around.
AllowDeactivateGrabs, and its sister option AllowClosedownGrabs which enables ctrl-alt-* to close apps with an active grab, have long been known to be a security hole that the user must explicitly enable. I'm surprised distributions are now somehow shipping with these options enabled! :/
Key combos:
Ctrl+Alt+* (num pad) Ctrl+Alt+Shift+8
Both with numlock on and off.
Or, by holding Ctrl+Alt and trying out all keys, out of pure curiosity.
Just because the bleeding edge version of Xorg is available on Gentoo doesn't mean you're forced to use it. You can always decide not to upgrade and stay with an old version of anything.
On the other hand, if you stay with old versions too long, things might break when you finally do try to upgrade.
physlock also eliminated some of the scaffolding code to deal with the multiple launches, etc. It's just a better tool solving the same problem. Recommended.
If you have any popup dialog box open anywhere, it completely inhibits the screensaver. Try it. Open Rhythmbox and open the volume slider and walk away from your computer. Open Chrome and open the Google Voice popopen box. Your computer will not go to sleep. Also, it breaks mouse focus and more. The GNOME developers don't seem to care at all.