logo

XRDP: Exploiting Unauthenticated X Windows Sessions

ID: d559eb96-1ab1-5ac4-a0e1-d0849ce3b5e1

STIX ID: report--d559eb96-1ab1-5ac4-a0e1-d0849ce3b5e1

Feed Name: SensePost Blog

Threat Score
50/100

Date Published: 2016-12-08

Date Updated: 2026-04-29

...
...

Executive Summary: This blog post explains techniques and proof-of-concept tooling to find and exploit unauthenticated X11 (X Window System) sessions. The authors present XRDP, a Python wrapper that automates window discovery, screen viewing, and input injection (using xwininfo, xwatchwin, xwd, xdotool) to obtain interactive access and spawn a reverse shell, and an nmap script (x11-active-displays) to detect active displays and capture screenshots. They tested scanning country-level ranges and found only a few vulnerable hosts, and published the tools on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.