xrdp.ini: Remove [vnc-any] as a default section

As it stands, this is not suitable for production environments, as
the attached CVE shows.
This commit is contained in:
matt335672
2026-04-15 10:58:49 +01:00
parent 9834a58ca6
commit a85e108cdf
+30 -26
View File
@@ -298,33 +298,37 @@ port=-1
#disabled_encodings_mask=0 #disabled_encodings_mask=0
; Generic VNC Proxy ; Generic VNC Proxy
; Tailor this to specific hosts and VNC instances by specifying an ip ; To use this, remove the '#-#' prefix from the lines below. Tailor
; the section to specific hosts and VNC instances by specifying an ip
; and port and setting a suitable name. ; and port and setting a suitable name.
[vnc-any] ; This can be used with no customisations in test environments, but
name=vnc-any ; should always be locked down to specific hosts and/or ports in
lib=libvnc.@lib_extension@ ; production.
ip=ask #-#[vnc-any]
port=ask5900 #-#name=vnc-any
username=na #-#lib=libvnc.@lib_extension@
password=ask #-#ip=ask
#pamusername=asksame #-#port=ask5900
#pampassword=asksame #-#username=na
#delay_ms=2000 #-#password=ask
; Use one of these to connect to a chansrv instance created outside of sesman #-##pamusername=asksame
; (e.g. as part of an x11vnc console session). Replace 's' with the #-##pampassword=asksame
; display string of the session, and (if applicable) 'u' with the numeric #-##delay_ms=2000
; UID of the session. #-#; Use one of these to connect to a chansrv instance created outside of sesman
; #-#; (e.g. as part of an x11vnc console session). Replace 's' with the
; For compatibility, a completely numeric display string is taken to be #-#; display string of the session, and (if applicable) 'u' with the numeric
; an X11 display number #-#; UID of the session.
; #-#;
; You will also need to change the value of SessionSockdirGroup in #-#; For compatibility, a completely numeric display string is taken to be
; sesman.ini to allow xrdp to reach the chansrv instance #-#; an X11 display number
; #-#;
; If 'username' or 'pamusername' is set, you probably don't need to use #-#; You will also need to change the value of SessionSockdirGroup in
; the two parameter variant with 'u'. #-#; sesman.ini to allow xrdp to reach the chansrv instance
#chansrvport=DISPLAY(n) #-#;
#chansrvport=DISPLAY(n,u) #-#; If 'username' or 'pamusername' is set, you probably don't need to use
#-#; the two parameter variant with 'u'.
#-##chansrvport=DISPLAY(n)
#-##chansrvport=DISPLAY(n,u)
; Generic RDP proxy using NeutrinoRDP ; Generic RDP proxy using NeutrinoRDP
; Tailor this to specific hosts by specifying an ip and port and setting ; Tailor this to specific hosts by specifying an ip and port and setting