<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5993&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5993</link>
		<description><![CDATA[The most recent posts in [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm.]]></description>
		<lastBuildDate>Sat, 23 Sep 2023 03:22:41 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44480#p44480</link>
			<description><![CDATA[<p>One amendment: To toggle full screen mode for <em>Calligrasheets</em>, it is <strong>Ctr+F11</strong>.&#160; I thought that there was some challenge with <em>Calligra&#039;s</em> full screen!&#160; Lol&#160; <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" />&#160; Have a good evening!</p>]]></description>
			<author><![CDATA[dummy@example.com (ExposeGlobalistsMadness)]]></author>
			<pubDate>Sat, 23 Sep 2023 03:22:41 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44480#p44480</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44479#p44479</link>
			<description><![CDATA[<p>Did you honestly expect anyone to read that wall of barely-coherent rant, or were you just thinking aloud to yourself?<br />This board some days <img src="https://dev1galaxy.org/img/smilies/roll.png" width="15" height="15" alt="roll" /></p><p>Ed. No, wait, it&#039;s <em>most</em> days. Guess that&#039;s why I don&#039;t bother trying to be helpful here, far too much crazy for my taste.</p>]]></description>
			<author><![CDATA[dummy@example.com (steve_v)]]></author>
			<pubDate>Sat, 23 Sep 2023 01:01:19 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44479#p44479</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44478#p44478</link>
			<description><![CDATA[<p>The artefacts recently were found to be due to these applications apparently starting in full screen mode;&#160; the solution was to strike the <strong>F11</strong> to toggle full screen off, as that thankfully appears to be a relevant key-binding in common for all these applications, although <em>calligrasheets</em> had to be toyed with a bit:&#160; the <em>calligra</em> suite had been later reinstalled, and I think <strong>F11</strong> would only respond by closing the <em>calligra</em> worksheet and applying <strong>F11</strong> with the <em>calligra</em> startup application that appeared.</p><p>Note that <em>Featherpad</em> also had developed similar artefacts, turned off also with <strong>F11</strong>:&#160; <em>Featherpad</em> could not be dragged or resized with the default mouse bindings;&#160; the default &#039;lower window&#039; binding had since been modified by choice to &#039;maximize window&#039;, and that wouldn&#039;t respond either.</p><p>These artefacts had persisted even when <em>blackbox</em>, a different window manager, was installed, including (a) with <em>Mousepad</em> when it was reinstalled;&#160; and (b) more recently, with <em>xfce4-terminal</em>.</p><p>That &#039;full screen&#039; suspicion and <strong>F11</strong> solution were<a href="https://forum.lxde.org/viewtopic.php?p=48287&amp;sid=f851477ac0ce6a759c285150a3cb3855#p48287" rel="nofollow"> proposed in 2013</a> for a similar situation with some LXDE application(s).&#160; One argument brought up for applications possibly starting in full screen mode was that it might be related somehow to some new theme(s) being applied.&#160; In my case, some themes from Devuan&#039;s official repos had indeed been installed earlier and, for what it&#039;s worth, later applied with an excellent LXDE theme manager:&#160; <em>lxappearance</em>.</p><p>Therefore, I could not identify any vulnerability, and this thread has been closed although, in case it could be &#039;remotely&#039; relevant, a &#039;dlm&#039; error was also noted on logout, but I can&#039;t find it in any current <span class="bbc">/var/log</span> file. Why would there be need for a &#039;distributed lock manager&#039; on my standalone pc?&#160; How could a lone dlm package - <strong>libdlm3</strong>, a &#039;Distributed Lock Manager library&#039; - have appeared on my system? After a bit of research, I decided to remove it without any noticeable knock-on effect, except the error occasionally was noted to persist on logout.</p>]]></description>
			<author><![CDATA[dummy@example.com (ExposeGlobalistsMadness)]]></author>
			<pubDate>Fri, 22 Sep 2023 22:37:44 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44478#p44478</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44410#p44410</link>
			<description><![CDATA[<p>Maybe my system got infected, perhaps exploiting, again presumably, a vulnerability elsewhere:&#160; <em>fbpanel</em> was preserved from my original <em>Chimaera</em> installation, persisting through the dist upgrade to <em>Daedalus</em> despite it no longer being offered by <em>Daedalus</em> nor its Debian equivalent, <em>Bookworm</em>, I noticed today.&#160; Maybe the following points to its imminent removal from the repository:&#160; <a href="https://lists.debian.org/debian-qt-kde/2022/08/msg00131.html" rel="nofollow">https://lists.debian.org/debian-qt-kde/ … 00131.html</a> </p><p>See the reason given in a <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=936507" rel="nofollow">link </a> there:&#160; <em>&quot;Python2 becomes end-of-live upstream, and Debian aims to remove Python2 from the distribution [...]&quot;</em>.</p><p>It is not maintained upstream:&#160; <a href="https://github.com/aanatoly/fbpanel" rel="nofollow">https://github.com/aanatoly/fbpanel</a> .</p><p>I suspected <em>fbpanel</em> to be compromised more recently, as its menu icons stopped displaying, even after restarting it or firejailing it, etc.&#160; <em>Fbpanel</em> has now been purged and replaced with <em>tint2</em>. <em>Mousepad</em> and the <em>Calligra</em> suite may be again retried at a later date:&#160; perhaps they might not be culprits, although <em>mousepad</em> and <em>calligrasheets</em> were not launched from <em>fbpanel</em> when their artefacts manifested:&#160; they were launched from <strong>.xinitrc</strong>.</p>]]></description>
			<author><![CDATA[dummy@example.com (ExposeGlobalistsMadness)]]></author>
			<pubDate>Mon, 18 Sep 2023 00:19:32 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44410#p44410</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44348#p44348</link>
			<description><![CDATA[<p>I have now noticed, days later, that <em>Calligrasheets</em> also cannot be dragged, resized or lowered despite using the default key bindings either.&#160; It was also launched from <strong>.xinitrc</strong> with a file as an argument while firejailed e.g.:</p><div class="codebox"><pre><code>/usr/bin/firejail  --net=none /usr/bin/calligrasheets &#039;/home/someusername/Documents/Somefile.ods&#039; &amp;</code></pre></div><p>Note that <em>mousepad</em> had also been launched from <span class="bbc">.xinitrc</span>, but with a check for the latest version of three files, each having slightly different suffixes before the <strong>.txt</strong> extension:</p><div class="codebox"><pre><code>/usr/bin/mousepad -- &quot;$(ls -t /home/$USER/Documents/SomeFolder/SomeFileVersion*.txt | head -n 1)&quot; &quot;$(ls -t /home/$USER/Downloads/SomeFolder/SomeOtherFileVersion*.txt | head -n 1)&quot; &quot;$(ls -t /home/$USER/Downloads//SomeFolder/SomeOtherFileVersion*.txt | head -n 1)&quot; &amp;</code></pre></div><p><em>calligra*</em> packages have been now been purged accordingly for now, to be on the safe side, although it is a great suite.&#160; I do not see a way to update the thread title to include this suite.</p>]]></description>
			<author><![CDATA[dummy@example.com (ExposeGlobalistsMadness)]]></author>
			<pubDate>Fri, 15 Sep 2023 22:29:37 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44348#p44348</guid>
		</item>
		<item>
			<title><![CDATA[[SOLVED] Vulnerability in Mousepad? Unable to drag, resize, or lower in cwm]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=44323#p44323</link>
			<description><![CDATA[<p><em>Mousepad</em> couldn&#039;t be dragged, resized or lowered despite using the default key bindings in a <strong>cwm</strong> window manager (<em>Alt</em> being the <em>Meta</em> key on my system), being <em>Alt+LeftClick+drag</em>, <em>Alt+MiddleClick+dragcorner</em> and <em>Alt+RightClick</em>, respectively:</p><div class="codebox"><pre><code>$ man cwm
[...]
          The default mouse bindings are:

           M-M1            Move current window.
           CM-M1           Toggle group membership of current window.
           M-M2            Resize current window
           M-M3            Lower current window.
           CMS-M3          Hide current window.
[...]</code></pre></div><p><span class="bbu">Background</span>:&#160; My Devuan system (on a Raspberry pi 400 arm64 architecture, in case it is relevant) was recently updated with bash instructions from <em>Chimaera</em> to <em>Daedalus</em>, and the display manager was purged to replace it with the system&#039;s interactive text login using an <strong>.xinitrc</strong> file (plus <strong>.bash_profile</strong>, <strong>.profile</strong>, and a soft link from <strong>.xsession</strong> to <strong>.xinitrc</strong>).&#160; It then automatically launches a <strong>cwm</strong> window manager and <em>ungoogled-chromium</em> browser among other applications in Xorg.&#160; Full disclosure:&#160; There may still be some unresolved error messages (see <a href="https://dev1galaxy.org/viewtopic.php?id=5900" rel="nofollow"> earlier messages</a>), and I am still unsure whether one of <em>Daedalus</em>&#039; offered improvements was automatically implemented - whether Xorg now runs as a user instead, or as root.&#160; Hopefully this was not botched in my upgrade, and no security risk as it stands!&#160; The system is up-to-date and, though I uninstalled mousepad last night, the current version, according to <span class="bbc">apt search mousepad</span>, is &quot;<span class="bbc">mousepad/stable 0.5.10-2 arm64</span>&quot;.</p><p>I thought it strange when I was not able to drag <em>Mousepad</em> quite a while ago but didn&#039;t get concerned enough until last night.&#160; Other windows responded well to all three bindings;&#160; windows included <em>xfce4-terminal</em>, <em>calligrasheets</em>, <em>librewolf</em> and <em>ungoogled-chromium</em>. I wonder whether someone remotely was able to commandeer my <em>Mousepad</em> to launch inside some kind of vm, with its window borders not visible, and disabling the dragging/resizing of that windows hides any vm(?)&#039;s window borders, so as to eavesdrop.&#160; I had been setting some changes in my <strong>.cwmrc</strong> file that I figured might be interfering.&#160; </p><p><em>Mousepad</em> (c.3Mb with dependencies) was therefore purged;&#160; <em>featherpad</em>, a &quot;<em>Lightweight Qt5 plain-text editor</em>&quot; was installed instead at c.500kb (with any dependencies), and it appears to offer roughly the same main functions.</p><p>Perhaps as a related issue, on a previous Devuan (<em>Chimaera</em>) installation, <em>Mousepad</em> wouldn&#039;t launch visibly when right-clicking on various<strong> .txt</strong> files one at a time in <em>spacefm</em> and when selecting the default &#039;Mousepad&#039;;&#160; it would only launch from a right-click menu when selecting the &#039;<em>Editor</em>&#039; choice, if my memory is correct.</p><p>Note that I don&#039;t bother with window grouping or tiling, so no such settings are knowingly amended in <strong>.cwmrc</strong>.</p><p>The only somewhat relevant .cwmrc custom bindings might be:-</p><div class="codebox"><pre><code># &quot;Sometimes it&#039;s necessary to unbind keys first [...]&quot;, acc. to https://www.reddit.com/r/openbsd/comments/fo7fou/cwm_default_terminal_cwmrc_applications/fldqiw8/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button
unbind-key all

# Window-maximize seems to toggle windows
# BUT THIS SETTING HAS SINCE BEEN COMMENTED OUT, AS DECIDED IT WAS UNNEEDED
bind-mouse M-3		window-maximize

# TO PREVENT POINTER FROM WARPING ON THE fbpanel LAUNCHER/SYSTEMS BAR/TASK BAR - 
# THE WINDOWNAME FROM xprop FOR fbpanel IS panel SO &quot;ignore fbpanel&quot; DOES NOT WORK
ignore panel</code></pre></div><p>If it could be of use, I could reinstall <em>Mousepad</em> temporarily to, say, give you its <em>xprop</em> description or terminal output when launched from a terminal in case the artefacts would present again or in case the reports are relevant.&#160; The only somewhat relevant .<strong>config</strong> object perhaps was a <strong>Mousepad</strong> folder, but I decided not to keep it, sorry (there was no <strong>.config/mousepad </strong>folder before purging <em>Mousepad</em>, if i recall correctly).&#160; I may have synced the <strong>Mousepad</strong> folder from lingering previous installation backups.&#160; I am tired of signing up to different websites so, sorry, but I am not inclined to register to file this as a bug report.&#160; If it is of interest or can be replicated, and if this sounds like something worse than a <strong>.cwmrc</strong> misconfiguration, perhaps an interested Devuan party could take this up.</p>]]></description>
			<author><![CDATA[dummy@example.com (ExposeGlobalistsMadness)]]></author>
			<pubDate>Thu, 14 Sep 2023 17:36:10 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=44323#p44323</guid>
		</item>
	</channel>
</rss>
