Xrdp for Security Onion refuses to work

3,282 views
Skip to first unread message

red hat

unread,
Aug 9, 2013, 2:40:33 PM8/9/13
to securit...@googlegroups.com
Hello Everybody

I am not Linux guy and try to setup IDS via security onion quick and dirty. Now I have problem to make xrdp to work.

Basically I did or tried

sudo apt-get update
sudo apt-get upgrade
sudo apt-get install xrdp
echo xfce4-session > ~/.xsession
sudo service xrdp restart

No errors running those commands.

When I used windows 7 RDP to connect Security Onion host, got time out error. But I sure, it was not network issues, because I can ping target the node and ssh to it too.

I searched net, no clue what step I could miss.

Please advice and thanks.

Red2004hat

Heine Lysemose

unread,
Aug 9, 2013, 3:26:02 PM8/9/13
to securit...@googlegroups.com

Does the firewall on your Security Onion box allow rdp?

https://code.google.com/p/security-onion/wiki/Firewall

Regards,
Lysemose

--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.


red hat

unread,
Aug 9, 2013, 4:57:02 PM8/9/13
to securit...@googlegroups.com

I am sure that is not firewall issue. Because both source and target nodes are under same subnet, no firewall in between.

Thanks to reply my post.

-Red2004hat

Doug Burks

unread,
Aug 9, 2013, 5:11:05 PM8/9/13
to securit...@googlegroups.com
Your Security Onion box has a host-based firewall (ufw, Ubuntu
Firewall) as described by the link that Lysemose gave you. By
default, the RDP port is not allowed in ufw. You'll need to open the
RDP port to allow inbound connections.
Doug
--
Doug Burks
http://securityonion.blogspot.com

Greg Porter

unread,
Aug 12, 2013, 4:18:50 PM8/12/13
to securit...@googlegroups.com

If you still have issues after checking your firewall you might try the installation script from here: http://scarygliders.net/x11rdp-o-matic-central-downloads-page/

Even if you choose to do a manual install it had some good tips for getting the Xubuntu desktop working for me.

GP

Richard Bejtlich

unread,
Aug 13, 2013, 5:30:08 PM8/13/13
to securit...@googlegroups.com
On Monday, August 12, 2013 4:18:50 PM UTC-4, Greg Porter wrote:
> On Friday, August 9, 2013 1:40:33 PM UTC-5, red hat wrote:
> > Hello Everybody
> >
> > I am not Linux guy and try to setup IDS via security onion quick and dirty. Now I have problem to make xrdp to work.
> >
> > Basically I did or tried
> >
> > sudo apt-get update
> > sudo apt-get upgrade
> > sudo apt-get install xrdp
> > echo xfce4-session > ~/.xsession
> > sudo service xrdp restart
> >
> > No errors running those commands.
> >
> > When I used windows 7 RDP to connect Security Onion host, got time out error. But I sure, it was not network issues, because I can ping target the node and ssh to it too.
> >

FWIW I used Windows 7 remote desktop connection to connect to xdrp on Security Onion today. I had to alter the firewall weeks ago when I set up the remote access though.

Sincerely,

Richard

red hat

unread,
Aug 15, 2013, 6:25:57 PM8/15/13
to securit...@googlegroups.com

Thanks to Everybody.

I opened firewall at security onion, now xrdp was connected, but I got black screen.

how to fix the black screen problem? I tried

echo xfec4-session > ~/.xsession

Make no different, black screen.....

Please help.


Red2004hat

Matt Gregory

unread,
Aug 15, 2013, 6:34:03 PM8/15/13
to securit...@googlegroups.com
In my experience, xrdp can be a little finicky on connection.  Sometimes a connection won't complete and I'll have to disconnect and reconnect.  The RDP client you use sometimes plays a factor - I've had the best luck with Microsoft's RDP client (I use the Mac version).

Matt




Red2004hat

Greg Porter

unread,
Aug 15, 2013, 9:31:01 PM8/15/13
to securit...@googlegroups.com
You might look at the session configuration utility from the scaryglider
install < RDPsesconfig.sh >

You can look at in on their git site here:

https://github.com/scarygliders/X11RDP-o-Matic/blob/master/RDPsesconfig.sh

It selects a desktop environment that the users will see after they log in via their RDP client. It then select which user logins to configure that environment for. i.e. gnome / unity /xfce /kde etc enviroment for the users.

I have not tried it with the ubuntu package install but you could try downloading the script and running it on a test system.

GP

On Friday, August 9, 2013 1:40:33 PM UTC-5, red hat wrote:

Walker, Greg

unread,
Aug 16, 2013, 8:36:46 AM8/16/13
to securit...@googlegroups.com
I was banging my head against this yesterday trying to get it working. The thing that worked for me was changing xfce4-session to startxfce4 in .xsession.

Greg

Jay Swearingen

unread,
Aug 14, 2017, 2:31:12 PM8/14/17
to security-onion, gwa...@blackbirdtech.com
4 years later ...fixed my "head banger" too. Thanks.

Jeff H

unread,
Dec 31, 2018, 8:59:25 AM12/31/18
to security-onion
thank goodness for this thread, finally fixed it as well. Good thing, my head was getting sore.

Bryant Treacle

unread,
Jan 1, 2019, 9:05:22 AM1/1/19
to security-onion
Jeff,

Sorry for the late post to this but I created a script with all necessary packages to enable xrdp/tigervnc on Security Onion 16.x. It walks you through with some basic questions (including ufw firewall mods). Maybe this will help someone in the future. Here is my github link.

https://github.com/bryant-treacle/Security_Onion_XRDP_Setup

Bryant

Philip Robson

unread,
Jan 29, 2019, 7:31:47 AM1/29/19
to security-onion
This is great thank you Bryant, followed it though and it worked a treat.
Reply all
Reply to author
Forward
0 new messages