BSI-100-2: S 4.105: Initial measures after a Unix standard installation: ~/.Xclients - 'xhost +' should never be used.
Xauth is to preferable to xhost - 'xhost +' should never be used. (see also S 4.9 Use of the security mechanisms of X-Window) Safeguard Catalogues: S 4: Hardware and software S 4.105: Initial measures after a Unix standard installation