Jump to content


Photo

OpenWebif login


  • Please log in to reply
28 replies to this topic

#1 leppen

  • Member
  • 2 posts

0
Neutral

Posted 5 October 2014 - 13:34

After update I can't login to OpenWebif anymore, isn't login root-dreambox anymore?

i'm using a VU+ Solo box with OpenPli 4.0.

 

Thanks!

/leppen

 



Re: OpenWebif login #2 athoik

  • PLi® Core member
  • 8,458 posts

+327
Excellent

Posted 5 October 2014 - 13:36

Login via telnet (no password) and set password for root (passwd) or go to plugins, open OpenWebIf plugin and set Http Authentication to No.

Until recently the default was No, but it changed to Yes for extra security.
Wavefield T90: 0.8W - 1.9E - 4.8E - 13E - 16E - 19.2E - 23.5E - 26E - 33E - 39E - 42E - 45E on EMP Centauri DiseqC 16/1
Unamed: 13E Quattro - 9E Quattro on IKUSI MS-0916

Re: OpenWebif login #3 leppen

  • Member
  • 2 posts

0
Neutral

Posted 5 October 2014 - 13:55

passwd did the trick!

thanks!

 

/leppen



Re: OpenWebif login #4 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 10 October 2014 - 18:53

or go to plugins, open OpenWebIf plugin and set Http Authentication to No.
Until recently the default was No, but it changed to Yes for extra security.


Let's rephrase that: "less insecurity" ;)

Actually the password login alone doesn't make it a good idea to open the OpenWebif to the outside world at all.

However, there are two colliding interests:
We have the user with OpenWebif configured to be opened securely to the outside world (Using key/cert and possibly key auth), but it would be wide open e.g. after reflashing his box (The port forwarding/firewall exception in his router would still be active) until he gets to entirely re-configure it.
This could lead to actual damage (Anyone could delete all your recordings while you are still busy restoring your bouquets or so).

On the other side we have users like leppen that do not want a login (e.g. because they do not open the Webif to the outside world at all), they now have to manually disable login.
This I have to admit is a bit of comfort loss.

Potential data loss during a re-installation however clearly outweights the "hassle" of changing one setting.
1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #5 WanWizard

  • PLi® Core member
  • 68,730 posts

+1,742
Excellent

Posted 10 October 2014 - 19:11

The side-effect for those stupid enough to put their box on the Internet. It's as stupid as installing Windows from the original CD's on a PC that has a live internet connection.

 

This change punishes the good, and allows the bad to get away with their behaviour. Therefore, bad idea.


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Pro (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: OpenWebif login #6 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 10 October 2014 - 19:25

The side-effect for those stupid enough to put their box on the Internet.

Or clever enough to do it right.

It's as stupid as installing Windows from the original CD's on a PC that has a live internet connection.

Who spreads such a bullshit?

Some unrevised knowledge from the mid-90s?

In the 90s that was true, when people had single computers directly attached to modems/bridges of any kind and Windows was a pure DOS-AddOn with no firewall at all.
Lots of homemade pr0n originates from that time, when everybody and his grandma could e.g. access anybody's CIFS shares over the internet, just because NetBIOS over TCP/IP was bound to every new connection and the only PC inside the household was directly attached to some plain DSL-/Cable-Modem ...

Nowadays it is much more likely that you can not even replace your ISP provided router at all anymore than finding a PC that is directly attached to some plain bridge.
Secondly, any still supported Windows comes with its Firewall pre-activated which considers any new network as "public network" and thus blocks any contact from the outside and also even most connections from the inside ...
1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #7 WanWizard

  • PLi® Core member
  • 68,730 posts

+1,742
Excellent

Posted 10 October 2014 - 19:36

lol, yeah, a NAT router gives you security... And Windows is secure out of the box. Keep on dreaming.

 

I'm the governments CERT representitive in this country, and you don't want believe the shit I see on a daily basis, shit that even sofisticated systems like FireEye don't detect.

 

So unlike you're "suggestion', I do know what I'm talking about.


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Pro (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: OpenWebif login #8 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 10 October 2014 - 19:54

lol, yeah, a NAT router gives you security... And Windows is secure out of the box. Keep on dreaming.

I'm not, you are.

I'm the governments CERT representitive in this country, and you don't want believe the shit I see on a daily basis, shit that even sofisticated systems like FireEye don't detect.
 
So unlike you're "suggestion', I do know what I'm talking about.

Then you would know that the only way to guarantee security is to pull the plug and to build a solid wall around the system.

And while there might be a slight security gain by installing Windows offline, then applying all fixes to the current date (Which you would need to have offline somewhere for that ...) and only then attaching the PC to the network, the realistic options are
- Install with the PC connected to the network, giving it the chance to download and apply fixes during installation
or
- Install offline, then connect the PC and download the security fixes while already working with the installation.


BTW:
I'm the government representative for the BER airport in this country ... ;)
And my older brother is a General inside the army ... a bit childish, eh?

When you talk about concepts and shit, it might be helpful if you would stick to what is realistic in a private environment.
There, the PC gets attached to the home router anyways and then it's better the latest fixes get applied during installation rather than hours after the system went up (If at all).
1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #9 theparasol

  • Senior Member
  • 4,157 posts

+198
Excellent

Posted 10 October 2014 - 20:19

@Mods: Better checkout SpaceRats account, it seems to be hacked: Lately his replies are very violent towards other users.


Edited by theparasol, 10 October 2014 - 20:20.

@Camping: ZGemma H.2S, Technisat Multytenne 4-in-1 @Home: Edision Mini 4K, Wave Frontier T55, EMP Centauri EMP DiSEqC 8/1 switch, 4x Inverto Ultra Black single LNB


Re: OpenWebif login #10 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 10 October 2014 - 20:28

Hahaha ...

I just can't stay calm if people start explaining how to keep the cake ... without telling the whole truth, which is that you can't eat it too ...

... or if someone tells us that it would be stupid to take the bus from home to work because the bus could be bombed ...
... which is very helpful to know if you can't afford going by plane, buying your own car or if the distance is too long to go on foot or on a bicycle ...

I just tell you the truth:
Life suxx and in the end we are all dead.
1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #11 WanWizard

  • PLi® Core member
  • 68,730 posts

+1,742
Excellent

Posted 10 October 2014 - 21:10

You're full of **** as usual.

 

Fact remains, you made a stupid decision, and a lot of people are annoyed by it. And instead of thinking it over, you go to great lengths to justify yourself, and make idiotic remarks. Very grown up of you.


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Pro (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: OpenWebif login #12 athoik

  • PLi® Core member
  • 8,458 posts

+327
Excellent

Posted 10 October 2014 - 21:45

@OpenPLi please fix SRC_URI or no images tonight.

-SRC_URI += "0001-Revert-Change-insane-default-again.patch"
+SRC_URI += "file://0001-Revert-Change-insane-default-again.patch"

Edited by athoik, 10 October 2014 - 21:46.

Wavefield T90: 0.8W - 1.9E - 4.8E - 13E - 16E - 19.2E - 23.5E - 26E - 33E - 39E - 42E - 45E on EMP Centauri DiseqC 16/1
Unamed: 13E Quattro - 9E Quattro on IKUSI MS-0916

Re: OpenWebif login #13 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 10 October 2014 - 22:52

You're full of **** as usual.
 
Fact remains, you made a stupid decision, and a lot of people are annoyed by it. And instead of thinking it over, you go to great lengths to justify yourself, and make idiotic remarks. Very grown up of you.

You haven't made a single point concerning the actual topic.
Instead you keep posting claims which aren't really wrong but pure theory.

I've probably kept more people from opening the WebInterface to the outside than all of you in this thread together
#1, #2, #3, ...

However, I can't and will not deny the reality:
In the real world we get 10 users opening the web interface for each one I or anyone else can keep from opening the web interface to the outside, if not more.

If having an at least semi-secure default can help to make some of them aware of the potential risks, I have already reached my goal.
1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #14 Erik Slagter

  • PLi® Core member
  • 46,960 posts

+541
Excellent

Posted 11 October 2014 - 07:51

SpaceRat, first you wil have to learn that often more views on a topic can exist and that even you might not have the one and only true view. As long as you can't live with that, I suggest you present yourself a bit more modest and friendly here, after all you are a guest, just like everyone else.


* Wavefrontier T90 with 28E/23E/19E/13E via SCR switches 2 x 2 x 6 user bands
I don't read PM -> if you have something to ask or to report, do it in the forum so others can benefit. I don't take freelance jobs.
Ik lees geen PM -> als je iets te vragen of te melden hebt, doe het op het forum, zodat anderen er ook wat aan hebben.


Re: OpenWebif login #15 SpaceRat

  • Senior Member
  • 1,030 posts

+65
Good

Posted 11 October 2014 - 11:57

SpaceRat, first you wil have to learn that often more views on a topic can exist and that even you might not have the one and only true view.

You must be confusing me with someone else.

It's not me who says that something which isn't good doesn't happen, that's MiLo.
His opinion is not only that opening the Webif to the outside world is bad (Which in general is true), he even enforces it by removing the slight protection there is whenever OpenPLi gets reinstalled, reset to factory defaults or loses its settings.
He puts his opinion above the reality, which is that you can easily find hundreds to thousands of opened WebInterfaces using Google and thanks to him some of them will have day of the open door today.

My opinion is that opening the Webif to the outside world in general is a bad idea (Unless you do it right, which involves a lot more than just adding a login/pass), but I accept that there are a lot of people that will do it anyways and that "even they" deserve a slight bit of protection too (Even if it is not really sufficient).
The impact on those who didn't open the Webif to the outside (and do not want password protection for any other reason, e.g. to keep out the children) is minimal: One toggle.

Everybody who reads this:
Which view is more balanced?


BTW:
What really p1sses me off is that MiLo instantly jumped in to enforce his opinion on this topic by patching the build process of OpenWebif.
If he would have spent the same effort in fixes autofs could work on OpenPLi by now, that's a one-liner too.

Edited by SpaceRat, 11 October 2014 - 11:57.

1st box: Vu+ Ultimo 4k 4xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
2nd box: Gigablue Quad 4k 2xDVB-S2 FBC / 2xDVB-C / 1.8 TB HDD / OpenATV 6.2
testing boxes: Vu+ Duo² + AX Quadbox HD2400 + 2x Vu+ Solo² + Octagon SF4008
Sats & Pay-TV: Astra 19.2°E + Hotbird 13°E with Redlight / SCT HD / SES Astra HD- / Sky V14 / 4th empire propaganda TV
Card-Server: Raspberry Pi + IPv6-capable oscam
Router: Linksys WRT1900ACS w/ LEDE + Fritz!Box 7390

Re: OpenWebif login #16 Erik Slagter

  • PLi® Core member
  • 46,960 posts

+541
Excellent

Posted 11 October 2014 - 12:44

Again QED...


* Wavefrontier T90 with 28E/23E/19E/13E via SCR switches 2 x 2 x 6 user bands
I don't read PM -> if you have something to ask or to report, do it in the forum so others can benefit. I don't take freelance jobs.
Ik lees geen PM -> als je iets te vragen of te melden hebt, doe het op het forum, zodat anderen er ook wat aan hebben.


Re: OpenWebif login #17 littlesat

  • PLi® Core member
  • 56,348 posts

+692
Excellent

Posted 11 October 2014 - 12:53

OpenWebif is safe when you tunel it via ssh (putty).... or use VPN. Then no password is required at all... so the password is extreme anoying... In addition it gives those who share their webif via the WWW a fake safety...

 

Then better give a description how to use the suff safely...

 

note when a box is hacked... it is not the one who open their box on the WWW did it wrong... It is OpenPLi's fault...


Edited by littlesat, 11 October 2014 - 12:55.

WaveFrontier 28.2E | 23.5E | 19.2E | 16E | 13E | 10/9E | 7E | 5E | 1W | 4/5W | 15W


Re: OpenWebif login #18 theparasol

  • Senior Member
  • 4,157 posts

+198
Excellent

Posted 11 October 2014 - 12:57

SSH and VPN are far too complicated to setup for the dumb crowd!

 

I agree with MiLo and my reason is that by setting the default webif protected with user/pass is useless.

First we have a hand full of people now what they are doing, they simply flip the usersetting and go to the webif unprotected again.

Second is the group of users complaining they cant get into the webif anymore and openpli need to tell over and over again how to do it.

Whatever openpli does: it is always wrong!

 

The majority that forwards on purpose the webif to the internet are very happy it "finally" works due to lack of knowledge e.g. how routers work / ip protocol in general.

Most people dont know shit about security and frankly I think most wont give a damn either. The day things start to go wrong badly they start to complain, its everybodies

fault exept theirs. You can tell them over and over again the webif is unsafe they just blame whoever not making it safe in the first place.

 

Same goes for precious data they have and stored on local harddrive. One bad day they got deleted by accident/error, drive dies, got encrypted by ransomware.

You name it. For that reason we have licenses for cars, planes, fire arms, fill in yourself. But not for using a computer or even having an internet connection.

 

Bottomline: you cant protect someone against their own stupidity. You cant warn them either since they consider themselves smart...


@Camping: ZGemma H.2S, Technisat Multytenne 4-in-1 @Home: Edision Mini 4K, Wave Frontier T55, EMP Centauri EMP DiSEqC 8/1 switch, 4x Inverto Ultra Black single LNB


Re: OpenWebif login #19 Erik Slagter

  • PLi® Core member
  • 46,960 posts

+541
Excellent

Posted 11 October 2014 - 13:03

I'd think that a check for ip adresses (only RFC local ranges are allowed) would have more sense. That way also people that use a vpn won't even notice.


* Wavefrontier T90 with 28E/23E/19E/13E via SCR switches 2 x 2 x 6 user bands
I don't read PM -> if you have something to ask or to report, do it in the forum so others can benefit. I don't take freelance jobs.
Ik lees geen PM -> als je iets te vragen of te melden hebt, doe het op het forum, zodat anderen er ook wat aan hebben.


Re: OpenWebif login #20 theparasol

  • Senior Member
  • 4,157 posts

+198
Excellent

Posted 11 October 2014 - 13:20

That could work out but I'm sure a storm of topics will raise about: cant use webif over the internet any longer.

Good luck explaining how to setup vnp on the routers and clientdevices...

 

But... from then on it will be safe :)


@Camping: ZGemma H.2S, Technisat Multytenne 4-in-1 @Home: Edision Mini 4K, Wave Frontier T55, EMP Centauri EMP DiSEqC 8/1 switch, 4x Inverto Ultra Black single LNB



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users