Jump to content


Photo

concerns about "anonym/guest" user connexion


  • Please log in to reply
5 replies to this topic

#1 gspock

  • Senior Member
  • 113 posts

+3
Neutral

Posted 31 July 2021 - 10:44

Hi all,

context: I am using an android app to connect to my VU+DUO4KSE to use the remote control facility. In this app, there is a username/password where I used to put "root" and its password, "root" being the only user on the system to my knowledge. A bit by hazard, those infos were cleaned-up, and now I see that even without those logging info I can connect to the STB.

 

I made the same test with a few other apps and that is the same ! access is allowed without giving any credential.

 

What am I missing ?

 

Thanks,

GS


VU+ DUO-4K-SE with 1 DBV-C and 1TB Hitachi HDD, OpenPLi 8.3


Re: concerns about "anonym/guest" user connexion #2 betacentauri

  • PLi® Core member
  • 7,185 posts

+323
Excellent

Posted 31 July 2021 - 12:36

Have you really set a password? If not, you can login via telnet with any password.

If you have set a password, this shouldn't be possible anymore. Only with the valid password.

 

Just login via telnet and use "passwd" to set a new password. There is also a plugin available which can set a password.

 

Nevertheless e2 boxes are NOT hardened security devices. Better don't use port forwarding to access the box from the internet. Instead use a vpn tunnel.


Xtrend ET-9200, ET-8000, ET-10000, OpenPliPC on Ubuntu 12.04

Re: concerns about "anonym/guest" user connexion #3 gspock

  • Senior Member
  • 113 posts

+3
Neutral

Posted 31 July 2021 - 14:04

Have you really set a password? If not, you can login via telnet with any password.

If you have set a password, this shouldn't be possible anymore. Only with the valid password.

 

Just login via telnet and use "passwd" to set a new password. There is also a plugin available which can set a password.

 

Nevertheless e2 boxes are NOT hardened security devices. Better don't use port forwarding to access the box from the internet. Instead use a vpn tunnel.

 

Thanks.

Yes, 100% sure "root" userid is password protected.

I am not using any port fwd and indeed when I want to remotely access any of my devices I am using a vpn .... I also noticed that with some version of Windows, I can access the system via SMB withou providing any credential info ....

This is really surprising, even if you say that "e2 boxes are not hardened ..." ;  so, anyone any other idea ?

 

BTW is there an easy way, from ssh session, to check who is connected to the box ?


VU+ DUO-4K-SE with 1 DBV-C and 1TB Hitachi HDD, OpenPLi 8.3


Re: concerns about "anonym/guest" user connexion #4 WanWizard

  • PLi® Core member
  • 70,929 posts

+1,835
Excellent

Posted 31 July 2021 - 14:25

I can access the system via SMB withou providing any credential info ....

 

There was a lot of opposition when we tried to change that.

 

You can change that by removing the # in front of

# include = /etc/samba/smb-secure.conf

in  /etc/samba/smb-user.conf

 

( there is no GUI option to change this yet )


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Ultimate (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: concerns about "anonym/guest" user connexion #5 WanWizard

  • PLi® Core member
  • 70,929 posts

+1,835
Excellent

Posted 31 July 2021 - 14:28

p.s. most apps connect to the web interface API, you can enable password authentication and/or enforcement of HTTPS in the plugin config (menu / plugins / openwebif ).

 

If authentication is disabled, it only allows passwordless access from the local subnet, or, if VPN access is allowed, from all RFC1918 addresses.


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Ultimate (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: concerns about "anonym/guest" user connexion #6 gspock

  • Senior Member
  • 113 posts

+3
Neutral

Posted 31 July 2021 - 15:37

@WanWizard Thanks for your answers.


Edited by gspock, 31 July 2021 - 15:37.

VU+ DUO-4K-SE with 1 DBV-C and 1TB Hitachi HDD, OpenPLi 8.3



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users