Announcement

Collapse
No announcement yet.

IMPORTANT: Stop forwarding your LMS ports to the internet!

Collapse
This is a sticky topic.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Originally posted by epoch1970 View Post
    Mhh. FLAC or WAV take a lot of bandwidth, probably the tunnel can't keep up.
    I have used bridged OpenVPN tunnels from time to time, everything is fine for mp3/AAC/CD-quality stuff but for hi-def or hi-quality I've seen issues.
    The server side uses its upload link to send the data, with asymmetric connexions (small upload/large download bandwidths) you get a bottleneck there.
    High definition playback does work via open Ports on windows though, on iPad and iPhone both OpenVPN and open ports. And the video I stream from my satellite receiver via OpenVPN to windows laptop is about 10 times higher bit rate then FLAC from LMS. So it must be some kind of issue between squeeze play and open VPN on windows which makes the bottleneck.
    The Earth Has Music For Those Who Listen

    Comment


      Originally posted by Pommes View Post
      So it must be some kind of issue between squeeze play and open VPN on windows which makes the bottleneck.
      Right. Past the 3 openvpn options I've described just above, I don't know what to do next.
      I suppose the idea could be to increase buffering in the player, but I'm not sure how to do that properly with squeezelite (?).
      Also take a look at your LMS settings for players, perhaps the preferences for that Win squeezelite are not set the same way as the others.
      2 SB 3 • 1 PCP 7 • Libratone Loop, Zipp, Zipp Mini • iPeng (iPhone + iPad) • LMS 8.1 (docker) with plugins: CD Player, WaveInput by bpa • Material Skin by Craig Drummond • IRBlaster by Gwendesign (Felix) • Smart Mix, Music Walk With Me, What Was That Tune? by Michael Herger • PowerSave by Jason Holtzapple • Song Info, Song Lyrics by Erland Isaksson • BBC Sounds by Stuart McLean • AirPlay Bridge by philippe_44 • Auto Dim Display, SaverSwitcher, ContextMenu by Peter Watkins.

      Comment


        Originally posted by epoch1970 View Post
        Right. Past the 3 openvpn options I've described just above, I don't know what to do next.
        I suppose the idea could be to increase buffering in the player, but I'm not sure how to do that properly with squeezelite (?).
        Also take a look at your LMS settings for players, perhaps the preferences for that Win squeezelite are not set the same way as the others.
        Don’t worry I will just use the open ports for squeezeplay. It is working fine with the open ports. But the modification of ovpn conf which you told me to do definitely increased the streaming ability via open VPN for my video from satellite receiver, so thanks again
        The Earth Has Music For Those Who Listen

        Comment


          Personally I would kill the idea of streaming flac to mobile devices and just bandwidth limit the client in LMS. 320kb MP3 is undoubtedly good enough when out and about. I would guess the limitation is insufficient pre buffering, whereas internet video players would be more aware of the requirements for this.

          Flac is as you say about 900kbit, maybe just over 1mbit so shouldn't really be a big issue. Note that HD video can be streamed in about 1.8mbit and still be bearable. Probably less, but still more than a flac stream.



          Transcoded from Matt's brain by Tapatalk
          --
          Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
          Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..

          Comment


            Originally posted by drmatt View Post
            Personally I would kill the idea of streaming flac to mobile devices and just bandwidth limit the client in LMS. 320kb MP3 is undoubtedly good enough when out and about. I would guess the limitation is insufficient pre buffering, whereas internet video players would be more aware of the requirements for this.

            Flac is as you say about 900kbit, maybe just over 1mbit so shouldn't really be a big issue. Note that HD video can be streamed in about 1.8mbit and still be bearable. Probably less, but still more than a flac stream.



            Transcoded from Matt's brain by Tapatalk
            For mobile use on iphone i use transcoded stream of 192kbit.
            For remote use with laptop connected to highend gear or good headphones i rather use flac. its just around 800kbit.
            The videos i stream from my sat reciever use a bandwith of 8-14mbit!
            No issue so far, even with openvpn. as i said: only the win7 squeezeplay when used via openvpn doesnt do, but streams flac when not using openvpn
            The Earth Has Music For Those Who Listen

            Comment


              I gave up on remotely accessing my LMS after I inadvertently left the ports open when the vpn no longer worked. I had some clown playing stuff on my system. Nowadays I have a backup on a wifi enabled WD Passport drive that runs its own copy of LMS. I use that to play locally to mobile devices or a Raspberry Pi.

              Robert
              Home: Raspberry Pi 4/pCP7.0/LMS8.1.2/Material with files on QNAP TS-251A
              Touch > DacMagic 100 > Naim Audio Nait 3 > Mission 752 (plus Rega Planar 3 > Rega Fono Mini; Naim CD3)
              2 x Squeezebox Radios, 1 X Squeezebox 3 (retired), 1 x SqueezeAMP
              Office: LMS8.0.0 running on Raspberry Pi3; Raspberry Pi 3 player with touchscreen/piCorePlayer/IQaudIO DAC and Amp
              Portable: Raspberry Pi 3B/pCP7.0.1/LMS8.1.2/Material, files on Seagate portable drive, powered via power brick

              Comment


                Originally posted by Grumpy Bob View Post
                I gave up on remotely accessing my LMS after I inadvertently left the ports open when the vpn no longer worked. I had some clown playing stuff on my system. Nowadays I have a backup on a wifi enabled WD Passport drive that runs its own copy of LMS. I use that to play locally to mobile devices or a Raspberry Pi.

                Robert
                well, that sucks, some clown taking control of your system.
                what did the clown do? was he able to delete anything or mess your LMS completely?
                did you have password protection on your lms?
                The Earth Has Music For Those Who Listen

                Comment


                  IMPORTANT: Stop forwarding your LMS ports to theinternet!

                  > what did the clown do?

                  See the very first posting in this thread.

                  --

                  Michael
                  Michael

                  "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
                  (LMS: Settings/Information)

                  Comment


                    I backtracked on that thread (should be working instead...) and I want to say having a password protecting settings from remote accesses will be (is?) a great addition.
                    To those with routed VPNs complaining about the extra password, I say use a bridged network, it makes player discovery work

                    In passing, I don't know the state of TOTP/QR on perl, but in my opinion a time-based password is a concept end-users grasp easily. Downloading an app and flashing a QR code is somehow an easier proposition than choosing and remembering yet another password, hard to guess please.
                    It would be probably better to have a short, volatile 6-digit password protect the server rather than the usual "passw0rd" or "lms1234"...
                    There are plenty of free TOTP clients for mobile, desktop or the command line.
                    2 SB 3 • 1 PCP 7 • Libratone Loop, Zipp, Zipp Mini • iPeng (iPhone + iPad) • LMS 8.1 (docker) with plugins: CD Player, WaveInput by bpa • Material Skin by Craig Drummond • IRBlaster by Gwendesign (Felix) • Smart Mix, Music Walk With Me, What Was That Tune? by Michael Herger • PowerSave by Jason Holtzapple • Song Info, Song Lyrics by Erland Isaksson • BBC Sounds by Stuart McLean • AirPlay Bridge by philippe_44 • Auto Dim Display, SaverSwitcher, ContextMenu by Peter Watkins.

                    Comment


                      The thread hasn't been active for a while, I hope some xperts are still reading.

                      Here's another victim...

                      LMS 7.9.1 on Synology with open - and now closed - port 9002, username and password were set, Picture Gallery installed, an additional non-music folder added in the general preferences (I could browse the entire folderstricture across the entire Diskstation...)

                      Reading to the first post here, my stomach turned upside down.

                      I deinstalled the LMS too quickly to check settings etc. and find out what the installation would have allowed the intruder to do.

                      Replicating with a fresh LMS installation didn't work, as the Picture Gallery plugin seems offline in the repository.

                      Assuming, someone 'only' installed the gallery plugin: does this allow reading / downloading also PDFs, excels, docs and so on? Or 'only' shows pictures it finds?

                      Am I understanding correctly, that once someone accessed the LMS, the user & password had to be set, i.e. max one person can go inside as it's locked afterwards?

                      Thanks for helping me gain a bit clarity on the dimensions...

                      Gesendet von meinem HTC U Ultra mit Tapatalk

                      Comment


                        Originally posted by dr..mike View Post
                        Assuming, someone 'only' installed the gallery plugin: does this allow reading / downloading also PDFs, excels, docs and so on? Or 'only' shows pictures it finds?

                        Am I understanding correctly, that once someone accessed the LMS, the user & password had to be set, i.e. max one person can go inside as it's locked afterwards?
                        The Gallery plugin was developed for pictures only. That said I know that some of the attackers did install modified versions of the plugin. They could potentially do anything they want. They could as well just write their own to download all those files, yes. But then I'm not aware of an attack at that level.

                        The password can be used by anyone knowing it. Most likely this is only being set to annoy the users, and potentially have a bit more time to explore whatever content they got access to.
                        Michael

                        "It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
                        (LMS: Settings/Information)

                        Comment


                          Originally posted by mherger View Post
                          The Gallery plugin was developed for pictures only.
                          Thanks for sharing your thoughts!!

                          With the above & the seemingly normal outgoing traffic volumes my router is showing, I'm trying to semi-comfort my mind that someone had their fun, looking at family pics or a weekend outing... and browsing the names of my directory structure, leaving the trace of a saved random folder in the settings...

                          Fingers crossed, but I suppose nothing to actively do to find out if things may have been stolen and where they may have ended up.

                          Gesendet von meinem HTC U Ultra mit Tapatalk

                          Comment


                            Originally posted by mherger View Post

                            And then there's that undocumented pref you can set to disable the check
                            in such an exceptional case.
                            So how to disable this check? I didn't find the answer! I want to disable it. Where is that pref, what should i do to disable it?

                            Comment


                              Synology router configuration

                              Just a warning to anyone who blocked theses ports in the past. If you get a new router and and use Synology's automatic router configuration, pay a little more attention than I did. I had blocked theses ports years ago on my old router and did not think to tell the server to not open them back up. Of course someone with too much time on there hands found them and locked me out of my LMS.

                              Of note, I informed Synology that they should not allow the automatic router configuration tool to do this as it is a known exploit. They basically told me it was my fault for using their software . Fair enough, but it is the first time I've had a response from Synology that annoyed me in the 9 years I've been using there servers.

                              Comment


                                But why is your nas open to internet, use router vpn!
                                SqueezeBoxes: 1x Transporter (Living room) 1x SB2 (shed), 1x Radio (Kitchen), 1x Boom (Dining room), 1x piCorePlayer (jacuzzi), 1x piCorePlayer (Garden) 1x OSMC + Squeezelite (Movie room), 1x Touch (Study 2), few spare unit's (SB2, SB3, Boom, Touch)
                                Server: LMS on Pi3B+ 8.1.2 on PcP 7.0.1
                                Network: Draytek, Netgear Smart Switch 24p, Ubiquiti PoE, 3x Ubiquity

                                Comment

                                Working...
                                X