I do understand that many like to be able to access their music while on the road, at work, away from home. But please do NOT configure your router to forward those ports to the internet. While this is easy to do, it's dangerous. LMS was not designed to be used this way. Any user out there (incl. me and your neighbor's kids you hate so much) could access your LMS and do all kinds of things.
- Set a password on your LMS, actually locking you out of your own music collection.
- Change the skin
- Blast crazy stupid music at full volume in the middle of the night. And then again five minutes after you turned it off. Repeat.
- Deface your LMS
- Install the Gallery plugin and have it scan all your folder of all your disks, causing a crash sooner or later
- Install any plugin they want, including their own development, doing things we don't even know about
More issues are reported regularly, eg.
- CVE-2017-16567 (https://www.exploit-db.com/exploits/43122/)
- CVE-2017-16568 (https://www.exploit-db.com/exploits/43123/)
On systems where LMS is running as root/admin the last one is particularly dangerous. We have evidence of these kinds of "attacks" almost on a daily basis now. See various threads in this forum.
Now you might think "who would be interested in finding my IP address and port used?". Your neighbor's kid. Or some bored soul seeking some kick. Because it's easy. There are search engines who list your computer and port. No need to figure this one out yourself. And then have some fun. NOT!
So please: review your router's settings. Block those ports. Install a VPN if you need access to your music.
Results 1 to 10 of 137
-
2017-03-22, 08:12 #1
IMPORTANT: Stop forwarding your LMS ports to the internet!
Last edited by mherger; 2017-12-15 at 22:16.
Michael
"It doesn't work - what shall I do?" - "Please check your server.log and/or scanner.log file!"
(LMS: Settings/Information)
-
2017-03-22, 09:08 #2
- Join Date
- Nov 2009
- Posts
- 1,273
May be the wiki should be changed accordingly?:
http://wiki.slimdevices.com/index.ph...cting_remotely
-
2017-03-22, 16:22 #3
-
2017-03-22, 16:23 #4
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,318
Wait till they enforce ipv6, then there will be none.
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..
-
2017-03-23, 02:04 #5"To try to judge the real from the false will always be hard. In this fast-growing art of 'high fidelity' the quackery will bear a solid gilt edge that will fool many people" - Paul W Klipsch, 1953
-
2017-03-23, 04:42 #6
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,318
Just because no-one knows how ipv6 works..
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..
-
2017-03-23, 04:47 #7
-
2017-03-24, 01:11 #8
Is it possible to limit LMS to the local subnet via programming , but have it working via a correctly setup VPN ?
It seems to be a support issues now :/
Wonder why some hacker finds this funny ?
It was that tread on the forum where someone actively asked for open IP's and wanted to share ? Wonder if that one was a cheapskate or a troll ?
That guy got p*** off when mherger told about exactly how bad this idea is ? Sort of guy that can do this ?
More risks someone can actively listen with your accounts on Spotify and your other services.
Ads his players to your mysb.com account via LMS it does that automatically .
Mess up your stats and scrobbling.--------------------------------------------------------------------
Main hifi: Rasbery PI digi+ MeridianG68J MeridianHD621 MeridianG98DH 2 x MeridianDSP5200 MeridianDSP5200HC 2 xMeridianDSP3100 +Rel Stadium 3 sub.
Bedroom/Office: Boom
Loggia: Raspi hifiberry dac + Adams
Bathroom : Radio (with battery)
iPad with iPengHD & SqueezePad
(spares Touch, SB3, reciever ,controller )
server Intel NUC Esxi VM Linux mint 18 LMS 7.9.2
http://people.xiph.org/~xiphmont/demo/neil-young.html
-
2017-03-24, 01:48 #9
- Join Date
- May 2009
- Location
- Clacton-on-Sea, Essex. UK
- Posts
- 635
Hi Michael,
Thank you for reminding me. I had forwarded 4 or 5 ports to trial accessing various things on my server remotely. It's didn't work the way I wanted so I abandoned the trial but of course forgot to delete the port forwarding. They have been removed now though :-)
Thank youLast edited by bobertuk; 2017-03-24 at 02:18.
2 x Touch
2 x Radio
2 x Boom
1 x Intel-NUC server/squeezelite running LMS 7.92 (from nightlies) on Windows 10
1 X Odroid-XU4 server/squeezelite running LMS 7.91 on Ubuntu 16.04
1 x iMac server running macos Hich Sierra
WaveIO USB into Lavry DA-10 DAC
Starfish Pre-amp : Based on NAIM NAC 72
Heavily modified NAIM NAP 250 Power-amp
Behringer DEQ2496
Linn Isobarik DMS
-
2017-03-24, 02:11 #10
IMPORTANT: Stop forwarding your LMS ports to theinternet!
> Is it possible to limit LMS to the local subnet via programming , but
> have it working via a correctly setup VPN ?
If using a VPN you should be fine already. If you feel like tinkering,
check out Settings/Advanced/Security.
> Wonder why some hacker finds this funny ?
Never picked up the phone book to call a random number as a kid?
> More risks someone can actively listen with your accounts on Spotify and
> your other services.
> Ads his players to your mysb.com account via LMS it does that
> automatically .
> Mess up your stats and scrobbling.
Or implement the plugin which will wipe your system. Or encrypt your data.
--
Michael