> Ok, figured it might be something like that. Not an easy problem to
> solve. In this circumstance it would be better to receive a page back
> that says *why* the request was blocked and where to look to allow it
> rather than a 403. Anonymise the hell out of the response of course so
> people can't reasonably guess it's an LMS instance.
That's kind of an oxymoron, isn't it? Tell the user what to do to open
the door, but not tell the attacker what system it is?...
--
Michael
Results 71 to 80 of 129
-
2018-01-12, 17:03 #71
IMPORTANT: Stop forwarding your LMS ports to theinternet!
-
2018-01-12, 17:32 #72Players: SliMP3,Squeezebox3 x3,Receiver,SqueezeLiteX,PiCorePlayer x3,Wandboard
Server: LMS Version: Latest Nightly on Centos 7 VM on ESXi 6.5.0U1 on Dell T320
Plugins: AutoRescan/BBCiPlayer/PowerSave/PowerSwitchIII/Squeezecloud/Spotty/Player Groups
Remotes: iPeng9/Orangesqueeze/PC/Jivelite/SqueezeLiteX
Music: 522GB,1660 albums with 23087 songs by 5204 artists mostly FLACs
Want a webapp ? See http://forums.slimdevices.com/showth...Webapp-for-LMS
-
2018-01-13, 03:07 #73
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,176
Yes, I know. Thought that as I wrote it. But a change to default behaviour really should be documented and even this is a vast improvement over just being wide open, even if an attacker knows what's there if they can't get anything back from it (not even a password prompt) there's little they can do to get into it.
Transcoded from Matt's brain by TapatalkLast edited by drmatt; 2018-01-13 at 03:10.
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..
-
2018-01-13, 10:48 #74
- Join Date
- Nov 2010
- Location
- Hertfordshire, UK
- Posts
- 2,701
I managed to get my remote access working again (a while since I had used it and some bits and bobs have changed). Using SSH (port 22) and public key. With Squeeze Commander I could still change the audio settings of players, even though I have no CLI password set. Is this what you would expect?
Setting a password would be problematic for some of my plugins, like the UPnP bridge.LMS 7.9.1 on VortexBox Midi box, Xubuntu 17.10, FLACs 16->24 bit, 44.1->192kbps. Touch & EDO. 2nd Touch standard.
LMS plugin UPnP/DLNA Bridge to MF M1 CLiC (to A308CR amp & ESLs) & Marantz CR603 UPnP renderers.
Alternatively Minimserver & Upplay to same & to upmpdcli/mpd PC renderers.
Squeezelite to Meridian USB Explorer DAC to PC speakers/headphones.
Wireless Xubuntu 17.10 laptop firefox/upplay or Android 'phone with Squeeze-Commander/BubbleUPnP controls LMS/Minimserver.
-
2018-01-13, 12:48 #75
- Join Date
- Apr 2005
- Location
- UK/London
- Posts
- 873
What does your LMS system see as your IP address when you connect in via that route?
I don't remember if LMS logs it ... but you could SSH to the LMS server and type
set | grep -i ssh
on a pCP server (and I suspect other Linux platforms) you will see the IP address of this SSH session.
-
2018-01-13, 13:57 #76
- Join Date
- Nov 2010
- Location
- Hertfordshire, UK
- Posts
- 2,701
It's an external IP address that I don't recognise - it isn't an internal one, nor the external IP address of my router/gateway.
I have tried looking at the standard web page in the mobile browser, and can still see all the settings and have changed one or two advanced plugin settings.
I'm running Logitech Media Server Version: 7.9.1 - 1515659378 @ Thu Jan 11 09:26:58 UTC 2018LMS 7.9.1 on VortexBox Midi box, Xubuntu 17.10, FLACs 16->24 bit, 44.1->192kbps. Touch & EDO. 2nd Touch standard.
LMS plugin UPnP/DLNA Bridge to MF M1 CLiC (to A308CR amp & ESLs) & Marantz CR603 UPnP renderers.
Alternatively Minimserver & Upplay to same & to upmpdcli/mpd PC renderers.
Squeezelite to Meridian USB Explorer DAC to PC speakers/headphones.
Wireless Xubuntu 17.10 laptop firefox/upplay or Android 'phone with Squeeze-Commander/BubbleUPnP controls LMS/Minimserver.
-
2018-01-14, 03:34 #77
- Join Date
- Apr 2005
- Location
- UK/London
- Posts
- 873
-
2018-01-14, 04:59 #78
- Join Date
- Nov 2010
- Location
- Hertfordshire, UK
- Posts
- 2,701
LMS 7.9.1 on VortexBox Midi box, Xubuntu 17.10, FLACs 16->24 bit, 44.1->192kbps. Touch & EDO. 2nd Touch standard.
LMS plugin UPnP/DLNA Bridge to MF M1 CLiC (to A308CR amp & ESLs) & Marantz CR603 UPnP renderers.
Alternatively Minimserver & Upplay to same & to upmpdcli/mpd PC renderers.
Squeezelite to Meridian USB Explorer DAC to PC speakers/headphones.
Wireless Xubuntu 17.10 laptop firefox/upplay or Android 'phone with Squeeze-Commander/BubbleUPnP controls LMS/Minimserver.
-
2018-01-14, 07:34 #79
-
2018-01-14, 07:42 #80
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,176
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..