Oh on open VPN already , just an idea to not make so easy to just open the ports like apearently >5000 people are doing already ?
If the next upgrade jts blocks this and they have search for info ....
Ransom ware as an lms plugin
My LMS machine is only that , another safety measure . Its not running on my daily use computer no other personal info on than the LMS settings , no documents no mail .
So I can just delete that VM and reinstall.
And the NAS that keeps the music files is another VM from the NAS that has my personal backup . So i can deleta that one to , but the music share its mounted read only and no executing of files to the LMS machine..
Music is backed up on USB drives .
Results 11 to 20 of 137
-
2017-03-24, 02:39 #11--------------------------------------------------------------------
Main hifi: Rasbery PI digi+ MeridianG68J MeridianHD621 MeridianG98DH 2 x MeridianDSP5200 MeridianDSP5200HC 2 xMeridianDSP3100 +Rel Stadium 3 sub.
Bedroom/Office: Boom
Loggia: Raspi hifiberry dac + Adams
Bathroom : Radio (with battery)
iPad with iPengHD & SqueezePad
(spares Touch, SB3, reciever ,controller )
server Intel NUC Esxi VM Linux mint 18 LMS 7.9.2
http://people.xiph.org/~xiphmont/demo/neil-young.html
-
2017-03-29, 05:54 #12
- Join Date
- Jan 2008
- Posts
- 306
Done. Thanks for the heads-up, Michael.
Interestingly, over the past few months LMS has randomly stopped, with no info in the logs and only "possible software conflict" in the diagnostics tray.
Been running and playing on DSTM for three days now without a stoppage. Could this be related?
Jason
-
2017-03-30, 06:42 #13
Their are some real A-holes out there. I work for a router vendor, and we have a non firewalled internet access in our lab. From time to time we turn it up for deep packet inspection testing, within 30 seconds of turning it up we get pounded with attacks.
Home Office
SB2->Benchmark DAC-1-> Bryston P-25, preamp -> Carver M1.0t Amp->PMC TB2
Home Theater System#1
SB2-> Emotiva PrePro->Bryston 9B ST -> PSB Stratus Goldi
/Home Theater System #2/ LazyEye Bar
Pi3 w/7" screen/HiFiBerry DAC>Outlaw 976-> Bryston 3B ->Klipsch La Scala's, 2x Bryston 4B (mono) EV 18" subwoofers
Bedroom System
SB2-> Sony BoomBox
Rear Deck/Patio
Pi4 --> Yamaha Receiver-> PSB Mini's,
Kitchen
Pi4 --> Yamaha Receiver -> Polk Ceiling Speakers
Ensuite
Squeeze Radio
-
2017-04-01, 12:38 #14
- Join Date
- Aug 2008
- Location
- Norway
- Posts
- 376
At least - if you really wish to have remote access to LMS, add a strong password to log on. This is probably not extremely difficult to hack for someone that knows how. I guess LMS logon exchange user name+password in clear text?
Nevertheless, it's better than nothing.
The downside is that there are several client apps out there that don't support password logon....QNAP TS-453Be 4x3TB RAID5 QNAP TS-251 2x3TB RAID0 QNAP HS-251 2x2TB RAID0 QNAP TS-453Mini 2x1TB Raid 10 LMS running in Docker Madsonic running in Docker Guacamole QPGK R&D and Test server Home Assistant running in Docker Node-Red running in Docker RainLoop QPKG Pi-Hole running in Docker Bastillion running in Docker DeConz running in Docker w/ConBee II Mosquitto MQTT running in Docker
-
2017-04-01, 12:54 #15--------------------------------------------------------------------
Main hifi: Rasbery PI digi+ MeridianG68J MeridianHD621 MeridianG98DH 2 x MeridianDSP5200 MeridianDSP5200HC 2 xMeridianDSP3100 +Rel Stadium 3 sub.
Bedroom/Office: Boom
Loggia: Raspi hifiberry dac + Adams
Bathroom : Radio (with battery)
iPad with iPengHD & SqueezePad
(spares Touch, SB3, reciever ,controller )
server Intel NUC Esxi VM Linux mint 18 LMS 7.9.2
http://people.xiph.org/~xiphmont/demo/neil-young.html
-
2017-04-02, 02:48 #16
And that's an especially bad idea in this case because it's so easy to log the clear-text username and password from LMS...
---
learn more about iPeng, the iPhone and iPad remote for the Squeezebox and
Logitech UE Smart Radio as well as iPeng Party, the free Party-App,
at penguinlovesmusic.com
New: iPeng 9, the Universal App for iPhone, iPad and Apple Watch
-
2017-04-02, 03:21 #17
- Join Date
- Dec 2010
- Posts
- 325
I had that problem, where my music player suddenly went whild in the middle of the night, I had forwarded my LMS ports to the internet. Now I use VPN and no problems at all anymore.
Shame, it was practical to use LMS on the road that way, but simply to unsafe.
Absolutely block those ports, this sort of thing does happen!LMS 7.9.0 - 1470391720 on Pi2 (Max2play)
Synology DS-414 NAS
Squeezebox Touch, Squeezebox Boom, Squeezebox Radio, HifiBerry PicorePlayer
Schiit - BIFROST AKM 4490 Dac
Spotify Premium
-
2017-04-02, 03:43 #18
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,322
I wonder if anyone has searched the darkwebs for LMS attacks..? There are probably "slurp all the music and set some annoying alarms" scripts out there.
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..
-
2017-04-02, 04:40 #19
- Join Date
- Aug 2008
- Location
- Norway
- Posts
- 376
You don't need a script for that. All you need is the IP.
QNAP TS-453Be 4x3TB RAID5 QNAP TS-251 2x3TB RAID0 QNAP HS-251 2x2TB RAID0 QNAP TS-453Mini 2x1TB Raid 10 LMS running in Docker Madsonic running in Docker Guacamole QPGK R&D and Test server Home Assistant running in Docker Node-Red running in Docker RainLoop QPKG Pi-Hole running in Docker Bastillion running in Docker DeConz running in Docker w/ConBee II Mosquitto MQTT running in Docker
-
2017-04-02, 08:15 #20
- Join Date
- Apr 2013
- Location
- UK
- Posts
- 1,322
You do, you know the control protocol. The script kiddies know nothing, they just run scripts.
--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k albums..