DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2008-06-02 13:09:59

Odin
New member
Registered: 2008-06-02
Posts: 1

Security issues bittorrent and download section in the web interface

Hi.


As many as you known the latest firmware enable bittorrent support.
I will raise the question if it is wise to allow EVERYBODY with access to connect to the ftp server also have access view and add torrent download.

Meaning everyone with a username and password can login to the download section of the web-browser interface.

- There is one positive thing that solve the problem many are struggling with..

If you NOT use the "admin" account you are able to delete the finished downloads.

However, I find it quite disturbing that everyone with ftp access (even that they are all my friends) can see and add torrent (and ftp) downloads.

Is it away to only allow a specific user group to log in to the download section ?

Offline

 

#2 2008-06-02 20:02:45

marca
Member
Registered: 2007-10-13
Posts: 64

Re: Security issues bittorrent and download section in the web interface

Well, you can portmap it on a "unknown" portnumber. (For example http://xxx.dyndns.org:80976) to connect to your internal DNS-323 IP.

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB