DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2010-04-06 07:42:51

2mymall
Member
Registered: 2010-03-29
Posts: 11

Ban/Deny access by IP address to funplug lighttpd server

I am using the lighttpd feature from funplug and have a webserver runing on the DNS 323. When people are accessing the site, it is normal to have both the internet access light and hard disk light on the NAS blinking.

But at times, I notice that only the internet access light blinking furiously. Checking the access logs, I find entries like:

222.186.13.75 bbs.rexian.net.cn - [04/Apr/2010:20:32:13 +0800] "GET http://bbs.rexian.net.cn/templates/defa … DE197923E2 HTTP/1.0" 404 345 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"

118.161.233.46 - - [04/Apr/2010:20:37:26 +0800] "CONNECT maile.burst.idv.tw:25 HTTP/1.0" 501 357 "-" "-"

114.255.168.213 [My DNS323 IP:Port] - [06/Apr/2010:01:37:13 +0800] "GET /manager/html HTTP/1.1" 404 345 "-" "Mozilla/3.0 (compatible; Indy Library)"

Correct me if I am wrong but I suspect someone has found a loophole to use the internet through the server.

Is there any way to ban or deny access to the web server.

Offline

 

#2 2010-04-06 16:29:51

hell0
Member
From: .de
Registered: 2008-05-13
Posts: 81

Re: Ban/Deny access by IP address to funplug lighttpd server

2mymall wrote:

Correct me if I am wrong but I suspect someone has found a loophole to use the internet through the server.

Read http://en.wikipedia.org/wiki/List_of_HTTP_status_codes to understand what you log means.
Don't run your webserver on a well known port like 80 and this will probably never happen again...


CH3SNAS firmware 1.05 with WD1000FYPS and ffp 0.5 on USB Stick

Offline

 

#3 2010-04-06 20:59:46

2mymall
Member
Registered: 2010-03-29
Posts: 11

Re: Ban/Deny access by IP address to funplug lighttpd server

Hello, Thanks for the link bit it does not help. Codes 345 & 357 are not listed.

Anyway the web server is not running on port 80.

Offline

 

#4 2010-04-06 22:00:57

hell0
Member
From: .de
Registered: 2008-05-13
Posts: 81

Re: Ban/Deny access by IP address to funplug lighttpd server

The codes in your log are 404 and 501 wink

Then its like port 443 or 8080?


CH3SNAS firmware 1.05 with WD1000FYPS and ffp 0.5 on USB Stick

Offline

 

#5 2010-04-07 09:32:53

2mymall
Member
Registered: 2010-03-29
Posts: 11

Re: Ban/Deny access by IP address to funplug lighttpd server

You're right.

Don't seem to have luck changing the ports though. I can see lighttpd config and open it in notepad, but don't have the correct permissions on win 7 to save it.

I can log in as root in shell and change file permissions but no idea how to modify the file in shell.

Even after changing the file permission to 777, I still cannot save changes using notepad.

Any advice??

Offline

 

#6 2010-04-07 09:49:11

mushanga
Member
Registered: 2009-06-26
Posts: 46

Re: Ban/Deny access by IP address to funplug lighttpd server

First, set the permission to 666 (read & write to everyone, no execution) instead of 777 (read/write/execute).
Then use a native linux editor (like vi or nano) under ssh or telnet access or, if you're not comfortable with that, use Notepadd++ in windows which is aware of linux text file format.
If it is not enougth try to download the configuration file, modify it under windows with Notepad++ and overwrite it.

Offline

 

#7 2010-04-07 11:17:17

KyleK
Member
From: Dresden, Germany
Registered: 2007-12-05
Posts: 1178

Re: Ban/Deny access by IP address to funplug lighttpd server

Offline

 

#8 2010-04-07 11:27:48

2mymall
Member
Registered: 2010-03-29
Posts: 11

Re: Ban/Deny access by IP address to funplug lighttpd server

Thanks mushanga. That worked.

Chmod it to 666, edited it with textpad and saved it back. Restarted the server and everything is ok.

Now just hope this stops the unauthorized activity I always notice on the server.

Thanks again man.

Last edited by 2mymall (2010-04-07 11:30:46)

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB