DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2007-06-21 08:19:30

mykroft
Member
Registered: 2007-05-12
Posts: 83

Easy Search Util

What prevents someone from finding out that I have a Dlink DNS box on the lan and having them download the ESU program and then start messing with what config build into that program without having admin access to the box?  Example - Language, DHCP, IP, Netmask, Gateway etc......

Offline

 

#2 2007-06-21 09:17:12

Apskaft
Member
From: Karlskrona, Sweden
Registered: 2007-01-09
Posts: 165

Re: Easy Search Util

That depends; EasySearch works with passwords - but not very well.

I posted something about this a few moths back.

/Apan

Last edited by Apskaft (2007-06-21 09:18:52)

Offline

 

#3 2007-06-21 14:52:35

fordem
Member
Registered: 2007-01-26
Posts: 1938

Re: Easy Search Util

Being overly paranoid myself, I understand your concerns - however, given the intended use of the device, I would like to suggest that if you have security issues on the local LAN, you most likely have bigger problems than the DNS-323 to worry about.

Offline

 

#4 2007-06-21 18:20:26

mykroft
Member
Registered: 2007-05-12
Posts: 83

Re: Easy Search Util

Well, my concern is if I recommend and start using some of these at work - there are ALWAYS nosy ppls.......

Offline

 

#5 2007-06-21 19:41:14

fordem
Member
Registered: 2007-01-26
Posts: 1938

Re: Easy Search Util

Aha - using consumer grade equipment in the corporate environment is always a risky proposition.

Have you considered the fact that you cannot, with the standard firmware, integrate the DNS-323 into an AD domain, and that your access control choices are read/write & read only?  I would think you'll have more curiosity in that regard than folks taking the trouble to download the ESU to poke around in your settings.

For corporate use, especially in a Windows environment, I would be more inclined to suggest a Windows Storage Server based product rather than linux.

Offline

 

#6 2007-06-21 21:18:32

mykroft
Member
Registered: 2007-05-12
Posts: 83

Re: Easy Search Util

Well, it would be a read only environment - archival of PDF manuals, memos, policy book sections/updates.  They are just using a xp box and sharing a drive read only.  But I thought this might work better for that task because it can be tucked away where someone will not mess with it like they do that computer at times.

It not a big company, 100 employees or so - but am just looking for a cheap solution for a simple task.

But you are correct about using consumer equip in a business environment - security is not the highest concern.  But then again, samba has alot more capabilities - they just need to update the web interface to access them.

Offline

 

#7 2007-06-21 21:47:12

fonz
Member / Developer
From: Berlin
Registered: 2007-02-06
Posts: 1716
Website

Re: Easy Search Util

mykroft wrote:

But then again, samba has alot more capabilities - they just need to update the web interface to access them.

Why not edit the config files directly?

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB