DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2011-09-08 22:17:39

franck.desert
New member
Registered: 2011-09-08
Posts: 1

telnet enabled / disabled

Hi,

I'm an happy user of the DNS323 and i'm tried tonight to install ssh protocol, to be able to accessit via web AND localy through my LAN.

I'm on Windows and I succeed in all operations described on related web pages but i got an issue :

The advice coming just after the fisrt accomplished ssh connection is to disable telnet (because of lack of security)

The fact is as soon I disable telnet, the DNS323 disappeared from my LAN (in the "Windows" network)

As soon I enable it, it reappears.

So my question :

If i need to access also localy to my DNS323, do I have to always  keep Telnet activated or do I have to establish a new type of connection inside my LAN ?

Hope your support ...

Offline

 

#2 2011-09-09 18:09:28

karlrado
Member
Registered: 2009-12-07
Posts: 229

Re: telnet enabled / disabled

I think that there is something else going on.  Enabling or disabling telnet on the 323 should not have an effect on Windows networks.

First, I'm not an expert on this particular aspect of Windows networking, but from what I understand, "being visible in a Windows network" involves some sort of discovery protocol which can take a variable amount of time to discover network resources.  I am guessing that when you disabled telnet and rebooted the 323, Windows didn't get around to probing around the network to look for the 323.  I think if you waited long enough, the 323 may have eventually shown up.  This might take on the order of 10-30 minutes.  And there are probably Windows commands to force a network probe, but I don't know what they are.

Second, the notion of disabling telnet for security reasons is probably overblown, depending on your network configuration and usage.  In my case, the 323 is on a very private home network with just two possible users.  It is connected to the Internet via a NAT router which forwards only SSH on a non-standard port to the 323.  So I just leave telnet enabled on the 323 because if I ever have a problem with SSH, like a configuration mistake, it is simpler to telnet in to make the repair.  I suppose the idea of disabling telnet may be more valuable in an office environment where there are several users that might be inclined to hack into the 323 via telnet or something like that.

In any case, I would try disabling telnet again and then waiting awhile to see if the 323 shows up.  If I'm totally wrong and you do need to have telnet enabled, you can decide for yourself if it causes a security issue for you.


DNS-323 FW 1.07 : 2 1TB WD Caviar Green SATA : fun_plug: utelnet + optware (no ffp)

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB