Jump to content

security issue/wrong configuration


Florin

Recommended Posts

Hello, I'm using Emby 3.0.5781.8 on FreeNAS 9.3, if I forward port 8096 on my router I can connect from my windows phone (Lumia 640) and also anyone who know my IP address can connect to server configuration page without any user/password using a simple link like http://IPAdress:8096

If I'm not forwarding port 8096 I cant connect from phone.

Is that a security issue or is my mistake configuring something wrong?

 

Thank you in advance!

Edited by Florin
Link to comment
Share on other sites

Solved temporary by creating another user and hiding the admin account from the login screen, anyway forwarding port 8096 which allow access to anyone to server configuration page is not normal and should be inaccessible by default.

If there is anything more that I can do please let me know. I'm at the begging with Emby and FreeNAS but I can learn.

Link to comment
Share on other sites

Emby should require all users to log in before granting access to anything at all. Maybe that there is some kind of network configuration that makes emby believe all users connecting to your server is the same person on the local network. Can you verify in "Recent Activity" section of the server dashbord that remote users are registered with different IP addresses?

Link to comment
Share on other sites

Is showing only a few messages from yesterday when I was trying and I don't see any related to that, I was calling a friend from another town and he confirmed that the server configuration page appeared after he connected using http://myDNSaddress:8096, he does not have account on my server and he was never connected to my server. I also experienced the same thing using my windows phone with internet explorer as browser and internet service by a different provider (not over wifi).

Edited by Florin
Link to comment
Share on other sites

I understand. Still, IP addresses might be rewritten during the NAT process and that is why I asked if you could verify that remote connection are correctly reported in the server dashboard. Access your server remotely (from the WAN), and have a look after at the dashboard and see which IP is reported. Is it a real remote IP or your router IP?

Edited by 3psus
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...