Jump to content

Help! ALL my users logged in to the server simultaneously


Go to solution Solved by AndreiP,

Recommended Posts

Posted

I've posted this before, adding here for reference.

General good practices for securing your Emby server.

1. Enable TLS/HTTPS
2. Use a reverse proxy if you can and know how to do it. If you don't know how look into Caddy and use a reverse proxy.
3. Force all users to have passwords.
4. Don't allow remote access for Admin accounts. If you do then make sure the passwords are strong.
5. Don't show users on the remote login page.
6. Don't show admin users on any login page.
7. Don't use the name Admin for your main admin user.

 

  • Agree 1
  • Thanks 1
Posted

Q-Droid and Neminem, thank you very much! 🙏
 

Could I ask you two questions, please:
1. Can I add/change the password from here using the mange Emby server? (Please check my screenshot).

2. If I add/change a password, will the user be able to connect to the server as before (with Emby Connect)? Or will they have to enter the password they connect the first time after changing the password? (or only the first time). They watch on TV and phones usually. 

Capture d’écran 2025-08-22 102800.png

Neminem
Posted
2 minutes ago, Q-Droid said:

1. Enable TLS/HTTPS
2. Use a reverse proxy if you can and know how to do it. If you don't know how look into Caddy and use a reverse proxy.
3. Force all users to have passwords.
4. Don't allow remote access for Admin accounts. If you do then make sure the passwords are strong.
5. Don't show users on the remote login page.
6. Don't show admin users on any login page.
7. Don't use the name Admin for your main admin user.

That a really great write up 👍

  • Thanks 2
Neminem
Posted
Just now, AndreiP said:

If I add/change a password, will the user be able to connect to the server as before (with Emby Connect)?

Yes

  • Thanks 1
Neminem
Posted (edited)

The password is for your local server.

Thats how they / that got in, circumventing Emby Connect.

Emby connect uses the forum credentials.

Edited by Neminem
  • Thanks 1
Posted
Quote

1. Can I add/change the password from here using the mange Emby server? (Please check my screenshot).

So, it's possible to ad or change password from this page also?  

Neminem
Posted (edited)
2 minutes ago, AndreiP said:

So, it's possible to ad or change password from this page also?  

You need to elaborate no this page ?

Emby Server :

Only the local password..

Emby Forum :

Emby connect password is changed via this forum.

But only by the user.

Edited by Neminem
Posted (edited)
Quote

 

Only the local password..

Emby connect password is changed via this forum.

 

Yes, I understand. In my case I mean I can add here the password for all my users to avoid this kind of situation, right? 

Edited by AndreiP
Neminem
Posted

Yes that should help 👍

It's not as safe as running disconnected from the internet, but what's the fun in that 🤣😂

But exposing anything to the internet has risks.

So it's up to you, now that you had a scare 😉

  • Haha 1
Posted

Once again, thank you very much for what you wrote! 🙏


I'll try to summarize the situation: a malware (?) managed to connect to my IP address using the port opened by/for Emby: 8096.
Then, from Emby's login screen, it connected all my users except admin because these users didn't have passwords configured for local access to the Emby server.
Thank you for confirming my understanding.

  • Like 1
  • Agree 1
Neminem
Posted (edited)

Yes that would be the short of it 👍

Edit

Malware : NO.

Sorry but !!

Admin error.

So happy it was only a scare to learn from 😁

Edited by Neminem
  • Agree 1
Posted

Thank you, Neminem! 

So, what/who connected to my server if it was not a malware? 

Neminem
Posted (edited)

Bot or script kiddy ( that had fun. )

In case you are scared, you have good reason !!

if they wanted it really annoy you they would have enabled deletion of media.

And deleted all your media 🤷‍♂️.

Be happy it was only a scare 😁

Edited by Neminem
  • Thanks 1
Neminem
Posted (edited)

Also I sometime see bots savaging for open servers to add to there streaming services.

FREE access, using your media and internet.

Edited by Neminem
Posted
Just now, Neminem said:

Also we sometime see bots savaging for open servers to add to there streaming services.

FREE access, using your media and internet.

🙀

Neminem
Posted

So its best to close it down tightly 😉

  • Solution
Posted (edited)
For other users who have the same problem. Q-Droid and Neminem found the solution.

I will resume here in this post what to do. 

1. Set a password for all users, even if they use Emby Connect.
2. Put this in your users' profile settings.
 

Capture d’écran 2025-08-22 092134.png

 

And please also check the post above of Q-Droid about "General good practices for securing your Emby server". 

Quote

 

I've posted this before, adding here for reference.

General good practices for securing your Emby server.

1. Enable TLS/HTTPS
2. Use a reverse proxy if you can and know how to do it. If you don't know how look into Caddy and use a reverse proxy.
3. Force all users to have passwords.
4. Don't allow remote access for Admin accounts. If you do then make sure the passwords are strong.
5. Don't show users on the remote login page.
6. Don't show admin users on any login page.
7. Don't use the name Admin for your main admin user.

 

 

Edited by AndreiP
  • Like 1
Posted

Thank you very much for your help! 👏

  • Thanks 1
rbjtech
Posted
1 hour ago, Q-Droid said:

I've posted this before, adding here for reference.

General good practices for securing your Emby server.

1. Enable TLS/HTTPS
2. Use a reverse proxy if you can and know how to do it. If you don't know how look into Caddy and use a reverse proxy.
3. Force all users to have passwords.
4. Don't allow remote access for Admin accounts. If you do then make sure the passwords are strong.
5. Don't show users on the remote login page.
6. Don't show admin users on any login page.
7. Don't use the name Admin for your main admin user.

 

tbh, I'm still not sure why these are not the default settings during the install wizard... 

  • Agree 1
Posted
14 minutes ago, rbjtech said:

tbh, I'm still not sure why these are not the default settings during the install wizard... 

Yes, they should be. I might have suggested a built-in checker a while back, around the time of the breach, to identify and warn of settings that deviated from or were in conflict with these. But other things have higher priority.

 

  • Agree 1
Neminem
Posted

TBH its incredible that Emby does not warn admins about these settings.

And Admins need to have a scare, to correct them.

It's both dumb and dangerous, when exposed to the internet, if these things are not mentioned or warned about.

  • Agree 2
  • 4 weeks later...
Posted

For anyone seeing this please up vote this

 

  • Agree 2
DarkStar1977
Posted

Additionally you can blacklist the IP that have been used to connect with all your users into your server, i'ts not a great solution but at least you will be sure from this IP they will never access again:

image.png.50b56ea1269a7a84e55f4fa8a58c0cac.png

In my case I've blacklisted all IP's that tried to access my server even they did not get access :)

  • Thanks 1
DarkStar1977
Posted (edited)

As well for my users I do not let them access to my emby server via web browser, I'm forcing them to use emby apps and you can link each user to specific devices:

On Access Tab for each user:

image.png.c46ac225f266c927ac590e735697075e.png
image.png.e8c4ce8d05250a6aa2561f081bfc83dc.png

So you can link specific users to specific devices and this will block any other type of connection even if they figure the user password, as the device will not match they will not be able to access to your server.

Hope this helps.

Edited by DarkStar1977
  • Like 1
  • Thanks 1
Posted
40 minutes ago, DarkStar1977 said:

As well for my users I do not let them access to my emby server via web browser, I'm forcing them to use emby apps and you can link each user to specific devices:

On Access Tab for each user:

image.png.c46ac225f266c927ac590e735697075e.png
image.png.e8c4ce8d05250a6aa2561f081bfc83dc.png

So you can link specific users to specific devices and this will block any other type of connection even if they figure the user password, as the device will not match they will not be able to access to your server.

Hope this helps.

Thnak you. It's very strange, but in my case it didn't help. The "users" logged in Emby server even if I did the same think from Device Access. 🤔

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...