Results 1 to 10 of 14

Thread: Boxee SMB security hole revealed

Hybrid View

  1. #1
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    327

    Default Boxee SMB security hole revealed

    Boxee SMB Security Hole

    SOURCE http://blog.kteck.ca/2012/05/04/boxe...security-hole/

    After doing some research on how the Boxee remote system worked i found some urls for doing basic control/info retrieval from the older desktop software/ current software on Boxee box. One of which was now playing status. After messing with some of the others I went back to the now playing url and noticed something that didn’t seem right.



    Boxee doesn’t store the smb (Windows file sharing) authentication in a secure data store and securely retrieve it like is done on modern systems. Instead it sends the username/password as part of EVERY request for media shared from a windows computer. That means every request for media sent out is done in this format *“smb://<username>:<password>/path/to/media/file.<extension>”. Which is not a secure method especially since app developers can do remote apps that interact with the software even to the extent of requesting currently playing media.

    While this isn’t a major issue on a single user network the issue really comes to focus on a muli-user shared network. Without a fix in the core of the Boxee software all you can do is setup your share security so a Boxee only user is exposed. For example make new user that is just for Boxee media shares or just setup your media shares to allow anyone to read but need authenticated user to write that way either a non important user is exposed or it can access the media without needing login.
    Last edited by nfodiz; May 4th, 2012 at 01:27 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  2. #2
    Join Date
    Mar 2009
    Location
    Las Vegas, NV
    Posts
    1,993

    Default

    Patiently awaiting a response to this one. I always love to see responses from somebody official... Where's my popcorn... I'm pulling up a chair now and waiting.
    Got questions about Navi-X??? Check our Navi-X Wiki at tinyurl.com/navixwiki for answers to even the toughest problems or drop us a note in our forums at http://www.navixtreme.com/forums and bookmark your question then check it later for an answer!

  3. #3
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    327

    Default

    An official response from Team Boxee would be great. I would like to see this fixed sooner rather than later
    Last edited by nfodiz; May 4th, 2012 at 03:28 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  4. #4

    Default

    You should submit a bug report in jira. The forum is not the place for this.

  5. #5

    Default

    Why use SMB?

  6. #6
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    327

    Default

    Quote Originally Posted by Scirocca View Post
    Why use SMB?
    I don't but i'm sure a lot of people out there do.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  7. #7
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    327

    Default

    Quote Originally Posted by influx2k View Post
    You should submit a bug report in jira. The forum is not the place for this.
    I had already filed a jira bug report (not that anything will happen with it)
    I disagree though that this should not have been posted here in the forums. Customers have a right to know about security holes in their systems and ways to work around the issue until a patch is released. Thanks for your valuable input though
    Last edited by nfodiz; May 5th, 2012 at 07:38 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •