Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Boxee SMB security hole revealed

  1. #1
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    328

    Default Boxee SMB security hole revealed

    Boxee SMB Security Hole

    SOURCE http://blog.kteck.ca/2012/05/04/boxe...security-hole/

    After doing some research on how the Boxee remote system worked i found some urls for doing basic control/info retrieval from the older desktop software/ current software on Boxee box. One of which was now playing status. After messing with some of the others I went back to the now playing url and noticed something that didn’t seem right.



    Boxee doesn’t store the smb (Windows file sharing) authentication in a secure data store and securely retrieve it like is done on modern systems. Instead it sends the username/password as part of EVERY request for media shared from a windows computer. That means every request for media sent out is done in this format *“smb://<username>:<password>/path/to/media/file.<extension>”. Which is not a secure method especially since app developers can do remote apps that interact with the software even to the extent of requesting currently playing media.

    While this isn’t a major issue on a single user network the issue really comes to focus on a muli-user shared network. Without a fix in the core of the Boxee software all you can do is setup your share security so a Boxee only user is exposed. For example make new user that is just for Boxee media shares or just setup your media shares to allow anyone to read but need authenticated user to write that way either a non important user is exposed or it can access the media without needing login.
    Last edited by nfodiz; May 4th, 2012 at 01:27 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  2. #2
    Join Date
    Mar 2009
    Location
    Las Vegas, NV
    Posts
    1,994

    Default

    Patiently awaiting a response to this one. I always love to see responses from somebody official... Where's my popcorn... I'm pulling up a chair now and waiting.
    Got questions about Navi-X??? Check our Navi-X Wiki at tinyurl.com/navixwiki for answers to even the toughest problems or drop us a note in our forums at http://www.navixtreme.com/forums and bookmark your question then check it later for an answer!

  3. #3
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    328

    Default

    An official response from Team Boxee would be great. I would like to see this fixed sooner rather than later
    Last edited by nfodiz; May 4th, 2012 at 03:28 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  4. #4

    Default

    You should submit a bug report in jira. The forum is not the place for this.

  5. #5

    Default

    Why use SMB?

  6. #6
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    328

    Default

    Quote Originally Posted by influx2k View Post
    You should submit a bug report in jira. The forum is not the place for this.
    I had already filed a jira bug report (not that anything will happen with it)
    I disagree though that this should not have been posted here in the forums. Customers have a right to know about security holes in their systems and ways to work around the issue until a patch is released. Thanks for your valuable input though
    Last edited by nfodiz; May 5th, 2012 at 07:38 PM.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  7. #7
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    328

    Default

    Quote Originally Posted by Scirocca View Post
    Why use SMB?
    I don't but i'm sure a lot of people out there do.
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  8. #8
    Join Date
    Jul 2011
    Location
    Raleigh, NC
    Posts
    328

    Default

    What did I tell you

    Ami Ben-David [Boxee] added the Fix Version 'Support' to BOXEE-12893 - Boxee SMB security hole

    Why move this to support?!
    Boxee Box rev A1 fw 1.5.1.23734 wired NFS - Boxee Box rev A2 fw 1.5.1.23734 wireless NFS
    WD Mybook Live 3TB fw 02.11.09-053 NFS - Seagate BlackArmor NAS 110 1TB fw 1000.1211
    Asus RT-N66U fw 3.0.0.3.151 -> Trendnet TEG-S80G 8 port Gigabit switch
    WDTV gen1 - WDTV Live - WDTV Live Streaming

  9. #9
    Join Date
    Feb 2012
    Posts
    169

    Default

    My boxee does not access my computer at all, but uses a NAS(s) and each NAS has a boxee account which is set to read only. I don't see this a security threat on my network.
    Boxee is a good product - stop bashing it.
    If we all include our setup we could all help each other better
    My Equipment :- Boxee Box, Cat5e, Prosafe Gigabit Switch(s), Airport Extreme, WD ShareSpace, WD MybookWorlds, Qnap-TS412, Samsung PD59D550 3D TV, Panasonic BT270 (for optical audio)

  10. #10

    Default

    Quote Originally Posted by Umpa View Post
    Boxee is a good product - stop bashing it.
    If we all include our setup we could all help each other better
    Totally agree!

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •