Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £129! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £179! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[VU+ Solo2] 403.6 IP address rejected

imish

New member
Joined
Sep 4, 2013
Messages
622
Reaction score
0
Points
0
Very surprised that this has happened to our VU box which has been rock solid for over 2 years.

Remotely upgraded this using CLI - now when I try and connect to the box using the web interface I get the following message

Forbidden

403.6 IP address rejected


tried a reset - no difference.
tried updating again using CLI - no difference

Any ideas of how I can troubleshoot as physical access to the box will have to wait.
 
Last edited:
Something very similar was reported on the OpenPLi forum a couple of days ago, so it's probably being looked at - could be wrong though.
 
I have just opened a GitHub issue here

Code:
https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/467
 
Won't fix: This is the desired behaviour.
You can no longer have the OWIF wide open to the net without at least a login/password.

Gesendet von meinem Siemens C25 mit Tapatalk
 
No login -> local use only.

Gesendet von meinem Siemens C25 mit Tapatalk
 
Mine isn't wide open. I access via VPN on a separate subnet.
 
init 4

Edit /etc/enigma2/settings
Within the OWIF settings add a setting
Code:
config.OpenWebif.vpn_access=True

init 3

Gesendet von meinem Siemens C25 mit Tapatalk
 
Last edited by a moderator:
Please let me know if you managed it.
If not, I can be somewhat more detailed later when I am back at a PC.

Gesendet von meinem Siemens C25 mit Tapatalk
 
init 4

Edit /etc/enigma2/settings
Within the OWIF settings add a setting
Blah.vpn_access=True
"Blah" = just how the other openwebif settings look like.

Init 3

Gesendet von meinem Siemens C25 mit Tapatalk

Tried this - couldn't upload the modified settings file so didn't work for me.

Does this new setting lock down all network access from different subnets inc FTP transfer?



Sent from my iPhone using Tapatalk
 
No, it just affects OWIF access.
You can still access it using ssh tunneling or when you are back home.

Gesendet von meinem Siemens C25 mit Tapatalk
 
No, it just affects OWIF access.
You can still access it using ssh tunneling or when you are back home.

Gesendet von meinem Siemens C25 mit Tapatalk

Worked around the FTP issue. (couldn't upload a new settings file via FTP - kept timing out).

FTP's a new settings_2 file
Deleted the original one
renamed the new one

Working now - Thanks for your help :thumbsup:
 
Last edited:
Workaround using only shell commands (For users that just use a VPN with different subnet, it won't restore "wide open access"):

Code:
init 4
echo config.OpenWebif.vpn_access=true >> /etc/enigma2/settings
init 3
 
Question - have they now resolved the security around the actual stream - does that now work when user credentials are switched on?




Sent from my iPhone using Tapatalk
 
You mean inside Web TV?
Or plain streaming links?
Transcoded or untranscoded?

Gesendet von meinem Siemens C25 mit Tapatalk
 
You mean inside Web TV?
Or plain streaming links?
Transcoded or untranscoded?

Gesendet von meinem Siemens C25 mit Tapatalk

Assuming that this feature was put in place to secure the box from external attacks when port forwarding. My natural question then is whether the security extends to the streams else I fail to see the point.




Sent from my iPhone using Tapatalk
 
Assuming that this feature was put in place to secure the box from external attacks when port forwarding. My natural question then is whether the security extends to the streams else I fail to see the point.
Yes and no, but more like "no" in Open...

There are multiple kinds of streaming providers:
  • Dream's streamproxy, also used by VuPlus incl. VTi and probably Black Hole Images, handles untranscoded streaming only (Port 8001)
    This variant also exists on our (OpenViX, OpenATV, OpenHDF, OpenBH, ...) feeds, just "opkg install streamproxy".

    It auths through the Web-Interface running on the same box, which will in most cases be OWIF but if you uninstall OWIF and install Dream's Web-Interface the latter will take the job.
    Auth settings for streaming have been somewhat weakened though, it will still allow external logins or even no auth at all, depending on what you configure for streaming auth inside OWIF.

    The difference is: "Attackers" can only "steal" tuners from you through the streaming port. Worse enough, but that's about it. Your personal risk.
    Through OWIF itself, they could install malicious packages in your box and take ownership of it. A risk for all of us, if the taken machine gets used for spam relaying or DDoS attacks.
  • "PLi streaming" (Streaming inside E2) on port 8001 incl. "multitranscoding" on machines using port 8001 not only for streaming but for transcoding too.
    PLi has integrated a functionally reduced streamproxy inside E2 code in 2011/2012 and all other Open... distros have merged these changes.
    It's now the default in all Open... images, incl. OpenViX, OpenATV, OpenHDF, ...

    It doesn't auth through OWIF (or Dream Webif) at all and thus doesn't honor any of its settings. Nothing OWIF devs can do about this.
    Auth for this variant of streaming isn't set up inside OWIF but somewhere inside E2 ("Extras" settings or something like that) and is limited to "yes" or "no".
    Sadly, some vendors (skylake (Mut@nt and AX Quadbox), Xtrend, ...) have integrated their transcoding here.

    As mentioned above, you can still revert to the streamproxy variant by installing the package "streamproxy" in OpenATV, OpenViX, ...
    But note that "streamproxy" can not handle transcoding, so streaming on machines using "multitranscoding" on port 8001 will lose transcoding capabilities.
  • transtreamproxy (Transcoding on separate port, in most cases 8002)
    This is VuPlus' and Dags' (Edision, iQon Force, ...) way of implementing transcoding. "transtreamproxy" is based on "streamproxy" code, extended for transcoding support on these machines.

    This way of transcoding also uses auth through OWIF (or Dream Webif), so that the settings from OWIF or Dream Webif will apply.

So in short:
You can safely install the package "streamproxy" on all machines
- not doing transcoding at all
- using a separate transcoding proxy on a different port (8002)
to get auth through OWIF with all its settings on both, streaming and transcoding.

Machines with multitranscoding (streaming and transcoding on the same port) can not use the package streamproxy as it would break transcoding.
In this case, E2 settings for streaming auth will apply and they are functionally limited.
 
General suggestion:

"Joe Average" is advised not to open OWIF (or Dream Webif), ftp, telnet, streaming (and transcoding) by using port-forwarding at all.
Note that HTTP, ftp and telnet transfer plain passwords, unencrypted!, over the internet!

Instead you should use a VPN, many routers (e.g. AVM Fritz!Box) already offer this feature itself.
If your router doesn't offer it, your NAS might and if that doesn't, you can use OpenVPN on the E2 box itself (Which is probably the hardest variant to set up).


Once you are logged into your LAN using a VPN, you can use any service on any machine in your home network just as if you were at home.
If there are no other reasons (like children) for setting logins, you can then even save the hassle of logins entrirely, just keep your VPN credentials/key files safe.


Another safe variant is the ssh access of your box using key pairs.

Execute the following commands to generate and install a key pair on your E2 box:
Code:
dropbearkey -t rsa -f ~/.ssh/id_rsa
dropbearkey -y -f ~/.ssh/id_rsa | grep "^ssh-rsa " >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/*
chmod 700 ~/.ssh
chmod 700 ~

You should now be able to login to your box using the private key file id_rsa located in /home/root/.ssh of your box (See the instructions of your ssh client on how to use key auth).

If this succeeds, make the content of /etc/default/dropbear read
Code:
DROPBEAR_EXTRA_ARGS="-s"
This will disallow password logins for ssh entirely (let alone logins with empty passwords, which is the default for all oe-a images) (The only way to recover from ssh login problems would then be telnet).

You can transfer the file /home/root/authorized_keys to other boxes too, to use the same key file for multiple boxes, but make sure to adjust the file rights after copy:
Code:
chmod 600 ~/.ssh/*
chmod 700 ~/.ssh
chmod 700 ~

With ssh, you have everything you need:
  • ssh gives you shell access, just like telnet but secure (when using key auth)
  • ssh gives you file access, either using scp (secure copy) or sftp (FileZilla supports sftp, you can access your box' files just like you could using ftp).
  • ssh allows to tunnel ports from the remote machine (= your E2 box) to your local machine.
    You can for example tunnel port 80 of your E2 box to port 80 of your smartphone and port 8001 of your E2 box to port 8001 of your smartphone.
    As long as the tunnel is established, you can login to your E2 webif using address "http://localhost" on your smartphone and use streaming, just as if your smartphone would be your E2 box.

The free app "ConnectBot" (https://play.google.com/store/apps/details?id=org.connectbot) has the necessary capabilities of using key auth and port tunneling on Android.

Personally, I use VPNs for machines which I permanently maintain and ssh tunneling for machines that I sometimes maintain.
 
Thanks for the informative post.


Sent from my iPhone using Tapatalk
 

OpenViX Feeds Status

Back
Top