• May 23, 2024, 12:58:30 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: BitTorrent (APKG) - security bug  (Read 7969 times)

Piotr

  • Level 2 Member
  • **
  • Posts: 59
BitTorrent (APKG) - security bug
« on: May 16, 2009, 06:38:18 AM »

Hardware Version: A1
Firmware Version: 1.08 beta
Software Version (Easy Search): 4.7.0.0 beta

Harddrive 1: Western Digital 1TB (WD10EACS-00ZJB0)
Harddrive 2: empty

Problem Type:

□ Other: security bug

Problem Description:

Everybody can access BT without authentication using direct link.

Function Tested: apkg bittorrent 1.00 beta

Test Procedure (steps to reproduce):

Just type this address in your browser: http://<put_dns323_ip_here>/imodule/BitTorrent/webui/fe02.asp

e.g. http://10.10.10.2/imodule/BitTorrent/webui/fe02.asp

To access BT settings page just type: http://<put_dns323_ip_here>/imodule/BitTorrent/webui/btsettings.asp
« Last Edit: May 16, 2009, 06:40:59 AM by Piotr »
Logged
DIR-655 H/W A2   FW 1.30EU    *    DSL-320B H/W D1  FW EU_1.21    *    DNS-323 H/W A1   FW 1.08b05    *    DWA-645 H/W A1

sgip2000

  • Level 2 Member
  • **
  • Posts: 77
Re: BitTorrent (APKG) - security bug
« Reply #1 on: May 16, 2009, 06:33:38 PM »

I can confirm this as well.
Logged

Banshee1971

  • Level 3 Member
  • ***
  • Posts: 105
Re: BitTorrent (APKG) - security bug
« Reply #2 on: May 17, 2009, 06:18:58 PM »

same result from me !
Logged

klein

  • Level 3 Member
  • ***
  • Posts: 129
Re: BitTorrent (APKG) - security bug
« Reply #3 on: May 17, 2009, 06:22:07 PM »

same result for me!!!
Logged

Piotr

  • Level 2 Member
  • **
  • Posts: 59
Re: BitTorrent (APKG) - security bug
« Reply #4 on: August 23, 2009, 09:00:54 AM »

Bug still present in 1.08b05 firmware !!!

Only this time type:
http://<yourdnsip>/imodule/BitTorrent/webui/fe02.asp?flag_btui=1

The way D-Link treats security bugs is unacceptable >:(  (add flag_btui=1 to url and every user has easy access to your BT -> they can add their own torrents, delete your tasks etc.)
This is old bug (it was reported over a year ago -> 1.05 firmware) and it's still not properly fixed.
Logged
DIR-655 H/W A2   FW 1.30EU    *    DSL-320B H/W D1  FW EU_1.21    *    DNS-323 H/W A1   FW 1.08b05    *    DWA-645 H/W A1

JohnnyDemonic

  • Level 1 Member
  • *
  • Posts: 20
Re: BitTorrent (APKG) - security bug
« Reply #5 on: June 14, 2010, 02:37:51 PM »

I actually like it this way, now I can view the whole torrent information without the screen being cut off.  Looks much better to me.  Your NAS should be behind a router and firewall already.  The security is fine as I see it.

I hope it stays this way for me at least.
Logged