bottleneck
Choose style:

Author Topic: Disable WebUI access from WAN  (Read 7693 times)

0 Members and 1 Guest are viewing this topic.

Offline mechcozmo

  • Backer
  • *
  • Posts: 5
  • Thanks: 0
  • Registered : 01/10/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Disable WebUI access from WAN
« on: October 01, 2014, 02:17:56 pm »
I was troubleshooting VPN access (which seems broken, incidentally...) and I discovered that the web UI is accessible from the WAN IP.

This should be disabled by default (and only optionally enabled via the UI) for security purposes, especially as the login page is not protected via HTTPS nor any kind of rate-limiting against brute forcing of passwords...

Offline matt

  • Backer
  • *
  • Posts: 151
  • Thanks: 1
  • Registered : 26/08/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Re: Disable WebUI access from WAN
« Reply #1 on: October 01, 2014, 06:27:50 pm »
Did you open port 80 on the firewall? I had to do so explicitly to get access to lighttpd remotely. Admittedly I'm still running R065.

Offline eldaria

  • Kickstarter Developer
  • *
  • Posts: 313
  • Thanks: 1
  • Registered : 26/07/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Re: Disable WebUI access from WAN
« Reply #2 on: October 02, 2014, 02:45:06 am »
By default the WAN port is closed for everything and it has been like this since the earliest Dev and Beta versions went out.
So if you could access the WebUI then you must have enabled this by misstake.
However unless you have another firewall and the Almond+ is not directly exposed to Internet, then I would recommend you turn that off as soon as possible, you should never have anything open unless you really have a need for it, and can monitor for intrusions. I would not even want to have such a service running on a standard port such as port 80.

LGNilsson

  • Guest
Re: Disable WebUI access from WAN
« Reply #3 on: October 02, 2014, 03:24:47 am »
Have a look in the LCD UI under Settings, WAN Access. Web Access (Port 80) should be disabled.

Offline mechcozmo

  • Backer
  • *
  • Posts: 5
  • Thanks: 0
  • Registered : 01/10/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Re: Disable WebUI access from WAN
« Reply #4 on: October 04, 2014, 03:18:48 am »
Have a look in the LCD UI under Settings, WAN Access. Web Access (Port 80) should be disabled.

Has no effect.

At first, I thought, "Maybe I'm just not understanding the UI?  Did I accidentally flip it on?"  But surely, greyed out means "not selected".  Just to be sure (and maybe the UI wasn't matching the underlying system?), I tried it both ways.  Nothing.  Still accessible from the WAN.

 

Page created in 0.092 seconds with 19 queries.