NextPVR Forums
  • ______
  • Home
  • New Posts
  • Wiki
  • Members
  • Help
  • Search
  • Register
  • Login
  • Home
  • Wiki
  • Members
  • Help
  • Search
NextPVR Forums Public Add-ons (3rd party plugins, utilities and skins) Old Stuff (Legacy) GB-PVR Support (legacy) v
« Previous 1 … 1092 1093 1094 1095 1096 … 1231 Next »
Running web admin through port 80...

 
  • 0 Vote(s) - 0 Average
Running web admin through port 80...
bgowland
Offline

Posting Freak

West Yorkshire, UK
Posts: 4,591
Threads: 386
Joined: Dec 2004
#11
2005-02-26, 12:40 AM
[b Wrote:Quote[/b] (chasef @ Feb. 25 2005,11:40)]Hey all,
 I wanna run my GB-PVR web admin through port 80.  What's the most secure way to do this?  Thanks!

Chase
If you're worried about portscanners out there discovering you've got something listening on port 80 then the only things you can do are as follows...

1. Make sure your router (assuming you have one) doesn't respond to port scans. This will prevent the 'probes' out there discovering it by chance.

2. Now you've announced on this forum that you want to run Web Admin on port 80 then point 1. above is actually meaningless (other than the fact that none of us know your domain name or IP address).

3. Assuming (from point 2.) that it is public knowledge that you are running Web Admin on port 80 and somebody malicious knows your domain name/IP address, then the only thing that you can do is change the username and password to be something REALLY REALLY obscure.

As a network sysadmin I know that little or nothing is ever really secure - it's just how difficult you make it to break and what the rewards would be for someone trying to do it.

In short, if your company won't allow you to connect from work using HTTP on any other ports and you're really worried about the security of your system, make sure you schedule your recordings before you leave home.  [Image: smile.gif]

Cheers,
Brian
capone
Offline

Posting Freak

Posts: 1,756
Threads: 190
Joined: Jan 2005
#12
2005-02-26, 05:09 PM
I'm assuming that you can't have a redirect page, either. Where you type in an address, and it redirects to an address w/ the port in it?

Btw, if you're not using a router at this point, and you're on a broadband connection, having 80 open is just one of your worries.
bgowland
Offline

Posting Freak

West Yorkshire, UK
Posts: 4,591
Threads: 386
Joined: Dec 2004
#13
2005-02-26, 05:33 PM
[b Wrote:Quote[/b] (chasef @ Feb. 25 2005,11:59)]The problem is, the ___ @ work think that I'll be jeopardizing network security if they don't lock off every port other than 80.
The only thing I could suggest is get friendly with your IT guys and, if the system allows it, asking them to put an address translation in on the company proxy/firewall server. We use MS ISA Server and I know it can be done with that. I've never tried it though.
UncleJohnsBand
Offline

Posting Freak

U.S.A.
Posts: 5,643
Threads: 258
Joined: Feb 2005
#14
2005-02-26, 06:25 PM
You could do the following.....

Get a dynamic DNS name for your work PC by using a free service such as DYNDNS.org. This will allow you to identify your work PC with a name and you won't need to worry about knowing the current IP address of you work PC. You will also need to load a dynamic updater to keep your PC's name in sync with your current IP address. I have been using DeeEnEs for about 4 years DeeEnEs

Set your router to forward port 80 to the PC running GBPVR.

Find a PC firewall that allows you you to filter on the host name rather than just IP. Norton Personal Fire Wall will do this....I believe there are others as well. Load this on the PC running GBPVR. In the settings allow access to port 80 only from your work PC name that you created above. Since you have now loaded a local firewall you may need to setup some other settings to allow GBPVR or the MVP 1000 to work correctly over your network(if you have one).

This setup limits access to port 80 from the outside to be only from your work PC. This coupled with the user id/password that the web interface requires should be strong enough security.

If you don't want to deal with the dynamic name thing you can stick with using your externally facing IP ranges instead.

Hope this helps.
Intel Core i7 @ 4.00GHz Skylake 14nm
ASUSTeK COMPUTER INC. Z170-DELUXE
Windows 10 Pro x64
PVR Software: NPVR 5.1.1
SiliconDust HDHomeRun HDHR5-4US Connect Quatro 4 Channel Tuner
Roku Ultra
2 PCH A-100's
Networker
Offline

Member

Posts: 188
Threads: 20
Joined: Feb 2005
#15
2005-02-27, 02:16 AM
Unless you don't mind doing some extra work, opening port 80 through to the GBPVR will simply open your machine up for any vulnerabilities the underlying web server software that is running.

You COULD do any number of things.. I tunnel through an SSH tunnel from work for all kinds of things to the house, RDP, GBPVR, IMAP, SMTP, HTTP, etc. So you if are willing to get SSH running on your windows box (assuming you have no Linux boxes) or you might be able to find a port of Stunnel to do SSL (secure socket layer - https). Using Stunnel you could connect to your GBPVR with 443 (which should be open through your work firewall, that's how I configure our firewall - oh did I mention that I do Network Security for a living [Image: rock.gif] ..


Edit - I just did some searches to make sure about the stunnel, if you go to Stunnel windows downloads, there is a OpenSSH project, it's not up2date but easy to setup compared to Cygwin


John



//// GBPVR \\\\
Abit
2.8GHz Proc
1 GB RAM
80 GB SATA sys volume
200 GB SATA Video Storage
3x PVR150s
2x MVPs - 100Mbps LAN attached

/// Music Server \\\
CentOS Samba Server
(moving to Video Server to be MediaServer Smile )

/// Video Server \\\
FreeNAS
1TB total storage
<to be renamed MediaServer>


Plugins: Xrecord, Video Archiver, DVD2MPG, My M.V.P., Weather, Theater, Rectracker
« Next Oldest | Next Newest »

Users browsing this thread: 1 Guest(s)

Pages (2): « Previous 1 2


Possibly Related Threads…
Thread Author Replies Views Last Post
  Running comskip at a scheduled time? gonzo90017 4 2,175 2010-05-19, 06:09 AM
Last Post: pBS
  Lost in a sea of Acronyms. Confusion is running amuck in my head Talcum 8 3,043 2010-04-12, 08:07 AM
Last Post: ga_mueller
  serial port IR Blaster twinfrey 1 1,865 2010-03-07, 10:49 PM
Last Post: markbb1
  webadmin not running? aneez 7 2,821 2010-02-24, 07:30 PM
Last Post: aneez
  File conversions not running luttrell1962 2 1,632 2010-02-06, 06:23 AM
Last Post: luttrell1962
  NVIDIA 6200 Settings (running slow/choppy) Atrus 7 6,044 2010-01-29, 12:13 AM
Last Post: Zeno110
  Crash when running pvxr2 to import xml file carpeVideo 5 2,616 2010-01-07, 02:40 PM
Last Post: carpeVideo
  Multiple audio decoders running liteswap 2 1,516 2009-11-12, 11:37 PM
Last Post: liteswap
  GB-PVR running in full screen minimizes when clicking on primary screen quinting 0 1,177 2009-10-02, 09:37 PM
Last Post: quinting
  Web Admin doesn't ask for id/password nitro888 1 1,368 2009-09-30, 08:37 PM
Last Post: HtV

  • View a Printable Version
  • Subscribe to this thread
Forum Jump:

© Designed by D&D, modified by NextPVR - Powered by MyBB

Linear Mode
Threaded Mode