Re: [SlimDevices: SqueezeCenter] Security reminder! Don't open your Squeezebox up to the internet.

2017-08-14 Thread Michael Herger

Having looked for myself, I was incredibly shocked as to how widespread
the problem is. I couldn't really believe people would do that.


Blame iPeng's popularity... many use iPeng to stream from their home 
while on the road, at the office etc.


And from the feedback I've had so far many still thought opening ports 
was _required_. Often one would have said "you need to open port 9000 on 
your server's firewall to make it accessible for the players" and users 
went and opened port 9000 on their routers.


--

Michael
___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Interesting map of Squeezebox users

2017-08-14 Thread w3wilkes

If you access the map directly can it be zoomed? From your post I don't
see anything at the Great Salt Lake. Salt Lake City is just east of what
shows as the white salt flats in the western USA.



Main system - Rock Solid with LMS 7.9 on WHS 2011 - 2 Duets and
Squeeseslave
Portable system - Rock solid with LMS 7.9 on Win10 Pro - 1 Duet and
Squeezeslave

w3wilkes's Profile: http://forums.slimdevices.com/member.php?userid=22973
View this thread: http://forums.slimdevices.com/showthread.php?t=107861

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Interesting map of Squeezebox users

2017-08-14 Thread Michael Herger

You've worked it out, but it's a sample based on instances that are
openly visable to the web at the moment (so assuming a guesstimate that
1% are open, then each dot would represent 100 players?).


What service have you been using? Shodan's maps look less detailed (at 
least those I've seen).


--

Michael
___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Security reminder! Don't open your Squeezebox up to the internet.

2017-08-14 Thread s2kiwi

mherger wrote: 
> 
> See my related posting:
> Michael

Yep - that post was top of mind for me when I posted this.

Having looked for myself, I was incredibly shocked as to how widespread
the problem is. I couldn't really believe people would do that.

I naively thought the level of knowledge required to open relevant
router ports would consequently limit it to people who know not to do it
in the first place!



s2kiwi's Profile: http://forums.slimdevices.com/member.php?userid=63950
View this thread: http://forums.slimdevices.com/showthread.php?t=107862

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Interesting map of Squeezebox users

2017-08-14 Thread s2kiwi

mherger wrote: 
> > I stumbled on a nice little map that shows the relative distribution
> of
> > people using squeezebox.
> 
> Interesting. Would you know how old this is and where it comes from? 
> What data it is based on?
> 
> -- 
> 
> Michael

You've worked it out, but it's a sample based on instances that are
openly visable to the web at the moment (so assuming a guesstimate that
1% are open, then each dot would represent 100 players?).

It should be pretty representative of usage around the world (as the %
of servers that are opened to the outside world would has no reason to
vary geographically).



s2kiwi's Profile: http://forums.slimdevices.com/member.php?userid=63950
View this thread: http://forums.slimdevices.com/showthread.php?t=107861

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Security reminder! Don't open your Squeezebox up to the internet.

2017-08-14 Thread Michael Herger

I was doing some basic checking on the security of my own system and I
was completely shocked to see how many people have opened their
squeezebox web front end to the internet.


Oh... I see where your map is coming from :-). See my related posting:

http://forums.slimdevices.com/showthread.php?107165-IMPORTANT-Stop-forwarding-your-LMS-ports-to-the-internet!


- a lot of those are controllable by anyone on the web!)-


And they are being exploited. We've had numerous reports about the kind 
of abuse described in my posting.


--

Michael
___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Interesting map of Squeezebox users

2017-08-14 Thread Michael Herger

I stumbled on a nice little map that shows the relative distribution of
people using squeezebox.


Interesting. Would you know how old this is and where it comes from? 
What data it is based on?


--

Michael
___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


[SlimDevices: SqueezeCenter] Security reminder! Don't open your Squeezebox up to the internet.

2017-08-14 Thread s2kiwi

Hi all,

I was doing some basic checking on the security of my own system and I
was completely shocked to see how many people have opened their
squeezebox web front end to the internet. 

If this is you, please turn this off ASAP. 

This is a major security hole (at a minimum I'm sure you wouldn't
appreciate someone turning your system on full volume at 3am).

-(and it you think people aren't really doing this, then 'here's the
scale of it'
(http://forums.slimdevices.com/showthread.php?107861-interesting-map-of-squeezebox-users)
- a lot of those are controllable by anyone on the web!)-



s2kiwi's Profile: http://forums.slimdevices.com/member.php?userid=63950
View this thread: http://forums.slimdevices.com/showthread.php?t=107862

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Performance using network drive for music storage? (LMS running in virtual machine)

2017-08-14 Thread itm

Many thanks for all the feedback. I think I'll try Jeff07971's
suggestion first and try a VMFS datastore first (I can't remember why I
chose RDM in the first place). At least I know I have the network
storage option as an acceptable alternative if the disk gets corrupted
again - subject to the caveat about scan times, of course.



itm's Profile: http://forums.slimdevices.com/member.php?userid=17437
View this thread: http://forums.slimdevices.com/showthread.php?t=107853

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Spotify playlist URL won't play in Favorite in LMS

2017-08-14 Thread karlek

wbree wrote: 
> Can I uninstall de Triode an Offical plug in of Spotify and still
> everything will be working as before?
> Wilco

Yes , you'll need only Spotty.





karlek's Profile: http://forums.slimdevices.com/member.php?userid=64321
View this thread: http://forums.slimdevices.com/showthread.php?t=107849

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Performance using network drive for music storage? (LMS running in virtual machine)

2017-08-14 Thread drmatt

As a network drive it makes zero difference to performance during
operation only during scan. Whether that scan is fast enough for you is
something only you can answer.. it won't change much as likely the drive
itself and the IOPs it supports is the limiting factor.


-Transcoded from Matt's brain by Tapatalk-



--
Hardware: 3x Touch, 1x Radio, 2x Receivers, 1 HP Microserver NAS with
Debian+LMS 7.9.0
Music: ~1300 CDs, as 450 GB of 16/44k FLACs. No less than 3x 24/44k
albums..

drmatt's Profile: http://forums.slimdevices.com/member.php?userid=59498
View this thread: http://forums.slimdevices.com/showthread.php?t=107853

___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter


Re: [SlimDevices: SqueezeCenter] Why Flash in LMS?

2017-08-14 Thread Michael Herger

Would this happen with the main web UI? Or only within settings, or some
specific plugin?


It is on the main web UI, thanks.


I checked the code again. Flash should _not_ be loaded in the normal web 
UI unless you enabled debugging in the skin (which I myself wouldn't 
even know any more how to do). The main UI uses a stripped down build of 
the ExtJS framework. Stripped down for performance reasons. Flash seems 
to be used in some charting module which we don't use. But only the 
Settings pages should even load that code (it just loads the full 
framework).


--

Michael
___
Squeezecenter mailing list
Squeezecenter@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/squeezecenter