D-Link Forums

The Graveyard - Products No Longer Supported => DNS-323 => D-Link Storage => Beta code! => Topic started by: Piotr on May 16, 2009, 06:38:18 AM

Title: BitTorrent (APKG) - security bug
Post by: Piotr on May 16, 2009, 06:38:18 AM
Hardware Version: A1
Firmware Version: 1.08 beta
Software Version (Easy Search): 4.7.0.0 beta

Harddrive 1: Western Digital 1TB (WD10EACS-00ZJB0)
Harddrive 2: empty

Problem Type:

□ Other: security bug

Problem Description:

Everybody can access BT without authentication using direct link.

Function Tested: apkg bittorrent 1.00 beta

Test Procedure (steps to reproduce):

Just type this address in your browser: http://<put_dns323_ip_here>/imodule/BitTorrent/webui/fe02.asp

e.g. http://10.10.10.2/imodule/BitTorrent/webui/fe02.asp

To access BT settings page just type: http://<put_dns323_ip_here>/imodule/BitTorrent/webui/btsettings.asp
Title: Re: BitTorrent (APKG) - security bug
Post by: sgip2000 on May 16, 2009, 06:33:38 PM
I can confirm this as well.
Title: Re: BitTorrent (APKG) - security bug
Post by: Banshee1971 on May 17, 2009, 06:18:58 PM
same result from me !
Title: Re: BitTorrent (APKG) - security bug
Post by: klein on May 17, 2009, 06:22:07 PM
same result for me!!!
Title: Re: BitTorrent (APKG) - security bug
Post by: Piotr on August 23, 2009, 09:00:54 AM
Bug still present in 1.08b05 firmware !!!

Only this time type:
http://<yourdnsip>/imodule/BitTorrent/webui/fe02.asp?flag_btui=1

The way D-Link treats security bugs is unacceptable >:(  (add flag_btui=1 to url and every user has easy access to your BT -> they can add their own torrents, delete your tasks etc.)
This is old bug (it was reported over a year ago -> 1.05 firmware) and it's still not properly fixed.
Title: Re: BitTorrent (APKG) - security bug
Post by: JohnnyDemonic on June 14, 2010, 02:37:51 PM
I actually like it this way, now I can view the whole torrent information without the screen being cut off.  Looks much better to me.  Your NAS should be behind a router and firewall already.  The security is fine as I see it.

I hope it stays this way for me at least.