• February 22, 2025, 03:39:43 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: http file access  (Read 6295 times)

dalbert

  • Guest
http file access
« on: October 05, 2008, 05:26:19 AM »

Is there a way to access shared volume(s) via http?

Is there a way to suppress http access to important files
that might pose a security risk: e.g. stuff in /etc like:
    /etc/passwd
    /etc/shadow
    /etc/ez-ipupdate.conf
    /etc/fstab
    /etc/mtab
    /etc/inittab
    /etc/hosts
    /etc/protocols
    /etc/services
Logged

fordem

  • Level 10 Member
  • *****
  • Posts: 2168
Re: http file access
« Reply #1 on: October 05, 2008, 10:38:06 AM »

I could be wrong on this ....

a) I believe if you downgrade to 1.04 those files will no longer be accessible
2) I believe http file access will be available in a future firmware release - there is an undocumented web page - http://<ip-address-of-DNS>/web/wfs_login.asp.

The way I heard it, preliminary code for the http file access was left in the 1.05 release leading to the insecurities that have upset many persons.
Logged
RAID1 is for disk redundancy - NOT data backup - don't confuse the two.

D-Link Multimedia

  • Poweruser
  • Level 7 Member
  • **
  • Posts: 1066
    • D-link Systems, Inc.
Re: http file access
« Reply #2 on: October 06, 2008, 09:33:47 AM »

Yes a preliminary HTTP file server was left in 1.05 however this was only on the DNS-323 and did not affect the DNS-321.

We are still looking into it.
Logged

fordem

  • Level 10 Member
  • *****
  • Posts: 2168
Re: http file access
« Reply #3 on: October 06, 2008, 12:16:35 PM »

Yes a preliminary HTTP file server was left in 1.05 however this was only on the DNS-323 and did not affect the DNS-321.

We are still looking into it.

Oops - forgot which forum I was in .... :-[
Logged
RAID1 is for disk redundancy - NOT data backup - don't confuse the two.