• February 24, 2025, 01:06:14 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: uauthorized access from User Nobody! after firmware 2,02  (Read 10345 times)

resch60

  • Level 1 Member
  • *
  • Posts: 4
uauthorized access from User Nobody! after firmware 2,02
« on: February 28, 2012, 10:43:47 PM »

i saw here in the forum that the firmware 2.02b1 the problem with the user Nobody fix.

so i download it the update from the

http://www.dlink.ca/products/?pid=DNS-320

page..

i still have the problem that someone is login in on my nas every day! I am here in canada! And i can't change my IP.. So the person is just looking around but i don't like that i turned the ftp down for 2 weeks but after i turn it on ! it happen again after 1 day...


Did i install the wrong firmware??

Everything else is great ! just that little problem.. thx for help
Logged

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #1 on: February 28, 2012, 11:16:18 PM »

After upgrading to firmware 2.02 (aka 2.02b1) does the NAS webUI allow login using nobody username? If it allow, did it prompt for password?

When I was still using firmware 2.00, I simply changed the nobody password via remote shell after I came to know about this issue.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]

ChrisSutherland

  • Level 1 Member
  • *
  • Posts: 7
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #2 on: February 29, 2012, 11:24:31 AM »

After upgrading to firmware 2.02 (aka 2.02b1) does the NAS webUI allow login using nobody username? If it allow, did it prompt for password?

When I was still using firmware 2.00, I simply changed the nobody password via remote shell after I came to know about this issue.

could you share how this is done please? I've logged into the web UI, and have no users listed under that name? by creating one called "nobody", does it override the current "nobody" user?

Just checked my logs and I have "nobody" also logging in, slightly worrying.
Logged

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #3 on: February 29, 2012, 05:51:34 PM »

could you share how this is done please? I've logged into the web UI, and have no users listed under that name? by creating one called "nobody", does it override the current "nobody" user?

Just checked my logs and I have "nobody" also logging in, slightly worrying.
So am I right to said that it's still not fix in 2.02?

What I did as stated earlier was to remote into the NAS via telnet/ssh (FFP is needed) and use the command passwd nobody and assign a password to it.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]

ChrisSutherland

  • Level 1 Member
  • *
  • Posts: 7
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #4 on: March 01, 2012, 12:57:02 AM »

remote into the NAS via telnet/ssh (FFP is needed)

Sorry but this means very little to me. I don't understand.
Logged

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #5 on: March 01, 2012, 05:16:42 AM »

Sorry but this means very little to me. I don't understand.

Which part, remote shell access or FFP? FFP = Fonz Fun_plug is needed because DNS-320 doesn't provide shell access.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]

resch60

  • Level 1 Member
  • *
  • Posts: 4
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #6 on: March 01, 2012, 06:57:01 AM »

thx i will just change the password than!
Logged

cable2

  • Level 3 Member
  • ***
  • Posts: 299
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #7 on: March 01, 2012, 07:02:24 AM »

Hi Chris,
Albert is referring to the linux fonzfun_plug install which is, at this time, a bit over your head.  Given where you are at, how about simply adding "nobody" or "Nobody" or both as user(s) with rather secure passwords and then use the "deny access" as rights on top of this.  You could do this quickly with the 320's GUI without any further knowledge and then just keep checking the logs to see if you are still being breached.  Good luck
Logged

resch60

  • Level 1 Member
  • *
  • Posts: 4
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #8 on: March 01, 2012, 05:22:58 PM »

no that did not work! i tried that already, i can't create a user Nobody or nobody!


How do i play the ffp on the nas?? with out the access ??

« Last Edit: March 01, 2012, 05:58:02 PM by resch60 »
Logged

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #9 on: March 01, 2012, 09:16:26 PM »

The user account nobody already exist by default and is now flagged as "invalid users" in samba conf file (in v2.02). What this meant is that it's not possible to login using this user account even if there is no password assigned to it. I have re-confirm this so there shouldn't be any undue worry over this issue.

But do take note that logs entries (recent activities) doesn't capture invalid login attempt from nobody so if your show otherwise then something is not right.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]

resch60

  • Level 1 Member
  • *
  • Posts: 4
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #10 on: March 01, 2012, 10:30:37 PM »

hmm i just see that nobody logs in but is not downloading....

ok i deleted the user Nobody from the "/home" so it just shows....

Problem gone... bot you said something from a samba server...
 

i will open a new topic  for that
« Last Edit: March 01, 2012, 10:53:46 PM by resch60 »
Logged

albert

  • Level 5 Member
  • *****
  • Posts: 510
    • SoHo NAS Forum
Re: uauthorized access from User Nobody! after firmware 2,02
« Reply #11 on: March 01, 2012, 10:33:38 PM »

hmm i just see that nobody logs in but is not downloading....

So, are able to login using nobody account? Leave password as blank.
Logged
D-Link DNS-320 rev A1 (FW: 2.05) [FFP-0.7]
PCI NAS-01G (FW: Encore ENNHD-1000 4.10)
PCI NAS-01G (FW: OpenNAS 1.9]