security concerns from a new user

User avatar
cpg
Administrator
Posts: 2618
Joined: Wed Dec 03, 2008 7:40 am
Contact:

security concerns from a new user

Postby cpg » Fri Jan 08, 2010 3:57 am

Dear AMAHI Team,

first of all: Congratulation to this simple to install home server system!

But to be frank I am concerned if Amahi is a safe and secure system?
There have been some issues today that cut my trust a bit.

Issue 1:
I installed AjaXplorer as user A. When I logged into my HDA as user B AjaXplorer gave me access to all files even to those I had no permission to (e.g. files of user A).

Issue 2:
On my HDA machine each user can browse through all linux directories and system files. Shouldn't this be possible only for the root?

I know AMAHI stuff will not be interested in my files and probably all that are worries of of a newbie who is not very experienced in Linux.

Maybe you can give me back my confidence :-)

And a question: Do I have to modify the firewall of my HDA? I noticed that it is deactivated.

Thanks a lot.

Alf
My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 8GB RAM, 1TBx2+3TBx1

User avatar
moredruid
Expert
Posts: 791
Joined: Tue Jan 20, 2009 1:33 am
Location: Netherlands
Contact:

Re: security concerns from a new user

Postby moredruid » Sun Jan 10, 2010 1:22 pm

as far as issue 2 goes:
depending on certain permissions you can look everywhere in a unix/linux system. that doesn't mean you can modify the things you can see though. home directories are usually more restrictive, depending on the permissions scheme. this is perfectly normal for a unix/linux operating system. I think it encourages users to look around and understand what's happening, even though they can't modify/mess up the system.
echo '16i[q]sa[ln0=aln100%Pln100/snlbx]sbA0D2173656C7572206968616D41snlbxq' | dc
Galileo - HP Proliant ML110 G6 quad core Xeon 2.4GHz, 4GB RAM, 2x750GB RAID1 + 2x1TB RAID1 HDD

fikse
Posts: 3
Joined: Sat Jan 16, 2010 2:41 am

Re: security concerns from a new user

Postby fikse » Sat Jan 16, 2010 2:53 am

So, in loss of answers of this question, it might seems that security is not a prioritised task for the Amahi.
I is/was interested in this homeserver thing, it is/was tempting. I have used several Linux-based firewall / all-in-one servers for several years now, the last 3-4 years with ClarkConnect/ClearOS. Pretty happy with it, very easy to make a secure enviroment for both kids and adults, easy to block the bad sites, restrict peer-to-peer downloads, and also with mailserver, antivirus, antiphishing, intrution prevention, webserver, and alot more. But, it is rather complicated to get up'n'running with other software. No plugins there! You got to have a more than basic understanding of linux to make all you want to work properly. For this I dont have much time. The Amahi looked like the solution for me, really!
But so far Ive not found any specific info regarding Amahi and security? Is it possible to have a advanced firewall at all? Filters? Access control?

Pleas convince me to select Amahi :D

rampage537
Posts: 124
Joined: Mon Jun 29, 2009 9:41 am
Location: Hazel Park, MI
Contact:

Re: security concerns from a new user

Postby rampage537 » Tue Jan 19, 2010 9:56 am

Amahi was never intended to be out on the internet, it is secure if left and used as intended being a home server. For access from the outside to get to/use your apps I would suggest using VPN instead of having it on the internet.
Security is always a concern with Amahi, but how do we deal with all the possible security issues with all the apps? This is why it's best left in a intranet and not on the internet.
Testmaster Manager
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives

fikse
Posts: 3
Joined: Sat Jan 16, 2010 2:41 am

Re: security concerns from a new user

Postby fikse » Tue Jan 19, 2010 10:32 am

OK. Thanks for the info. Nice to know... ;)

rampage537
Posts: 124
Joined: Mon Jun 29, 2009 9:41 am
Location: Hazel Park, MI
Contact:

Re: security concerns from a new user

Postby rampage537 » Tue Jan 19, 2010 10:37 am

Maybe in the future we will add more features, right now the team is small. If you are interested in helping in some way please let use know
Testmaster Manager
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives

fikse
Posts: 3
Joined: Sat Jan 16, 2010 2:41 am

Re: security concerns from a new user

Postby fikse » Tue Jan 19, 2010 11:17 am

Maybe in the future we will add more features, right now the team is small. If you are interested in helping in some way please let use know
For my case I dont think I could help so much. Im not a Linux-head, far from :roll: I can only think of a box, with a combination of yours fantastic Amahi, and i.e. ClearOS/ClarkConnect, or other opensource firewall solution. I know several would say that its no good to combine a firewall with several applications like web/email, but AFAIK the CO/CC is pretty solid. The CO/CC is also based on installable modules, but its maingoal is not a homeserver, more to act as a all-in-one solution for companys and home. Since its based on opensource Linux distro (CentOS/RH), its possible to let it do whatever you want, but then you have to be more than average competent in programming.

Sorry Im not able to help further!

Regards
Bent, Norway

Who is online

Users browsing this forum: No registered users and 45 guests