Dear AMAHI Team,
first of all: Congratulation to this simple to install home server system!
But to be frank I am concerned if Amahi is a safe and secure system?
There have been some issues today that cut my trust a bit.
Issue 1:
I installed AjaXplorer as user A. When I logged into my HDA as user B AjaXplorer gave me access to all files even to those I had no permission to (e.g. files of user A).
Issue 2:
On my HDA machine each user can browse through all linux directories and system files. Shouldn't this be possible only for the root?
I know AMAHI stuff will not be interested in my files and probably all that are worries of of a newbie who is not very experienced in Linux.
Maybe you can give me back my confidence
And a question: Do I have to modify the firewall of my HDA? I noticed that it is deactivated.
Thanks a lot.
Alf
security concerns from a new user
security concerns from a new user
My HDA: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz on MSI board, 8GB RAM, 1TBx2+3TBx1
Re: security concerns from a new user
as far as issue 2 goes:
depending on certain permissions you can look everywhere in a unix/linux system. that doesn't mean you can modify the things you can see though. home directories are usually more restrictive, depending on the permissions scheme. this is perfectly normal for a unix/linux operating system. I think it encourages users to look around and understand what's happening, even though they can't modify/mess up the system.
depending on certain permissions you can look everywhere in a unix/linux system. that doesn't mean you can modify the things you can see though. home directories are usually more restrictive, depending on the permissions scheme. this is perfectly normal for a unix/linux operating system. I think it encourages users to look around and understand what's happening, even though they can't modify/mess up the system.
echo '16i[q]sa[ln0=aln100%Pln100/snlbx]sbA0D2173656C7572206968616D41snlbxq' | dc
Galileo - HP Proliant ML110 G6 quad core Xeon 2.4GHz, 4GB RAM, 2x750GB RAID1 + 2x1TB RAID1 HDD
Galileo - HP Proliant ML110 G6 quad core Xeon 2.4GHz, 4GB RAM, 2x750GB RAID1 + 2x1TB RAID1 HDD
Re: security concerns from a new user
So, in loss of answers of this question, it might seems that security is not a prioritised task for the Amahi.
I is/was interested in this homeserver thing, it is/was tempting. I have used several Linux-based firewall / all-in-one servers for several years now, the last 3-4 years with ClarkConnect/ClearOS. Pretty happy with it, very easy to make a secure enviroment for both kids and adults, easy to block the bad sites, restrict peer-to-peer downloads, and also with mailserver, antivirus, antiphishing, intrution prevention, webserver, and alot more. But, it is rather complicated to get up'n'running with other software. No plugins there! You got to have a more than basic understanding of linux to make all you want to work properly. For this I dont have much time. The Amahi looked like the solution for me, really!
But so far Ive not found any specific info regarding Amahi and security? Is it possible to have a advanced firewall at all? Filters? Access control?
Pleas convince me to select Amahi
I is/was interested in this homeserver thing, it is/was tempting. I have used several Linux-based firewall / all-in-one servers for several years now, the last 3-4 years with ClarkConnect/ClearOS. Pretty happy with it, very easy to make a secure enviroment for both kids and adults, easy to block the bad sites, restrict peer-to-peer downloads, and also with mailserver, antivirus, antiphishing, intrution prevention, webserver, and alot more. But, it is rather complicated to get up'n'running with other software. No plugins there! You got to have a more than basic understanding of linux to make all you want to work properly. For this I dont have much time. The Amahi looked like the solution for me, really!
But so far Ive not found any specific info regarding Amahi and security? Is it possible to have a advanced firewall at all? Filters? Access control?
Pleas convince me to select Amahi

-
- Posts: 124
- Joined: Mon Jun 29, 2009 9:41 am
- Location: Hazel Park, MI
- Contact:
Re: security concerns from a new user
Amahi was never intended to be out on the internet, it is secure if left and used as intended being a home server. For access from the outside to get to/use your apps I would suggest using VPN instead of having it on the internet.
Security is always a concern with Amahi, but how do we deal with all the possible security issues with all the apps? This is why it's best left in a intranet and not on the internet.
Security is always a concern with Amahi, but how do we deal with all the possible security issues with all the apps? This is why it's best left in a intranet and not on the internet.
Testmaster Manager
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives
Re: security concerns from a new user
OK. Thanks for the info. Nice to know... 

-
- Posts: 124
- Joined: Mon Jun 29, 2009 9:41 am
- Location: Hazel Park, MI
- Contact:
Re: security concerns from a new user
Maybe in the future we will add more features, right now the team is small. If you are interested in helping in some way please let use know
Testmaster Manager
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives
Amahi HDA Custom Dual 2.7 GHz, 3 GB DDR2 (667MHz) Ram, 80GB HDD for OS + 1TB and 320GB HDD for Share Drives
Re: security concerns from a new user
For my case I dont think I could help so much. Im not a Linux-head, far fromMaybe in the future we will add more features, right now the team is small. If you are interested in helping in some way please let use know

Sorry Im not able to help further!
Regards
Bent, Norway
Who is online
Users browsing this forum: Google [Bot] and 8 guests