ARCHIVE
LinuxMCE Forums
May 23, 2013, 10:30:57 am GMT-1 *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Rule #1 - Be Patient - Rule #2 - Don't ask when, if you don't contribute - Rule #3 - You have coding skills - LinuxMCE's small brother is available: http://www.agocontrol.com
 
   Home   Help Search Chat Login Register  
Pages: [1]
  Print  
Author Topic: Security questions on Remote Orbiters  (Read 1798 times)
archived
Hello, I'm new here

Posts: 0


View Profile
« on: October 12, 2005, 11:53:40 am »

I'm using a win XP Orbiter on my laptop and I arranged my external firewall in order to be able to connect to my hybrid through internet when I'm not at home.

So far so good. Connection is working fine and I'm able to get in touch with my hybrid from wherever I can get an internet connection for my laptop.

The first question is: how safe is this?
Is the traffic between orbiter and core/hybrid somehow encrypted?
Is it something that may be sniffed and tampered, or is it something like terminal services protocol?

Second question: what about access validation?
In principle if I perform a portscan on a bunch of public internet addresses and by chance I find some of them responding to the proper port, I could try to connect using my orbiter to a remote and unknown core/hybrid, maybe gaining access to their system. In fact when I connect to my hybrid no password is asked, just double click and I'm right in.
Ok, a device number has to be supplied in the conf file, but it is not a major problem to try to guess a real and working one ...

In this situation I think it wouldn't be that safe to allow remote orbiters to connect from internet, unless using a SSH tunnel.

Are things like this or am I missing something?

Regards
Marco
Logged
archived
Hello, I'm new here

Posts: 0


View Profile
« Reply #1 on: October 13, 2005, 07:50:01 am »

Hi Marco,

Orbiter wasn't designed to work remotely, because it communicates with the core using plain text, so it's not recommended to use it this way. However, in a future release, the communication between pluto devices will be encrypted with algorithms like blowfish, using a public key, randomly generated for each installation.

For now, the solution will be to use a ssh tunnel, like you said.

Regards,
Chris M.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Pluto provided a snapshot of their forums with approximately 5,000 posts in February, 2007 when LinuxMCE branched off. Browse those forum posts in the Archive section. Those posts have been included in the search engine and can be found with keyword searches.