View Single Post
Posts: 13 | Thanked: 12 times | Joined on Feb 2012 @ Czech Republic
#41
Originally Posted by helex View Post
Ooooh, well...
I wanted to avoid this. It would make it necessary to add encryption to my application to make storing of the password possible and secure.......
I understand what do you talking about in your last post..... I have pretty good Linux knowledge, I use it as my primary operating system at home, also for my work. First thing I have done was to set root password for dreambox via telnet :-) I also share your opinion that it is not so good to route http web interface outside of home network via router, since http authentication is only basic method and not sufficient to secure dreambox from attack....You can bind web interface service to non-standard TCP port (as I actually have) but even if one enable http authentication, it is done via plain http protocol (no https), so password is visible in unencrypted plain form and therefore to be caught by anyone "in the middle" very simply... You are right that it should be used only on secured local lan. So as it seems I have to live without this function Maybe in the future, who knows... Anyway, it is a good work, I will evaluate it on Ovi store

Only for info, I tried to clear root password temporarily for dreambox root account, but it doesn't help...the challenge to give a root password (though empty) still shows up for
Code:
http://<IP>/root/tmp/screenshot.jpg
with http authentication disabled...I do not understand why.
 

The Following User Says Thank You to sanmob For This Useful Post: