FAQ  •  Register  •  Login

Serviio Console Access Restriction

<<

cruisinforgold

Serviio newbie

Posts: 7

Joined: Wed Feb 05, 2014 4:21 am

Post Thu Mar 10, 2022 2:46 pm

Serviio Console Access Restriction

How to protect serviio console external access on Synology.

I'm running latest Serviio on Synology DSM7.0.1 using Docker.

I have a domain name that I use to access the Synology. For the console I connect [domainname:23423/console]. This is apparently open to the world to access. I have a User account specified for Mediabrowser access that challenges the user with name and password.

Is there any way to restrict the console to a specified user name and password?

Thanks for any assistance.
Panasonic TC-L55WT60; Win x64 on Asus z87 Deluxe/Quad i7-4770K: Synology DS1515+; DSM 7.0.1;10
<<

atc98092

User avatar

DLNA master

Posts: 5212

Joined: Fri Aug 17, 2012 10:22 pm

Location: Washington (the state)

Post Thu Mar 10, 2022 8:55 pm

Re: Serviio Console Access Restriction

No, there is no authentication for the Serviio console. But it's not open to the world. It is open to your network, but unless you set up port forwarding to your console in your network firewall, it can't be reached from elsewhere. And of course MediaBrowser isn't available to the Internet side unless you also port forward it as well. So if port 23423 is not forwarded in your firewall, it's protected from the Internet at large.
Dan

LG NANO85 4K TV, Samsung JU7100 4K TV, Sony BDP-S3500, Sharp 4K Roku TV, Insignia Roku TV, Roku Ultra, Premiere and Stick, Nvidia Shield, Yamaha RX-V583 AVR.
Primary server: Intel i5-6400, 16 gig ram, Windows 10 Pro, 22 TB hard drive space | Test server Windows 10 Pro, AMD Phenom II X4 965, 8 gig ram

HOWTO: Enable debug logging HOWTO: Identify media file contents
<<

nobody511

Serviio newbie

Posts: 8

Joined: Thu Feb 09, 2023 3:09 pm

Post Fri Mar 17, 2023 11:25 am

Re: Serviio Console Access Restriction

I think not beeing able to restrict acess to the console with an extra login -regardless from whatever location- is a defect.
Any unauthenticated user from the local network is able to login to the serviio console and then is able to modify/grant/delete the rights for acessing a media Library.
You might say the home network is trusted, but then think of a scenario like this:
You have two video Libraries, one with general content the other filled with Porn.
Serviio can set a library to beeing acessible only for some users. You dont want your underage family members to get access to the over 18 content.
But as soon as anyone of the household has figured out the default Port the Admin interface listens to, he can give himself acess to the Porn library. Ok I can simply forbid him to do this again, but then problem has already happend.

Leaving the administration unsecured while making it possible to restrict content by the administration makes no sense unless you can secure the administration.
<<

nobody511

Serviio newbie

Posts: 8

Joined: Thu Feb 09, 2023 3:09 pm

Post Fri Mar 17, 2023 6:00 pm

Re: Serviio Console Access Restriction

There is a simple workaround for this problem. You can use a firewall to block connections to port 23423 (http) and 23523 (https) for anyone but a designated IP you want to use for Managment. Playback is still possible because it uses other ports.
Qnap includes a firewall which is easy to manage. Windows also.
Other platform most likely also have a similar feature.
Still an authentication would be a good thing to have.
<<

bharath026

Serviio newbie

Posts: 3

Joined: Wed Jun 09, 2021 11:56 pm

Post Tue May 09, 2023 1:29 pm

Re: Serviio Console Access Restriction

Once users are setup with access password, is it possible for the same authentication to be used for access to the console?

As now the firewall is great idea bur not viable for use with andriod app, or remote access.

But true I agree any one with little knowledge about ip with web browser can just type

Http://(Web access ip):23423/console

And have a big security risk for foul play.
Hope this can be resolved
<<

atc98092

User avatar

DLNA master

Posts: 5212

Joined: Fri Aug 17, 2012 10:22 pm

Location: Washington (the state)

Post Wed May 10, 2023 12:10 am

Re: Serviio Console Access Restriction

bharath026 wrote:Once users are setup with access password, is it possible for the same authentication to be used for access to the console?


No, there's no authentication for the console. But as I responded to you in your other post, there's really no reason to make the console available through your router to the Internet.
Dan

LG NANO85 4K TV, Samsung JU7100 4K TV, Sony BDP-S3500, Sharp 4K Roku TV, Insignia Roku TV, Roku Ultra, Premiere and Stick, Nvidia Shield, Yamaha RX-V583 AVR.
Primary server: Intel i5-6400, 16 gig ram, Windows 10 Pro, 22 TB hard drive space | Test server Windows 10 Pro, AMD Phenom II X4 965, 8 gig ram

HOWTO: Enable debug logging HOWTO: Identify media file contents

Return to NAS installation

Who is online

Users browsing this forum: No registered users and 7 guests

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by ST Software for PTF.