Security issue No name and pswd required with the same workgroup
Linux - NewbieThis Linux forum is for members that are new to Linux.
Just starting out and have a question?
If it is not in the man pages or the how-to's this is the place!
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
Security issue No name and pswd required with the same workgroup
Hello ,
When installing a Toshiba laptop w7 with Wifi on my linux suze 42.2 with Samba and creating a common workgroup it happen the toshiba can enter on the server and Samba without any name or password . It can even read or delete a file !!!
How can this happen ? My other desktop always needed to create a user on linux and type a password .
The user name of the Toshiba does not exist on samba .
I will try to post the Smb.conf .
Note : I also tried an other laptop Acer with a name that does not exist on samba user list and it can access samba
if the workgroup name on windows is the same as the workgroup created on samba .
Oups , seems nobody is connected but still everything runs !
4 connected with no names : 192.168.1.111 / 112 / 113/ 114
I do not knwo what happens .
The only thing I change in the past was the directory used ( share2 ) to home
I had only 40mb available on share2 and did not know how to create a directory with available space .....
There appears to be a pretty serious security hole in the configuration of your server, which is in fact accepting anonymous connections without challenge, and giving them access!
How long might this have been going on, when you thought that your data was protected, while it very-obviously isn't?
May be 2 or 3 month that may be the data are not really protected .
But first i know what is going on , where is the mistake and how to correct it ,
Regards
ger56
Without you posting the configurations for samba, there is no way we can tell what might be wrong with the configuration of samba. We will be watching for you to post this information.
Without you posting the configurations for samba, there is no way we can tell what might be wrong with the configuration of samba. We will be watching for you to post this information.
Look at the attached files and screenshot I sent this morning .
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.