Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question?
If it is not in the man pages or the how-to's this is the place! |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
|
07-17-2017, 09:20 AM
|
#1
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Rep: 
|
Security issue No name and pswd required with the same workgroup
Hello ,
When installing a Toshiba laptop w7 with Wifi on my linux suze 42.2 with Samba and creating a common workgroup it happen the toshiba can enter on the server and Samba without any name or password . It can even read or delete a file !!!
How can this happen ? My other desktop always needed to create a user on linux and type a password .
Thank you for your answers
Ger56
|
|
|
07-17-2017, 10:18 AM
|
#2
|
Senior Member
Registered: Dec 2014
Location: Montreal, Quebec and Dartmouth, Nova Scotia CANADA
Distribution: Arch, AntiX, ArtiX
Posts: 1,364
|
Hi ger56,
You are correct that this is atypical behaviour in most circumstances. Could you please post some additional details:
- User name on the Toshiba laptop for which this automatic access is granted
- smb.conf on your linux server
- smbpassword and password contents on your linux server
... let's start with that - it'll help members here assist you.
|
|
|
07-17-2017, 10:30 AM
|
#3
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
hello ,
The Toshiba user name has never been created on linux , so no name and no pswd bu it still can entrer into Samba .
Smb.conf is standtard without any security add on .
Regards
ger56
|
|
|
07-17-2017, 10:35 AM
|
#4
|
Senior Member
Registered: Dec 2014
Location: Montreal, Quebec and Dartmouth, Nova Scotia CANADA
Distribution: Arch, AntiX, ArtiX
Posts: 1,364
|
Hi ger56,
Is the Toshiba user name the same as for the desktop that already has samba access ?
It would still probably help if you would post the contents of your smb.conf.
Cheers,
|
|
|
07-17-2017, 10:52 AM
|
#5
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
Hello ,
The user name of the Toshiba does not exist on samba .
I will try to post the Smb.conf .
Note : I also tried an other laptop Acer with a name that does not exist on samba user list and it can access samba
if the workgroup name on windows is the same as the workgroup created on samba .
Ger56
|
|
|
07-17-2017, 11:10 AM
|
#6
|
LQ Guru
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 11,201
|
You should find record of the SMB connection in the Windows event viewer. You should also see the Toshiba in a list of connected SMB users.
|
|
|
07-17-2017, 05:39 PM
|
#7
|
LQ Guru
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524
|
That might be a SuSE feature.
|
|
|
07-18-2017, 05:20 AM
|
#8
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
Hello ,
Oups , seems nobody is connected but still everything runs !
4 connected with no names : 192.168.1.111 / 112 / 113/ 114
I do not knwo what happens .
The only thing I change in the past was the directory used ( share2 ) to home
I had only 40mb available on share2 and did not know how to create a directory with available space .....
See attachment : smbconf and smb connexion
Regards
Ger56
|
|
|
07-18-2017, 09:40 AM
|
#9
|
LQ Guru
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 11,201
|
There appears to be a pretty serious security hole in the configuration of your server, which is in fact accepting anonymous connections without challenge, and giving them access!
How long might this have been going on, when you thought that your data was protected, while it very-obviously isn't?
|
|
|
07-18-2017, 09:53 AM
|
#10
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
Hello ,
May be 2 or 3 month that may be the data are not really protected .
But first i know what is going on , where is the mistake and how to correct it ,
Regards
ger56
|
|
|
07-18-2017, 09:56 AM
|
#11
|
LQ Guru
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 6,174
|
Quote:
Originally Posted by ger56
Hello ,
May be 2 or 3 month that may be the data are not really protected .
But first i know what is going on , where is the mistake and how to correct it ,
Regards
ger56
|
Without you posting the configurations for samba, there is no way we can tell what might be wrong with the configuration of samba. We will be watching for you to post this information.
|
|
|
07-18-2017, 10:02 AM
|
#12
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
Quote:
Originally Posted by wpeckham
Without you posting the configurations for samba, there is no way we can tell what might be wrong with the configuration of samba. We will be watching for you to post this information.
|
Look at the attached files and screenshot I sent this morning .
Ger56
|
|
|
07-18-2017, 10:15 AM
|
#13
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
again in 2 files attached smb.conf
|
|
|
07-18-2017, 11:11 AM
|
#14
|
Senior Member
Registered: Dec 2014
Location: Montreal, Quebec and Dartmouth, Nova Scotia CANADA
Distribution: Arch, AntiX, ArtiX
Posts: 1,364
|
Hi ger56 ...
It will be easier for us to examine your smb.conf if you just post the contents between code tags instead of taking pictures. Like this:
Code:
.... contents of your smb.conf .....
... The code tags are "["code"]" at the beginning and "["/code"]" at the end (omitting the quotation marks).
Last edited by Rickkkk; 07-18-2017 at 11:12 AM.
|
|
|
07-18-2017, 11:50 AM
|
#15
|
LQ Newbie
Registered: Jul 2017
Posts: 10
Original Poster
Rep: 
|
Quote:
Originally Posted by Rickkkk
Hi ger56 ...
It will be easier for us to examine your smb.conf if you just post the contents between code tags instead of taking pictures. Like this:
Code:
.... contents of your smb.conf .....
... The code tags are "["code"]" at the beginning and "["/code"]" at the end (omitting the quotation marks).
|
hello ,
the server is only use for sharing files this is why I made some picture I am not using any browser or printer on it .
I can re type the smb.conf if you wish but attached pic should be enough ?
Ger56
|
|
|
All times are GMT -5. The time now is 10:58 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|