![]() |
|
|||||||
| General Discussion General discussion about SageTV and related companies, products, and technologies. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
Web Server Security - is it safe?
I'm wondering what people's opinions are on the safety of running web servers (like the Sage web server add-on) over the open internet?
What's the risk if I get a dynamic dns account and setup port forwarding in my router so that I can access a lightweight web server like this over the internet? I'm interested because I recently installed some security cameras outside my house and have been playing with some different camera monitoring software. One of the programs I have been looking at is Blue Iris. The Blue Iris software has its own web server built-in to allow you to access your live cameras and recorded clips over the LAN or WAN. I plan to run it on the same PC that is used as my Sage Server. I was also thinking about installing the web server plugin for Sage (I can set it to use a different port than Blue Iris).
__________________
CPU: Athlon II X4 630, Motherboard: Gigabyte MA770T-UD3P (AM3), Video Card: VisionTek Radeon HD4670 PCIe w/ Component output to 50" CRT Rear-Projection HDTV (Mitsubishi), Tuners (9): 1x Colossus, 1x HD-PVR, 1x HDHR, 1x HVR-2250, 1x HDHR Prime Other info: Win7-64Bit (Home Premium), 4GB RAM, 4.5TB HDD total, also 1x HD200 connected via HDMI to 42" LCD HDTV (Vizio). Comcast Cable (2x STB's to Colossus and HD-PVR, 2x QAM to HDHR, 2x QAM to HVR2250, 3x CableCard to Prime w/ SageDCT). |
|
#2
|
||||
|
||||
|
Just my opinion...
Not really Quote:
Quote:
Quote:
What I do at home is I use apache as a reverse proxy for this sort of thing - this allows me to wrap the sagetv web interface with SSL.
__________________
Love, Joe |
|
#3
|
|||
|
|||
|
You may want to look at port knocking
http://en.wikipedia.org/wiki/Port_knocking to improve your chances.
__________________
TV: Samsung UN46D8000 Server: Intel Core i3 540, 4G RAM, Matrox G450, 70GB EXT3 encrypted software RAID1 system drive, 1TB XFS tv recording drive, 2TB EXT3 encrypted data drive mirror across 2 machines, 2TB EXT3 encrypted media drive mirror across 2 machines, CentOS 6 64 bit, Experimenting with DNLA servers 1Gb wired network Disconnected after G day[HD 100 Media Extender, Placeshifter 7.x, SageTV 7.x, HDHomeRun] |
|
#4
|
|||
|
|||
|
VPN
You might want to look into running a VPN server for access to your internal network. OpenVPN is quite good.
Also, running a simple / small / obscure web server does tend to help. I ran my company's web server with thttpd running under FreeBSD on a DEC Alpha for many years. It was never down & never hacked. All the apache / x86 targeted attacks just bounced right off. With "professional IT" now running the server since it is "business critical", it is running some kind of "best practices" apache/php clusterf*ck and gets hacked pretty much weekly.. So much for the pros. Drew
__________________
Server HW: Xeon CPU E3-1270, 16GB RAM, 9TB Raid-Z + L2Arc, Server SW: Ubuntu 12.04 x86_64, ZFS on Linux, Java 1.6.0_21, SageTV 7.1.9.1 Tuner HW: Pinnacle 800i, Pinnacle 801e USB, HDHR Client: HD300, HD100 |
|
#5
|
|||
|
|||
|
+1 for VPN
Jetty can use HTTPS but obviously you still have to forward the port. I am using pfSense firewall and IPsec VPN (for iOS clents). If you don't need iPhone/iPad access you can use OpenVPN. IMHO Ps. I also use Blue Iris ...very good.
__________________
SageTV 7.1.9 on Win 7 Ultimate x86; Intel DH67CF, i3-2100T, 4GB DDR3, 60GB SSD, 8TB Drive Bender storage pool, blu-ray. 2x HD PVR (SA 4250HD firewire channel change), 2x HD200 extenders (external IR receiver mod, HD300 remotes). Plugins: Custom Main Menu, Enable/Disable Favorites, Stock Manager, Web Interface, Mobile Web Interface, PlayOn Last edited by DMT; 08-17-2012 at 08:45 AM. |
|
#6
|
||||
|
||||
|
Quote:
This wouldn't be for public viewing (just me and possibly family members), but I want to be able to access from the office or when traveling. I'm not sure what Blue Iris uses for its web server (maybe it's Jetty, maybe not). After reading the various comments, I'm beginning to think the VPN route makes the most sense. I see that iPhone doesn't support OpenVPN, but it looks like it supports PPtP. It looks like Windows 7 has built in support to set-up PPtP for inbound connections, so I may give that a shot. Even with VPN, I'll need to open up a port on the router, but it seems like a VPN connection is a lot more secure than an exposed web server.
__________________
CPU: Athlon II X4 630, Motherboard: Gigabyte MA770T-UD3P (AM3), Video Card: VisionTek Radeon HD4670 PCIe w/ Component output to 50" CRT Rear-Projection HDTV (Mitsubishi), Tuners (9): 1x Colossus, 1x HD-PVR, 1x HDHR, 1x HVR-2250, 1x HDHR Prime Other info: Win7-64Bit (Home Premium), 4GB RAM, 4.5TB HDD total, also 1x HD200 connected via HDMI to 42" LCD HDTV (Vizio). Comcast Cable (2x STB's to Colossus and HD-PVR, 2x QAM to HDHR, 2x QAM to HVR2250, 3x CableCard to Prime w/ SageDCT). |
|
#7
|
|||
|
|||
|
__________________
Server (Headless): MSI H57M-ED65 mATX Motherboard, Intel i3-530 CPU, 4 x 2TB Hitachi Drives, Win7 Home Premium 32 bit, SageTV 7.1.9 Tuners: 4 x Hauppauge WinTV-HVR-2250 Dual TV Tuner Boards, 1 x SiliconDust HDHomeRun Dual Digital TV Tuner (OTA) Clients: 4 x HD300 Extenders, 2 x HD200 Extenders Miscellaneous: 2 x Sony RM-VLZ620 Universal Remote Controls |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Java safe to use list | MacDaddy | SageTV Software | 3 | 03-27-2011 08:15 AM |
| Safe to use Diamond on 7.1.5 or stil must stay on 7.1.2? | TechBill | Diamond | 10 | 03-15-2011 08:00 AM |
| Safe to edit UID Prefix? | tmiranda | SageTV Studio | 7 | 12-19-2009 06:43 PM |
| How safe is 33099??? | Big Jeff | SageTV Placeshifter | 3 | 07-21-2007 04:12 AM |
| New Safe Way to Expand Storage | spike5884 | The SageTV Community | 17 | 07-07-2007 03:12 PM |