 |
|
|
|
|
 |
|
|
|
|
Junior Member
Offline
Posts: 28
Level: 4 [  ]
Life: 0 / 75
Magic: 9 / 284
Experience: 3%
Thanks: 1
Thanked 18 Times in 12 Posts
Join Date: Dec 2008
|
Be aware of the Enigma1 version you use... -
08-December-2009, 00:19
Be aware of the Enigma1 version you use...
I found out that you can get stolen your newcs and cccam files, as well as many others... quiet simple... test and check your box.
If you get on your browser the line, then you need to change the Firmware.
Emo
Test lines :
*edit*
Last edited by Morte; 08-December-2009 at 06:30.
|
|
|
|
|
The Following 2 Users Say Thank You to emosim For This Useful Post:
|
|
|
|
|
|
Super Moderator
Offline
Posts: 8,611
Level: 61 [    ]
Life: 1584 / 1980
Magic: 2870 / 12653
Experience: 93%
Thanks: 3,236
Thanked 3,785 Times in 1,404 Posts
Join Date: May 2007
|
08-December-2009, 06:33
Emosim I removed the test lines,because I cant test now anything but it seems like any open dreambox (port 80) without password or default password is the real problem OR does this testline gets on any passworded dreambox?
As many times told/warned before DO NOT forward port 80 or put the dreambox in a DMZ
E1 & E2
I pulled already enough cfg's in a different manner just to warn users 
From E1 & E2 boxes
Hardware: DM500S, MaximumTorodial T90, Inverto Silver Tech 0,2 db
Sat positions: 4.8°,13.0°,19.2°,28.2°
Software: Pli Jade 2 with X-line Skin
CAM: Cccam 2.1.2
NOT LOOKING FOR SHARES
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
Use the ====>>>> <<<<==== when you are happy with a post instead of replying to a post (rule #11 and gets you even banned)
Last edited by Morte; 08-December-2009 at 06:36.
|
|
|
|
|
The Following 6 Users Say Thank You to Morte For This Useful Post:
|
|
|
|
|
|
Junior Member
Offline
Posts: 28
Level: 4 [  ]
Life: 0 / 75
Magic: 9 / 284
Experience: 3%
Thanks: 1
Thanked 18 Times in 12 Posts
Join Date: Dec 2008
|
08-December-2009, 13:26
You need to keep the lines on the post, as otherwise the post is useless.
Passworded boxes also can get the CCcam.cfg and Newcs files extracted by that method... but only some versions, not the last ones.
Load a EDG-Nemesis 4.2, or a Gemini 4.4 (release 4.4.0, 27.05.2008) have that bug...
Emo
|
|
|
|
|
The Following 2 Users Say Thank You to emosim For This Useful Post:
|
|
|
|
|
|
Junior Member
Offline
Posts: 28
Level: 4 [  ]
Life: 0 / 75
Magic: 9 / 284
Experience: 3%
Thanks: 1
Thanked 18 Times in 12 Posts
Join Date: Dec 2008
|
08-December-2009, 16:02
It doesn't help to put in a DMZ, as you can extract the CCcam.cfg and newcamd files no problem... on the EDG-Nemesis 4.2 and Gemini 4.4, for Enigma1.
Just check with the lines I included on my message above...
Emo
|
|
|
|
|
The Following User Says Thank You to emosim For This Useful Post:
|
|
|
|
|
|
Super Moderator
Offline
Posts: 8,611
Level: 61 [    ]
Life: 1584 / 1980
Magic: 2870 / 12653
Experience: 93%
Thanks: 3,236
Thanked 3,785 Times in 1,404 Posts
Join Date: May 2007
|
14-December-2009, 22:29
I think you are confused what is DMZ, I told never to put in DMZ.
The lines are not needed to make this a useful post.
It's all about awareness and if ppl read this they should know better also without the lines to never forward port 80(go home to watch tv or use restream) even when passworded.
Keeping the lines public will 100% sure be abused by a few and many get frustrated they find their c-lines open on the web posted as "free servers"
(15-December-2009 21:01)
OK this is scary.
A user reported me that another leaked his lines.
I checked port 80 from that user and password was changed, but with the lines EMOSIM gave I could download his cccam.cfg without any problem
Hardware: DM500S, MaximumTorodial T90, Inverto Silver Tech 0,2 db
Sat positions: 4.8°,13.0°,19.2°,28.2°
Software: Pli Jade 2 with X-line Skin
CAM: Cccam 2.1.2
NOT LOOKING FOR SHARES
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
Use the ====>>>> <<<<==== when you are happy with a post instead of replying to a post (rule #11 and gets you even banned)
Last edited by Morte; 15-December-2009 at 21:00.
Reason: Automerged Doublepost
|
|
|
|
|
The Following 7 Users Say Thank You to Morte For This Useful Post:
|
|
|
|
|
|
Senior Member
Offline
Posts: 101
Level: 9 [ ]
Life: 0 / 201
Magic: 33 / 766
Experience: 5%
Thanks: 51
Thanked 16 Times in 13 Posts
Join Date: Nov 2008
|
15-December-2009, 21:14
i dont understand this. am i missing sumthing? cheers
|
|
|
|
|
|
|
|
Super Moderator
Offline
Posts: 8,611
Level: 61 [    ]
Life: 1584 / 1980
Magic: 2870 / 12653
Experience: 93%
Thanks: 3,236
Thanked 3,785 Times in 1,404 Posts
Join Date: May 2007
|
15-December-2009, 21:29
Lets say you got port 80 forwarded to your dreambox and changed the default login root/dreambox
Doesnt matter I can download your cccam.cfg, already tested it.
Hardware: DM500S, MaximumTorodial T90, Inverto Silver Tech 0,2 db
Sat positions: 4.8°,13.0°,19.2°,28.2°
Software: Pli Jade 2 with X-line Skin
CAM: Cccam 2.1.2
NOT LOOKING FOR SHARES
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
Use the ====>>>> <<<<==== when you are happy with a post instead of replying to a post (rule #11 and gets you even banned)
|
|
|
|
|
The Following 5 Users Say Thank You to Morte For This Useful Post:
|
|
|
|
|
|
Senior Member
Offline
Posts: 101
Level: 9 [ ]
Life: 0 / 201
Magic: 33 / 766
Experience: 5%
Thanks: 51
Thanked 16 Times in 13 Posts
Join Date: Nov 2008
|
15-December-2009, 21:42
Quote:
|
Lets say you got port 80 forwarded to your dreambox and changed the default login root/dreambox
Doesnt matter I can download your cccam.cfg, already tested it.
|
you have mine ???? or you mean u have tested the trick on others?
|
|
|
|
|
|
|
|
Super Moderator
Offline
Posts: 8,611
Level: 61 [    ]
Life: 1584 / 1980
Magic: 2870 / 12653
Experience: 93%
Thanks: 3,236
Thanked 3,785 Times in 1,404 Posts
Join Date: May 2007
|
15-December-2009, 23:15
I tested it on peers who were suspected of leaking lines (I had several reports in my PM box) and indeed, they did not leak but I tested this security flaw and it worked, their cfg's were stolen and published on the web
Hardware: DM500S, MaximumTorodial T90, Inverto Silver Tech 0,2 db
Sat positions: 4.8°,13.0°,19.2°,28.2°
Software: Pli Jade 2 with X-line Skin
CAM: Cccam 2.1.2
NOT LOOKING FOR SHARES
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
[Only Registered Users Can See LinksClick Here To Register]
Use the ====>>>> <<<<==== when you are happy with a post instead of replying to a post (rule #11 and gets you even banned)
|
|
|
|
|
The Following 2 Users Say Thank You to Morte For This Useful Post:
|
|
|
|
|
|
Senior Member
Online
Posts: 108
Level: 9 [ ]
Life: 0 / 210
Magic: 36 / 1103
Experience: 40%
Thanks: 148
Thanked 90 Times in 41 Posts
Join Date: Jun 2008
|
16-December-2009, 00:37
I think this may be a good way for everyone to check if port 80 or others are open or closed to their device!?
[Only Registered Users Can See LinksClick Here To Register]
cheers
|
|
|
|
|
The Following 2 Users Say Thank You to dionysos For This Useful Post:
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
|
 |