SageTV Community  

Go Back   SageTV Community > SageTV Products > SageTV HD Theater - Media Player
Forum Rules FAQs Community Downloads Today's Posts Search

Notices

SageTV HD Theater - Media Player Discussion related to using the SageTV HD Theater as a Media Player, i.e.: in use while not connected to a SageTV server. Questions, issues, problems, suggestions, etc. relating to using a SageTV HD Theater as a Media Player should be posted here. Use the SageTV Media Extender forum for issues related to using it while connected to a SageTV server.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 02-10-2010, 10:03 PM
Mpegger Mpegger is offline
Sage User
 
Join Date: Feb 2010
Location: NYC
Posts: 9
HD Theatre can view entire WHS

I just finished playing around abit with the HD Theatre, and so far its working great, except for one very big problem.

The SageTV server is installed on a Windows Home Server setup, and there are only a few folders shared, which show up as it should within the HD Theatre (Video folder, Photos folder, Music folder, and Public folder).

The problem is that if I choose "Browse Media Files", then "Browse Files on the Server", it allows access to the entire WHS, both C: and D:, even folders that are not supposed to be accessible.

I didn't realize this on SageTV Client because I never needed to use that option before, but this is totally unacceptable that the HD Theatre can access the entire server unhindered.

Is there a way this fix this behavior? It should only have access to those folders which are shared and no others, regardless of whether its running off the server or not.
Reply With Quote
  #2  
Old 02-10-2010, 10:12 PM
Fuzzy's Avatar
Fuzzy Fuzzy is offline
SageTVaholic
 
Join Date: Sep 2005
Location: Jurupa Valley, CA
Posts: 9,957
The reasoning for this, is the HD200 isn't accessing the files. The SageTV Server is. The HD200 runs in the context of the server, so since it's local, it has full access. Standalone mode wouldn't be able to access non-shared files. If you want to disable the 'browse for files' feature, you should be able to with some minor changes in Studio.
__________________
Buy Fuzzy a beer! (Fuzzy likes beer)

unRAID Server: i7-6700, 32GB RAM, Dual 128GB SSD cache and 13TB pool, with SageTVv9, openDCT, Logitech Media Server and Plex Media Server each in Dockers.
Sources: HRHR Prime with Charter CableCard. HDHR-US for OTA.
Primary Client: HD-300 through XBoxOne in Living Room, Samsung HLT-6189S
Other Clients: Mi Box in Master Bedroom, HD-200 in kids room
Reply With Quote
  #3  
Old 02-10-2010, 10:23 PM
Mpegger Mpegger is offline
Sage User
 
Join Date: Feb 2010
Location: NYC
Posts: 9
Quote:
Originally Posted by Fuzzy View Post
The reasoning for this, is the HD200 isn't accessing the files. The SageTV Server is. The HD200 runs in the context of the server, so since it's local, it has full access. Standalone mode wouldn't be able to access non-shared files. If you want to disable the 'browse for files' feature, you should be able to with some minor changes in Studio.
I understand its because the HD200 is running off the server in extender mode, so in essences, its like running a remote screen from the computer. I just don't understand why a big security flaw like this would be left in for the WHS version. Absolutely NO clients, extender or not, should be allowed to view ANY other folders on the server except for those public share(s) and designated recording folder(s).

That being said, yes, I want to disable this behavior and would love to know how to do so.
Reply With Quote
  #4  
Old 02-10-2010, 10:35 PM
Fuzzy's Avatar
Fuzzy Fuzzy is offline
SageTVaholic
 
Join Date: Sep 2005
Location: Jurupa Valley, CA
Posts: 9,957
no idea exactly how to do so, but if you read up on studio, you should be able to find that widget in the code and disable it.

And I also don't see how this is some sort of 'security flaw'. Worst someone could do is watch your videos that aren't in the import for some reason.
__________________
Buy Fuzzy a beer! (Fuzzy likes beer)

unRAID Server: i7-6700, 32GB RAM, Dual 128GB SSD cache and 13TB pool, with SageTVv9, openDCT, Logitech Media Server and Plex Media Server each in Dockers.
Sources: HRHR Prime with Charter CableCard. HDHR-US for OTA.
Primary Client: HD-300 through XBoxOne in Living Room, Samsung HLT-6189S
Other Clients: Mi Box in Master Bedroom, HD-200 in kids room
Reply With Quote
  #5  
Old 02-10-2010, 10:45 PM
Mpegger Mpegger is offline
Sage User
 
Join Date: Feb 2010
Location: NYC
Posts: 9
Quote:
Originally Posted by Fuzzy View Post
no idea exactly how to do so, but if you read up on studio, you should be able to find that widget in the code and disable it.

And I also don't see how this is some sort of 'security flaw'. Worst someone could do is watch your videos that aren't in the import for some reason.
Quote:
Files Types Shown In Browser: All Files
Allow File Deletion - Checked
Those settings alone are the security problem I'm talking about. With it, you can view any file, and delete it, from within SageTV. Sure, you can't view the file if it was a document of some sort, or run it if it was some type of program, or even download it to the client/remote connecting PC, but one (ie kids, inept/curious users) can easily royally hose a system because of it.

I'm looking into Studio right now to remove that file browsing option from SageTV altogether.
Reply With Quote
  #6  
Old 02-11-2010, 06:58 AM
stanger89's Avatar
stanger89 stanger89 is offline
SageTVaholic
 
Join Date: May 2003
Location: Marion, IA
Posts: 15,188
I'd think the problem is you're running the Sage service under the LocalSystem account which has access to everything. If you don't want Sage to have access to everything, you should run it as a different user with more limited access.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
View Pic... View Movie... Back & Forth... joelinkup SageTV Customizations 3 01-05-2010 09:57 PM
How to Fill Entire Monitor? Pegleg SageTV Software 1 02-06-2004 12:00 AM
Help setting up entire house w/ SageTV StylinLP SageTV Software 16 09-24-2003 12:39 AM


All times are GMT -6. The time now is 01:09 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2023, vBulletin Solutions Inc.
Copyright 2003-2005 SageTV, LLC. All rights reserved.