Security warning if you use IP based authentication (Non-LAN only/Limit IP) - Take action ASAP

Nathan

Getting the hang of it
Dec 18, 2016
56
29
Hi,

Please continue reading if you meet this criteria:
AND
  • Non-LAN only authentication
OR
  • Limit IP access
If your BlueIris instance is exposed to the Internet and meets the above criteria then please either update your Blue Iris version or disable the IP based authentication and switch to 100% user/password. If you do not to this, there is a security vulnerability that will allow anyone from the Internet to be able to escalate their access to your IP based access as if they had that IP.

For example, if you have Non-LAN only authentication turned on, someone from the Internet can access your cameras/Blue Iris instance as if they were in your LAN.

I reported this security vulnerability to Ken/Support on 11/28/2016 and they promptly confirmed and fixed it on 12/11/2016.

It doesn't appear that Blue Iris Software widely reported this as a security update so I will let this serve as a public warning. I am not going to disclose the vulnerability at this point in order to give folks time to update.

The actual update that fixed this was earlier than 4.4.9.4 but I did a poor job of tracking the version. I hesitate to name an earlier minor version that had the fix as I don't have a way to quickly confirm it. The vulnerability does exist in the initial release of 4.4.9. I warn against updating to anything beyond .4 at this point as there are some other functionality issues with .5 and .6.
 
A lot of NAS have a setting to lock out for a specified amount of time after several unsuccessful login attempts. I wonder if this is something worth adding to BI.
 
A lot of NAS have a setting to lock out for a specified amount of time after several unsuccessful login attempts. I wonder if this is something worth adding to BI.
Maybe but this vulnerability exists regardless of the login attempts. If you allow your LAN network to access blue iris as anonymous (or admin with ^), someone from the Internet would be able to access it as if they were on their LAN, bypassing any user/password authentication.
 
  • Like
Reactions: nayr
can anyone please tell me how to swith to USER/PASSWORD all the time instead of automatically logging in?
Thank you in advance