OSx Server 3.1.2 - Wiki (collabd) Authentication Vulnerable to Brute Force?

Hello Team,
     I have been using OSx Servers (3.1.2 - Build 1354517) 'wiki' or Collaborative suite to host some personally created wiki's and documentation. Upon having this open to external (WAN) connections, as was my eventual goal; I noticed a potential problem. I found that I could continually attempt authenticate against the website, without any timeout or anything else to slow down my attempts.
     To elaborate briefly, I don't mean authentication against .htpassword as maybe configured in OSX Servers Website hosting setup. I mean against the wiki software itself. The only way around this, that I can find, would be to use .htpassword for an additional layer of security.
     Given that there are MANY ways to gain usernames against the wiki server (Profiles, default 'alias', activity logs - etc), and the fact that this authenticates against local system accounts, is this a genuine security threat?
     I appreciate any feedback from other users or perhaps Apple.

Hello Linc,
     I appreciate your reply, though I feel it misses the core content of my enquiry. It's not unnecessary to expose this service, but I would like the ability to. I don't think the service accessibility limitations should be defined on whether the application is secure or not.
     And either way, even if run in a secure environment; it's still a compromise.
     In the end, I'm still not sure; Do you acknowledge that this is vulnerable to brute force?
     Thanks,

Similar Messages

  • OSX server 3.0.3 wiki issues using the iPad

    Hello,
    I just got the new OSX server 3.0.3 Maverics installed and everything seems to work fine except for going to the Wiki using an iPad. The Mac and the iPhone work fine but when you try and go to the wiki using the iPad it try's to redirect to https://domainname/wiki/ipad/#route=/wiki/ipad/ but it won't work. I just get a blank page on the iPad.
    Any idea how to fix this. It's driving me crazy.
    Thank you.

    There are add-on packages for Windows that can access CardDAV (addresses) and CalDAV (calendar) services. 
    See this list and this list for some of the available options.
    Windows Server with Exchange Server and Microsoft Office clients might be a better choice, if you're working with a whole lot of Windows clients.  Microsoft Office is also available for OS X, as well.

  • Is there a way to have a wiki on osx server where users can be created at first logon? (for a semi-public wiki)

    Hello,
    I am installing an osx server that will be primarly used as a wiki for collaboration.
    Problem: there will be many users from various organisations -> creating users manually on the server is not an option.
    Is there a way to have a page/something where users will login and the account will be created at first logon? (after being approved if possible).
    I'd want my users to go to the wiki and do something like click a "new user" or "create account" button then fill a form. The account in th directory would be then auto magically created.
    Does this feature already exist for osx server with the built-in wiki?

    Just generate the TTS on a separate slide and then assign the audio file created in the LIbrary to whatever object you need.

  • Mac OSX Server 10.5 not allowing wikis to work.

    Hey everyone.
    Currently, where I work, we have two servers.
    One running OSX Server 10.4 (cause of all the problems associated with 10.5!) and another running 10.5. The one running 10.4 does all our DNS, DHCP, logins etc.
    The 10.5 server is only running Web, SMB, XGrid and Open Directory. Its primary use is to host our intranet, cause we want wikis and blogs to work. The 10.5 Server we have is running Open Directory (connected to a directory system, since 10.4 cant replica to 10.5 and visa versa) so we can just have the login data.
    The problem we are having is: When we go into Workgroup Manager, select a group, the options to enable the following services for this group on...has nothing in the list.
    We have been to Server Admin, gone to Web, gone to sites, turned all the services on...made our site done all that. Its just the option in Workgroup Manager that isn't working. Can anyone shed some light to why this wouldn't be working?

    You need to make sure that the group you are enabling the services for is in the LDAP path for the 10.5 server, and not in the local directory or the LDAP for the 10.4 server.

  • OSX server - Comment on Wiki (Mountain Lion Server) does not work

    OSX server - Comment on Wiki (Mountain Lion Server) does not work - it always give an error "Comment could not be saved, please try again" eitheir upgrade from Lion Server or fresh install.

    sorry, I had been allowed anyone to comment, and use wiki owner user also.

  • How to disable OSX server 3 SMTP authentication

    Hi,
    I upgraded my 10.5 server to 10.9 OSX server. The mail server is only used internally. I use a HP Multifuntion printer which I often use to scan documents and the printer would mail me the scans in PDF. In 10.9 the user have to authenticate in order to send mail via the SMTP server. Unfortunately the HP printer expects an open SMTP server.
    I know that underneath OSX mail server Postfix is running. Is  there a way to dissable SMTP authentication so I can us my multifunction printer to mail me the scanned documents again?

    MrHoffman,
    Thank you very much for pointing me in the right direction. I added my network to the mynetwork parameter and still got an error on the mail server. This was what I found in the log:
    NOQUEUE: reject: RCPT from hpprinter.warmoezier.home[192.168.XX.XX]: 504 5.5.2 <NPIB32ACB>: Helo command rejected: need fully-qualified hostname; from=<XXXXXXXXXX> to=<XXXXXXXXXX> proto=ESMTP helo=<NPIB32ACB>
    (I removed my mail addresses from the printout. It seems that the HP printer doesnot provide the fqdn in the HELO command.
    Then I replaced:
    smtpd_helo_restrictions = reject_non_fqdn_helo_hostname reject_invalid_helo_hostname
    with:
    smtpd_helo_restrictions = reject_invalid_helo_hostname
    This solved my problem.
    I gues I have to replace the network with the exact printer address in the mynetworks parameter to be on the safe side concerning openrelays in my private network.
    I edited the main.cf directly without using the postconf command or should I have used postconf?
    Thanks again for sharing your knowledge.
    Peter.
    P.s.
    btw is the command in your post correct?
    postconf -c /Library/Server/Mail/Config/postfix mynetworks -e "mynetworks = 127.0.0.0/8, [::1]/128, 10.20.30.40"
    shouldn't it be:
    postconf -c /Library/Server/Mail/Config/postfix -e "mynetworks = 127.0.0.0/8, [::1]/128, 10.20.30.40"

  • Why does OSX Server serve out Wikis so slowly?

    Hi,
    I didn't see this topic so here's my question. I've got OSX server running and updated. I've installed Mediawiki and it works fine, but its very slow. When I've had other Web pages up, they are quick, but for some reason the Wiki is incredibly slow. So slow that when you post a change, it times out before refreshing. You can see the progress bar move half way (indicating the changes are saved), but then you sit and wait and it times out. If you go back and refresh the page, your changes are there.
    I'm on a University Campus and have pretty good internet connection speeds. Our Tech support stated he heard Wikis are served slow on OSX and I'd need to do somethign to speed it up, but no idea what.
    Its a G4 with a couple GB of RAM. Any questions to help me trouble shoot this I'll be happy to answer. I know Leopard is going to have the Wiki server, but I'd like to get this working before then!

    I guess I am somewhat confused, and my real
    concern is does plain old OSX really provide the
    basic server functions mentioned above
    out-of-the-box?
    Yes.
    Here is more
    info about what "OS X Server" is. If you don't
    know you need it, you probably don't:)
    Microsoft isn't much better with naming, considering
    I used to use MS Office at home to do
    schoolwork...
    Yah, I'm a confused apple newbie, an old UNIX hacker, and I would like to learn more web type programming, so that is my interest in learning some new things.
    Thanks for the answer.

  • Powershell Error for SharePoint Online -"The remote server returned an error: (407) Proxy Authentication Required."

    I am trying to call sharepoint online from powershell. Below is the code. I get 
    Exception calling "ExecuteQuery" with "0" argument(s): "The remote server returned an error: (407) Proxy Authentication Required."
    $loadInfo1 = [System.Reflection.Assembly]::LoadWithPartialName("Microsoft.SharePoint.Client")
    $loadInfo2 = [System.Reflection.Assembly]::LoadWithPartialName("Microsoft.SharePoint.Client.Runtime")
    $webUrl = "ZZZZ"
    $username = "XXX"
    $password = "YYYY"
    $ctx = New-Object Microsoft.SharePoint.Client.ClientContext($webUrl) 
    $ctx.Credentials = New-Object Microsoft.SharePoint.Client.SharePointOnlineCredentials($username, $password)
    $web = $ctx.Web
    $lists = $web.Lists 
    $ctx.Load($lists)
    $ctx.ExecuteQuery()
    $lists| select -Property Title
    Raj-Shpt

    Hi,
    About how to access SharePoint online site using PowerShell, the blog below would be helpful:
    http://social.technet.microsoft.com/wiki/contents/articles/29518.csom-sharepoint-powershell-reference-and-example-codes.aspx
    Another two demos for your reference:
    http://www.hartsteve.com/2013/06/sharepoint-online-powershell/
    http://www.sharepointnutsandbolts.com/2013/12/Using-CSOM-in-PowerShell-scripts-with-Office365.html
    Thanks
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • Can't establish VPN on windows client to OSX server

    Hi everyone,
    I'm stuck for a while now with a very annoying problem.
    I can't establish a VPN connection on a windows client to a OSX Server. It worked fine while we had OSX server 10.6.
    We recently updated to 10.8 and got this problem.
    I know some of u are now thinking, the solution is: Just don't use windows... But the director of the company i am doing this for
    doesn't want to switch to mac.
    Also, this problem maybe be related to windows but i hope someone here can help me.
    Things i've done:
    I've tried PPTP ( didn't work either )
    I've tried different users
    I've tried adding a rule te regedit in windows ( according to a windows vista kb file for VPN trough NAT devices )
    I've tried different authentication rules
    In VPN log is Server admin everything goes well until:
    pppd[87435]: fatal signal 6
    vpnd[104]: --> Client with address 192.168.0.24 has hungup
    after this it goes further with some successes.
    I hope someone here knows the solution!
    Thanks in advance,
    Remy
    Mac mini server, 10.8.5
    server admin 2
    ( client ) windows 7 & 8
    ps. sorry for my bad grammer, i'm dutch..

    You could have a look at the following and see if it helps.
    http://support.apple.com/kb/HT5078

  • Diffs b/n 10.4.3 clients and 10.3.9 on OSX Server 10.3.9

    We have a smooth running OSX Server (standalone running 10.3.9) with mainly 10.3.9 clients (G3 iMacs to latest eMacs). When we configure brand new 10.4.3 clients (new eMacs) using the same settings in Directory Access we can't get login to work.
    All that happens is that the Username and Password go grey and the machine hangs with frantic network activity (based on flickering lights on the switch). The dialog box doesn't shake.
    In some cases the computer will eventually login but it takes several hours - usually though, not at all - or at least I get sick of waiting after a full school day.
    Clearly there is some wrinkle about 10.4.3 that I can't see. If I clone one of our 10.3.9 machines onto the new machines they workl perfectly, but I want to use Tiger.
    Everything is fully updated, network is 100baseT.
    Steve Richards
    Creswick PS
    Australia
    eMacs and a G4 Xserve   Mac OS X (10.4.3)   Server is 10.3.9

    Stephen,
    You seem to be doing pretty well for having trained yourself.
    By forward and reverse lookups, I meant DNS lookups--I typically use nslookup, but lookupd will work too. If you get the server's IP address from the FQDN (foward lookup) and the FQDN from the IP address (reverse lookup), then your DNS settings are fine.
    Ultimately, you should change the paths to your share points so they meet the requirements, but before you do that, I would run a test with a temporary share point to see if you can get your 10.4.3 clients to work. Use something like the default /Users share point--re-share it if necessary, and make sure you create a network mount record for it--and then set up a test user with its home directory in that share point. Then see if you can log in as that user on a 10.4.3 client.
    If you still can't, try using the dscl command-line utility to see if you can see the directory records for your automount. Here's an example from our setup (what you type is in italics):
    % dscl localhost
    cd LDAPv3/10.1.0.101/Mounts
    /LDAPv3/10.1.0.101/Mounts > ls
    my.server.edu:/Volumes/Students
    /LDAPv3/10.1.0.161/Mounts > read my.server.edu<tab to auto-complete>
    cn: my.server.edu:/Volumes/Students
    mountDirectory: /Network/Servers/
    Basically, this tells you what mounts are published on your server. In your instance, you should see an entry for your Group Folders/Middle Years share point in the list from the ls command. If you can see the mount records for your home directory share points, and you can see the attributes of those records with the read command, that eliminates one possible source of the problem (whether the client is having problems binding to the server). This is unlikely to be the problem in your circumstances, but it's good to eliminate it out of the box.
    Note that your server's entry may be listed by host name instead of IP address--in dscl, cd into the LDAPv3 directory and do an ls to see what's there. If you don't see an entry, or if you can't cd into the Mounts directory or you see nothing there, try rebuilding the Directory Access preferences from scratch. Log in as admin, delete the contents of /Library/Preferences/DirectoryService, reboot, and run Directory Access to re-add an LDAPv3 configuration for your server. When you do that, enter the server's IP address, and Directory Access should fill in the search base for you. Save, quit, and reboot the machine, and see if you can log in then.
    Now, to your questions. Search base is in fact the dc=my,dc=com part. The ldapsearch command is useful if you need to see whether your client can bind to an LDAP server. It's actually not likely to be helpful in this situation, because your clients seem to be authenticating. I wasn't thinking when I added that suggestion. As to "static bind"--that just means that you are configuring Directory Access explicitly to contact a specific server, rather than letting the client get that information through DHCP.
    If none of this helps, of course, post back. And good luck.
    David Walton
    Power Macintosh G5 1.8/PowerBook G4 15 1.42   Mac OS X (10.3.9)  

  • Mac OSX Server VPN Not Working

    Heres how my setup is: I have an ATT DHCP Server/Router That assigns my public ip.
    I have an Apple AirPort Extreme in Bridge Mode Which hosts the main wifi connection.
    I have my Mac OSX Server connected to the AirPort Extreme
    On my ATT Router DHCP Server's Firewall I have my computer set to DMZ Plus mode which forwards all ports on the network to my mac.
    I am trying to connect to the vpn network via my MacBook Pro and iPhone5 and I cannot. However I can connect to the online wiki page on my server by going to server.djswirkmke.com if you would like to see it. My host name is server.local on the network but on the internet it is server.djswirkmke.com I also have a mail domain setup as mail.djswirkmke.com. My problem is I am not able to connect to the vpn on the client computers can you please help?

    In a moment of random frustration, I tried listing the DNS server in VPN settings three times, and it somehow fixed the problem. Even though it is the same IP all three times, it works when it is listed three times but not when it is listed just once.
    In other words, in VPN > Settings > Client Information > DNS Servers, I have:
    192.168.100.64
    192.168.100.64
    192.168.100.64
    Hope this helps someone having the same problem.

  • I BOUGHT osx server but could you tell what must i do to load this os on line tks  A poug

    Good evening
    I bought os server on line but i do not know what can i do to load this os on line,could you please help me?
    This is my first apple machine.
    Tks very much.
    A.poug

    What model Mini is it?
    http://en.wikipedia.org/wiki/Mac_Mini
    What displays when you boot it up?
    What version of OSX/server is installed?
    Did it come with any install disks?

  • What's the purpose of OSX Server on a Mac Mini?

    What's the purpose of OSX Server on a Mac Mini? Is it to make it a Media server?
    Thanks,
    Jeff

    Mac Mini makes a good workgroup server, classroom server, web server, DNS server, authentication server, or... Pretty much any time you want a small and quiet computer for a particular task. And for typical tasks (web and DNS and...) you can roll several together onto a single box, and can run (for instance) two as paired DNS and Open Directory servers.
    Mac OS X Server works nicely on most any of the Mac Mini boxes, too, while the Mac Mini Server does have a better price here and a configuration that's more targeted at server-oriented uses. The MMS adds RAID in particular, though that could be added onto the previous servers using external storage and FireWire.
    If you want a media server, then you don't necessarily need Mac OS X Server, you can do nicely with Mac OS X client and connections to whatever you want to use for media; digital TV or whatever. Front Row works OK here, and EyeTV is very nice.

  • Newbie: Connect Windows - OSX Server

    Hi
    I'm completely new with osx server. Installed it 5 min ago
    I'm wondering how i manage to get a remote desktop connection from a windows machine to the osx server?
    If i try on the windows the remote desktop with the IP of the server it can't connect.
    By the way, how to i manage to get a remote connection from mac to mac server?
    Thx

    I would politely disagree. Yes, definitely, the Mac 'Screen Sharing' app works a treat, and Apple Remote Desktop.app works as well, but I am coming from a Window's PeeCee.
    For me, connecting to my 10.5(.8) Server via tightvnc gives 'Server did not offer supported security type!". Using RealVNC to this machine states "No matching security types Do you wish to reconnect to ... ?" a telnet to this AppleVNCServer service (port 5900), shows RFB 003.889 *, or Remote Frame Buffer Major 3, minor 889.
    Also, connecting to multiple 10.6(.1) Clients with Tightvnc correctly asks for a password but then hangs at "Status: Security type requested". Using RealVNC opens, connects, asks for authentication, and exits. Telneting to this AppleVNCServer service (port 5900), also shows RFB 003.889 *.
    The Current Version of the protocol is supposed to be 3.8, that is Major version 3, minor version 8. Not 80 or 800 but Eight). http://www.realvnc.com/docs/rfbproto.pdf and I believe that tightvnc only supports up to version 3.7.
    On each station I have installed the 'old' OSXVnc.app as a service (to a unique port). OSXVnc utilizes protocol 3.3 and I can control them successfully, but that is of my own doing because of this issue.
    Now JollysFastVNC works a treat to any machine I have EVER tried to connect to. I have not tried COTVNC or any of the others (too slow for me, when they wer e around)
    Also, I just noticed that RealVNC states that their free and personal version will not connect to Mac OSX (x86 and PPC) but the Enterprise one will. I just Dl'ed the Enterprise Viewer and it gave essentially the same thing ('protocol is not valid' message, even after it asks for a password). Anyway, I am not here to hijack this thread, just trying to keep the info flowing and open.
    Maybe I am the only one with these problems but the bottom line is I cannot use Real or Tight, or UltraVNC to administer my server or clients as long as AppleVNCServer gives out the 003.889 protocol version.
    Peter
    * The ProtocolVersion message consists of 12 bytes interpreted as a string of ASCII characters in the format "RFB xxx.yyy\n" where xxx and yyy are the major and
    minor version numbers, padded with zeros.

  • OSX Server Error.

    I've just install osx server. This is show when i open wiki sever. Any suggestion for this problem.

    When ,I click at " View Wiki ".
    The Screen Show, these errors. How can i fixed it.

Maybe you are looking for

  • How do i get into my ipod when it says disabled connect to itunes

    how di get into my ipod when it says disabled connect to itunes

  • Can you help, please?  Time sensitive question about import quality.

    Hi, Didn't get an answer the first time, so with a little more research on my part I discovered that: Video clips shot with my S95 Powershot, imported automatically into iPhoto then into iMovie, are 1280x720 H.264, Linear PCM, and look fantastic. Sam

  • Applets

    i have a simple question when writing an applet in java is it possible to input codes in applets same as codes for java. and if not how do we write for example do while()code thank you in advance

  • BT Infinity availability date

    The BT Infinity postcode check shows that my exchange will be enabled for BT Infinity on 30th March 2011, but SamKnows shows that the date is 30th June 2011.  Does anyone know which is more reliable?

  • Catalog Previews.lrdata folders

    I see that in the previews.lrdata folder, there are several folders, each containing about a thousands empty folders. What are all of these folders? Are they really empty, or is it stuff that Windows just will not show. I have "show hidden folders" t