Security advisory: shares could be writeable when not meant to

No sooner we called this week “bug week” in our recent post … we found a somewhat serious bug in Amahi, the first in years. That is not what we meant by bug week!

The bug in question is that under certain conditions, users who should not have write permissions to a share could potentially write to it. It was fixed within minutes of being reported and the fix is available for the Amahi 6 beta. Fortunately there is an easy work-around for everyone else.

Who is Affected

If you set permissions to per-user access control to shares, you could be affected. If you did not turn off global writeability to the share before enabling per-user share control, you are affected.

Here is how it may happen: When a share has the “All users” and “Writeable” selected (which is the default) and the admin wants to manage per-users permissions and to give some users either read-only or no permissions, All users is unchecked. If Writeable is not unchecked first, users can still write to the share.

Typically one would click on All users to unclick it, to show all the users to control their permissions individually, without clicking on Writeable. Then manage the different users permissions. In this situation, the share would still be writeable to all users.

The Workaround

Fortunately, there is an easy work-around: unclick Writeable to before clicking on All users to manage their permissions individually. So, if you were affected and you had per-user permissions, you do this:

  • check All users to enable all users access
  • uncheck Writeable and then check All users again. All should be good then!

We have released and tested a fix for the Amahi 6 Beta release. You can see the details of the bug in our bug tracker.

Thanks go to Jimmy Hosio for hunting down this issue and to Bogdan (aka megabitdragon) for very quickly helping verify the fix!

Cheers!

The Amahi Team

[Facebook] [Slashdot] [Twitter]

The Drought is Nearly Over: Amahi 6 Beta, Torrent of app updates!

Amahi 6 Beta

Recently leaked reports reveal that Amahi 6 is in Beta, with an impending release!

Today we are happy to announce the newly-renamed Amahi 6 Beta for your testing pleasure. This is Platform and Base system only, VERY FEW APPS are available at this time.  We are shooting for a mid-February full release, after the beta testing. Early users report good things about the new pre-release bits and it should only be a little bit longer till release!

Grab a Fedora 14 DVD (not the live cd!), set this url http://f14.amahi.org as a repo and you are all set to kick the tires! Please report your findings and feedback in this forum thread.

We will have a bug week starting this Saturday February 5th. Reply in the forums, or come to the IRC channel with your  favorite fixes and bugs we just *must fix* in this release:) … A link to a bug in the bug tracker is required to participate :)   … We will report what’s new in Amahi 6 in the full release announcement but you can take a peek.

DLNA, FTP, Updates, Lots of New Apps

Amahi is becoming a media server powerhouse. Three weeks ago we released an update to the Amahi DLNA server app (now at v0.92.2), which brings stability fixes and enhanced compatibility with Samsung devices like TVs and settop boxes. Our community submitted these fixes upstream and were accepted right away!

Some other media oriented apps that are in beta still are getting some much-needed attention like MediaTomb (a transcoding DLNA server), PS3 Media Server (a PS3 centric DLNA server), CouchPotato, (an NZB downloader) and Sick Beard (a PVR for newsgroups).  We also have one cloud sharing app called Tonido. Media sharing is akey aspect of Amahi!

Did someone say FTP? We had avoided FTP (a legacy, but resilient, way to transfer files within your network) for the longest time, due to the fact that it’s not secure and that FTP over SSH is supported by many clients. However, you wanted FTP, so now we have two FTP servers apps available in beta thanks to the hard efforts of sabat and Solar_: vsftp and Proftp. Contact them in IRC or the forums to help test them.  Thanks to user ksjuggalo for help in packaging vsftpd!

More apps? Check out our pipeline of new apps …  how about Monitorix to monitor your network, and your HDA? Or how about Kmotion, a nifty home surveillance app. For the hardcore in you, if you do not want to miss a beat in IRC, how about having your own IRC bouncer with ZNC? Or a nifty app to check on the real-time health stats of your system, Linfo.

Migration

Kudos to the Community

Kudos to the community at this time where we had a large influx of new users from Windows Home Server. The team has trouble keeping up (and keeping you up-to-date!)  with everything going on in AmahiLand! We are recruiting to add to our awesome team a passionate community manager with great knack for communication to help us bring news in a concise and fun way to you faster. Interested? Get in touch with the team! (team at this domain …)

We recently have experienced more than triple the usual activity, related to Vail Fail. Lots of great feedback and some well deserved criticism on how to improve Amahi (we hear ya!). If you have spent any time in the Amahi IRC Channel, no doubt you’ve seen a lot of statements like “I’m new to Amahi and Linux, how do I…?” or, “I want to migrate my data from WHS Drive Extender to Amahi and Greyhole.”  These questions, as well as, features, apps, and support requests have generated a flurry of development and community activity. To support this we count with an outstanding community sharing their expertise in the IRC channel, in the wiki, and in the forums. Help is always readily available. So fear not, we few, we band of intrepid explorers in the wonders of the home server are here to aid the newly converted! Welcome fearless brethren, welcome! Special thanks to those new users who hang out in #amahi to help other new users with their expertise, this is very useful!

Amahi Edge!

We had bigger plans for what we used to call Amahi 6. Today we are renaming Amahi 6 to Amahi Edge. In addition of networking improvements and fixes that we have not merged in yet, Amahi Edge is the release with the elusive new dashboard, with more performance and efficiency, a new disk wizard, widgets, gadgets, and other whizzbang tech based on Ruby on Rails 3.0.

Cheers!

The Amahi Team.

[Facebook] [Slashdot] [Twitter]

Amahi on Fedora 14 Alpha Testing!

Fedora 14

Fedora 14 was released a few hours ago and we got a small flood of requests asking if it’s working. It’s getting there! :-)

We found an issue in Fedora 14 upstream that caused the Amahi installer to crash. We’re working around it and we’d like to release it for your testing.

Please see this thread on how to start testing Amahi on Fedora 14!

Many thanks go to bigfoot65 for the quick turn-around in isolating critical issues!

A few things will change, so we ask that you do not put this in a “production” system.

Cheers and happy hacking!

Carlos

[Facebook] [Slashdot] [Twitter]

Trick or Treat?! Celebrate “All Hallows Eve” with a new Amahi release!

As we pondered in all of our geek and glory we decided to expand our story;
Amahi is here with a new release for you to enjoy, but relax it isn’t gory;
Many of the changes are quaint and contain much Amahi Lore;
There is no tapping of chamber doors, only intense mapping of the Amahi Core.
Yet as we speak, we are set to release, many more apps to the app store!
It’s not just this, it’s so much more!

It’s not Halloween without a reading of Edgar Allan Poe’s “The Raven” and while we are not literary poets, Amahi brings poetry-in-motion for the digital management of your media. We’re happy to announce our newest release, a new logo and and update on what’s next!

Amahi 5.6

Many enhancements and some fixes:

  • New platform with a few simplifications in the user interface, major performance improvements for application installs, and some fixes: translations to Spanish/Polish/Japanese, DLNA improvements for .nfo support, enhanced support for elevated privileges in some apps, added functionality for wake-on-LAN (WOL) for dynamic leases, improvements to the Primary Domain Controller (PDC) and more
  • HalloweenA new Greyhole release, v0.6.28, the very popular Storage Pooling technology built in with Amahi, with some stability updates and a new feature: browsing the recycle bin with a share
  • A new release of Amahi Plug Edition, version 1.0, for the popular Plug Computer! This update includes over 10 performance updates and tweaks, so that Amahi can run in even the most resource constrained Plug devices with as low as 128MB of memory, like the Seagate Dockstar or a PogoPlug.

New Logo!

We’ve got a new logo! This is the “dice” logo and we’re very happy to announce this! It turns out that choosing a new logo was a pretty intense experience (with 400+ entries received and so many good designs, mixed with opinions of every kind).

We got a lot of great feedback and we will be deploying the new logo along with a makeover of Amahi’s website soon!

Skipping Fedora 13 for F14

You’ve all been asking and we’ve decided to skip Fedora 13 and head straight to Fedora 14, due in 3 days! This provides numerous advantages to Amahi, including kernel updates without reboots!

We see a pattern of supporting even releases! (We also skipped F11).

Many thanks to obinou and ppmt for testing the new release of the Amahi Plug Edition, to Mouton for the great progress on Greyhole, to all of you in the community who gave feedback for the logo and for helping test the new release! Amahi could not do all this without you!

Cheers!

The Amahi Team

Photo by euart

[Facebook] [Slashdot] [Twitter]

Crank up your media with Videos5 and .. GoogleTV!? (no permission required)

Word of Videos5 was leaked early in its development and, since then, it has been one of the most requested Apps in the history of Amahi. Today we’re happy to release Videos5 and the all-new Gallery 3 live. Two truly powerful apps!

Videos5 lets you stream your media to devices that can support HTML5, like the iPhone, iPad and iPod, Android devices and many others. It even lets you easily queue your media for transcoding to the format appropriate for streaming*.

Videos5 is expected to play well with the much buzzed about Google TV devices (Logitech revue, Sony TV). While everyone is steering people to watch things from the internet … how about watching your media in your screen(s)?!

Here is a quick video tour of the Videos5 app being used from an iPad:

Gallery 3

Gallery 3 is the latest from The Gallery ProjectGallery 2 has been one of the most popular one-click apps in Amahi. So its successor is highly anticipated!

Gallery is the premier open source web based photo album organizer. It gives you an intuitive way to blend photo management seamlessly into your own website whether you’re running a small personal site, large community site, or you’re just running it off of your HDA internally within your own network!

Back to Videos5

Have you ever had that one movie, the one you love, but is just too big for your phone or iPad? Now you can stream your videos to your iPhone/iPod Touch/iPad or browser (and easily transcode it, if necessary)!

Videos5 allows you to stream your MPEG-4 (H.264) videos using any HTML5-compliant browser: Safari, Chrome & Android as well as the new versions of Firefox and Opera.

For each file that isn’t ready to stream, Videos5 will allow you to queue it for background transcoding. It even supports thumbnails. If your Movies share contains folder.jpg and filename.tbn files (also used by XBMC), those will be used in Videos5. Check the Videos5 wiki page for the juicy details.

We anticipate that you are now itching to go try out this new app for yourselves! Videos5 is now live!

As a pioneering leader in digital home management we are proud to bring you these two new apps. So get out there try it and rejoice in the wonders in which Amahi strives to bring you! Both of these apps deserve a Hollywood style Red Carpet Premier!  Flash! Glamour & Glitz!

Amahi is about making networking simple! Because it’s your network!

Cheers!

The Amahi Team

* Transcoding not available yet in the Amahi Plug Edition

[Facebook] [Slashdot] [Twitter]