<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://archivedforum.beoworld.org:443/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>BeoSound 5 Forum</title><link>https://archivedforum.beoworld.org:443/forums/53.aspx</link><description>Learn all about the functionality and solve your set-up issues on this Forum.</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP2 (Build: 31104.93)</generator><item><title>Re: BM5 Software issues</title><link>https://archivedforum.beoworld.org:443/forums/thread/246977.aspx</link><pubDate>Fri, 18 Dec 2009 17:03:20 GMT</pubDate><guid isPermaLink="false">41a2a90c-3a1e-4bd3-b144-3883695a7f38:246977</guid><dc:creator>zett</dc:creator><slash:comments>0</slash:comments><comments>https://archivedforum.beoworld.org:443/forums/thread/246977.aspx</comments><wfw:commentRss>https://archivedforum.beoworld.org:443/forums/commentrss.aspx?SectionID=53&amp;PostID=246977</wfw:commentRss><description>&lt;p&gt;In hindsight my example of someone stealing music was a very bad one.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;The probability that someone would put any effort in messing with a music collection is without doubt very low, however not unlikely!&lt;br /&gt;&lt;br /&gt;What one could worry about are all the people on the Internet wanting to run a botnet.&amp;nbsp; They don&amp;rsquo;t care about the contents on a computer; their incentive is to control it.&amp;nbsp; Even though BM5&amp;rsquo;s are rare they are still vulnerable when unpatched and consequently a very desirable target.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I&amp;rsquo;m just keeping my fingers crossed that B&amp;amp;O, will include a patched version of XP in a future software update.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: BM5 Software issues</title><link>https://archivedforum.beoworld.org:443/forums/thread/246702.aspx</link><pubDate>Thu, 17 Dec 2009 11:25:42 GMT</pubDate><guid isPermaLink="false">41a2a90c-3a1e-4bd3-b144-3883695a7f38:246702</guid><dc:creator>Stan</dc:creator><slash:comments>0</slash:comments><comments>https://archivedforum.beoworld.org:443/forums/thread/246702.aspx</comments><wfw:commentRss>https://archivedforum.beoworld.org:443/forums/commentrss.aspx?SectionID=53&amp;PostID=246702</wfw:commentRss><description>&lt;p&gt;The way I look at it is that it is a very big world.&amp;nbsp; There are millions of computers on the internet.&amp;nbsp; There are maybe 10,000 BM5s (I&amp;#39;m only guessing, it could be more or less, but for argument let&amp;#39;s just say 10K).&amp;nbsp; Do I really believe that somebody will hack through my router and go after my BM5 and delete my music (which I have backed up anyway)?&amp;nbsp; This seems very unlikely (like finding a needle in a hay stack).&amp;nbsp; There are many more desireable targets among those millions of computers out there.&amp;nbsp; Maybe I&amp;#39;m blissfully ignorant, but I just don&amp;#39;t worry about this.&lt;/p&gt;
&lt;p&gt;Stan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: BM5 Software issues</title><link>https://archivedforum.beoworld.org:443/forums/thread/246553.aspx</link><pubDate>Wed, 16 Dec 2009 17:25:40 GMT</pubDate><guid isPermaLink="false">41a2a90c-3a1e-4bd3-b144-3883695a7f38:246553</guid><dc:creator>zett</dc:creator><slash:comments>0</slash:comments><comments>https://archivedforum.beoworld.org:443/forums/thread/246553.aspx</comments><wfw:commentRss>https://archivedforum.beoworld.org:443/forums/commentrss.aspx?SectionID=53&amp;PostID=246553</wfw:commentRss><description>&lt;p&gt;Thanks for the reply and the tips re. router configuration.&lt;br /&gt;&lt;br /&gt;I agree with you that anybody setting up port forwarding to the BM5 would be unlikely. &lt;br /&gt;&lt;br /&gt;Network security is a complex subject and always entails compromises. &lt;/p&gt;
&lt;p&gt;My view is that a chain is only as strong as its weakest link; I would feel much more comfortable with a patched version of XP rather than putting all my trust in the router.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: BM5 Software issues</title><link>https://archivedforum.beoworld.org:443/forums/thread/246145.aspx</link><pubDate>Tue, 15 Dec 2009 23:08:58 GMT</pubDate><guid isPermaLink="false">41a2a90c-3a1e-4bd3-b144-3883695a7f38:246145</guid><dc:creator>Stan</dc:creator><slash:comments>0</slash:comments><comments>https://archivedforum.beoworld.org:443/forums/thread/246145.aspx</comments><wfw:commentRss>https://archivedforum.beoworld.org:443/forums/commentrss.aspx?SectionID=53&amp;PostID=246145</wfw:commentRss><description>&lt;p&gt;If you have a typical home network with a single IP address provided by your ISP, one must generally configure &amp;quot;port forwarding&amp;quot; for any &amp;quot;outside&amp;quot; computer to access any computer in your home network.&amp;nbsp; That is, the router &amp;quot;owns&amp;quot; the IP address that is visable to the outside world.&amp;nbsp; If you haven&amp;#39;t forwarded any ports to your BM5, you don&amp;#39;t have to worry about a hacker accessing it (unless it is on an unsecure wireless network - but then you have bigger problems).&amp;nbsp; The BM5 can talk to outside computers (for N.Radio or software downloads) without port forwarding because it initiates the coversation.&lt;/p&gt;
&lt;p&gt;Stan&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>BM5 Software issues</title><link>https://archivedforum.beoworld.org:443/forums/thread/246108.aspx</link><pubDate>Tue, 15 Dec 2009 16:08:40 GMT</pubDate><guid isPermaLink="false">41a2a90c-3a1e-4bd3-b144-3883695a7f38:246108</guid><dc:creator>zett</dc:creator><slash:comments>0</slash:comments><comments>https://archivedforum.beoworld.org:443/forums/thread/246108.aspx</comments><wfw:commentRss>https://archivedforum.beoworld.org:443/forums/commentrss.aspx?SectionID=53&amp;PostID=246108</wfw:commentRss><description>&lt;p&gt;Hi all,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I&amp;rsquo;m new here so please forgive me if this post is in the wrong category.&amp;nbsp; Having said that here goes:&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I have a BS5/BM5 system that&amp;rsquo;s been up and running for a while now and the software have been updated twice.&amp;nbsp; All in all I&amp;rsquo;m happy with the setup, despite some software related quirks.&lt;br /&gt;&lt;br /&gt;When checking my home computer network (in which BM5 is a part) with Nessus, a security scanner (www.nessus.org), BM5 was flagged with several vulnerabilities.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Microsoft categorizes two of these as critical:&lt;br /&gt;&lt;br /&gt;MS08-067: Microsoft Windows Server Service Crafted RPC Request Handling Remote Code Execution (958644)&lt;br /&gt;&lt;br /&gt;MS09-001: Microsoft Windows SMB Vulnerabilities Remote Code Execution (958687)&lt;br /&gt;&lt;br /&gt;MS-08-067 is perhaps the most severe of these two - it allows an outside hacker to run his or her own software or commands on the BM5, e.g. someone could steal or erase your entire music collection, or use the BM5 to steal personal data from other computers connected to the BM5. &lt;br /&gt;&lt;br /&gt;Microsoft released a patch addressing this problem in October 2008, however it appears as if this patch has been omitted in the updates from B&amp;amp;O.&lt;br /&gt;&lt;br /&gt;By using Metasploit -tool for exploit research and penetration testing (www.metasploit.com) you can verify that the BM5 is wide open to hackers. &lt;br /&gt;&lt;br /&gt;Does anyone here know if there is a patch available or could anyone suggest appropriate rules for a firewall?&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>