.htaccess use and Network Access Protection

Post your questions about Web Server usage and Apache + PHP + MySQL/SQLite web applications.

.htaccess use and Network Access Protection

Postby PharCyder » Tue May 15, 2012 3:54 am

Hi,

First time posting so please be gentle :D I've just bought my first QNAP product, namely a TS-412 running FM 3.6.1. Whilst I'm finding the CPU a bit of a bottleneck, I love it.

I bought it primarily for home use as a private cloud. I have port forwarded the PPTP VPN and SSL (Apache on 443) ports to my QNAP. I have also installed AjaXplorer v4 for Web based accessed. I figured this is a better option than allowing the default WebFM in as this means the Admin GUI is exposed too as they run off the same web server. All is setup and working a-OK.

Because this is exposed to the Internet, I want to ensure its locked down as much as possible. Other than the obvious best practice of strong passwords, I'm using Network Access Protection functionality on all protocols. This seems to work fine except for HTTP(S) protection. I figured that as AjaXplorer uses its own user accounts and so its own authentication, failed auth attempts won't be caught using Network Access Protection (would love to be proved wrong).

Thinking I could make use of the IP banning functionality at the Apache level itself, I thought by setting up .htaccess authentication, failed auth attempts would be caught as Apache is the authenticator. Sadly, they are not being caught making the Web Server a target for dictionary or other brute force attacks.

Is this right or does Network Access Protection only work with the Admin/WebFM web server? If not, how can one make it work with Apache auth?

Thanks
PharCyder
Know my way around
 
Posts: 125
Joined: Sun Apr 01, 2012 12:03 am
Location: London, UK
NAS Model: TS-559 Pro+

Re: .htaccess use and Network Access Protection

Postby PharCyder » Thu May 17, 2012 5:21 am

Bump - anyone?
PharCyder
Know my way around
 
Posts: 125
Joined: Sun Apr 01, 2012 12:03 am
Location: London, UK
NAS Model: TS-559 Pro+

Re: .htaccess use and Network Access Protection

Postby schumaku » Thu May 17, 2012 5:15 pm

The Network Access Protection is not intended to be expandable to other logs - that's why you dont get replies.
User avatar
schumaku
Guru
 
Posts: 22571
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro

Re: .htaccess use and Network Access Protection

Postby PharCyder » Thu May 17, 2012 5:39 pm

So expected behaviour is that HTTP(S) Network Access Protection only works on the Webserver that hosts the Admin GUI and WebFM?
PharCyder
Know my way around
 
Posts: 125
Joined: Sun Apr 01, 2012 12:03 am
Location: London, UK
NAS Model: TS-559 Pro+

Re: .htaccess use and Network Access Protection

Postby schumaku » Thu May 17, 2012 9:54 pm

Yes. Not even the QNAP-own Multimedia Station (MSV2), PhotoStation, or MusicStation are covered by the Network Access Protection on the "real" Web server side.

For years, I'm challenging QNPA to migrate the administration away from that rubbish (ie. 2 GB file size limit) and limiting ocntrollable thttpd to the real Apache Web server. Nothing in sifght yet.
User avatar
schumaku
Guru
 
Posts: 22571
Joined: Mon Jan 21, 2008 4:41 pm
Location: Kloten (Zurich), Switzerland -- Skype: schumaku
NAS Model: TS-x79 Pro


Return to Web Server & Applications (Apache + PHP + MySQL / SQLite)

Who is online

Users browsing this forum: bigspender and 2 guests