OnlineVideos 0.33 (19.09.2011) (1 Viewer)

Status
Not open for further replies.

doveman

Portal Pro
February 12, 2008
2,326
178
Home Country
United Kingdom United Kingdom
Just had an error pop-up referencing OnlineVideos and saying that MP had crashed and had to close.

I didn't notice it for some time and MP kept running fine until I clicked OK, when it closed.

I think the crash was caused when I accidentally selected Download, but I don't see why this should make MP crash.
 

Carlo

Portal Member
November 4, 2009
9
0
As I said, they've hidden it well...
I guess you have to check with a network sniffer to see where the video is coming from, and see if you can trace back that video-source to something in that html.

But I can assure you: that isn't going to be easy

Thank you, I misunderstood your first post slightly. Now it's clear.
The great news is, I do not need to do it, as I found out, that the videos I'm looking for, are already contained within the big offer of "das erste - Mediathek" ... so all work for nothing. But nice to have them running now ;-)
 

parkuhr

Portal Pro
September 2, 2007
357
4
Home Country
Germany Germany
AW: OnlineVideos 0.33 (19.09.2011)

first i have to say thx for this great plugin!

but there is something you should change soon as passible!:

big security hole found:

onlinevideo is saving acount-data and password in cleartext! in the logs.
even if you collect logs for bug report with mediaportal startet in the debug-mode, you see the acount-data with password from onlinevideos in cleartext! in the logs!

for me this is a BIG security hole and concern everyone of us, who is sending logs for bug reports etc.
please try to change that, so that people can keep their privacy and sensible personal data, if they use onlinevideos.

greetings and best regards
parkuhr
 

offbyone

Development Group
  • Team MediaPortal
  • April 26, 2008
    3,989
    3,712
    Stuttgart
    Home Country
    Germany Germany
    Can you prove this by posting logs that contain your account and password infos (make them ***** before).
     

    parkuhr

    Portal Pro
    September 2, 2007
    357
    4
    Home Country
    Germany Germany
    AW: Re: OnlineVideos 0.33 (19.09.2011)

    Can you prove this by posting logs that contain your account and password infos (make them ***** before).

    yes of course!

    logs attached: search for the row: youtube and look for my entries: (acountname and pw removed).

    by the way: the fritzbox-plugin has the same problem: saving username and password of your fritzbox-router also in cleartext!
    have this also deletet from the log.

    best regards
    greetings
    parkuhr

    p.s.: log removed for security reasons.
     

    SilentException

    Retired Team Member
  • Premium Supporter
  • October 27, 2008
    2,617
    1,130
    Rijeka, Croatia
    Home Country
    Croatia Croatia
    Re: AW: Re: OnlineVideos 0.33 (19.09.2011)

    Can you prove this by posting logs that contain your account and password infos (make them ***** before).

    yes of course!

    logs attached: search for the row: youtube and look for my entries: (acountname and pw removed).

    by the way: the fritzbox-plugin has the same problem: saving username and password from you fritzbox-router also in cleartext!
    have this also deletet from the log.

    best regards
    greetings
    parkuhr

    It's not possible to fix that. Even if UN/PW was encrypted in config, OV needs to decrypt it so decryption routine is known. Or you want to be asked for master password every time you use OV? ;)
     

    parkuhr

    Portal Pro
    September 2, 2007
    357
    4
    Home Country
    Germany Germany
    AW: OnlineVideos 0.33 (19.09.2011)

    then we must find a secure way for bug reports, if such sensible data are in the logs!
    sure you can try to search the whole logs and hope that you not forget to delete all! personal/sensible data. but this will cost you much time and you never can be sure, that you have not forget to delete one of the sensible entrys.
    i see this as an big proplem and not only onlinevideo seem to have this security bug...
    i like this plugin very much and i am very thankfull for the hard work offbyone and probable many others invest in this plugin.
    this should also be no offence! i only try to find a solution with you for this proplem

    best regards
    greetings
    parkuhr
     

    offbyone

    Development Group
  • Team MediaPortal
  • April 26, 2008
    3,989
    3,712
    Stuttgart
    Home Country
    Germany Germany
    Since when is MediaPortal.xml a log file? It's the config file for MediaPortal and NOT in the logs dir...

    Where else would we store configuration data?
     

    SilentException

    Retired Team Member
  • Premium Supporter
  • October 27, 2008
    2,617
    1,130
    Rijeka, Croatia
    Home Country
    Croatia Croatia
    Since when is MediaPortal.xml a log file? It's the config file and NOT in the logs dir...

    It is unfortunately packed with WatchDog logs. But OV is not the only plugin with this problem. Any plugin where passwords are used has the same problem. Unless it's closed source. But that's just security through obscurity.
     

    parkuhr

    Portal Pro
    September 2, 2007
    357
    4
    Home Country
    Germany Germany
    AW: Re: OnlineVideos 0.33 (19.09.2011)

    Since when is MediaPortal.xml a log file? It's the config file for MediaPortal and NOT in the logs dir...

    like SilentException already said: "It is unfortunately packed with WatchDog logs."
    i am also not sure if the MediaPortal.xml is the only logfile, wich contains sensible data.
    there are to many logs, to search in every one of it for sensible data.
    and he is also right that ov is not the only plugin with this proplem. the other plugin i have mentioned, has the same proplem and very probable many other plugins too.
    so it seems a generall proplem of some plugins and its not only concern onlinevideos.
    but onlinevideos is one of my favorite plugins:), so i found that out with onlinevideos.
    a few days ago, i talked to the devs in mediaportal irc-channel about this.
    they said, that this a proplem from the plugin-devs of the concerned plugins and i should create a thread in the forum of the concerned plugins.
    therefore i createt this thread.

    -------------

    so if this should really not be fixable, then we should make us some thoughts for the future of posting logs for bug reports.
    i don t want to say that all here are bad guys, the opposite is the case:
    the most people i had to do here through the years, were nice and friendly, this includes of course offboyne:)
    but you never know..! if this sensible data comes in the "wrong hands" then you have a proplem!
    i think this concerns many of us wich are helping to make mediaportal and plugins better with bug reports and attaching logs for that...

    best regards
    parkuhr
     
    Status
    Not open for further replies.

    Users who are viewing this thread

    Top Bottom