Is subsonic really that insecure?
Hello everybody,
I'm wondering when I open a m3u-playlist (which I got from subsonic) in an editor and copy the URL 'http://$url:$port/stream?player=3&id=8283&suffix=.mp3' and give this URL any person, why can he open and listen to it?? Without any password, login, and something else. Sure there's no password or something in the URL, but I expected at least an IP check or something like that?
So if someone does a portscan and finds the subsonic port he can simply download my whole music library by incrementing the id-number??? Is that true?
Greetings from Germany
shavenne
I'm wondering when I open a m3u-playlist (which I got from subsonic) in an editor and copy the URL 'http://$url:$port/stream?player=3&id=8283&suffix=.mp3' and give this URL any person, why can he open and listen to it?? Without any password, login, and something else. Sure there's no password or something in the URL, but I expected at least an IP check or something like that?
So if someone does a portscan and finds the subsonic port he can simply download my whole music library by incrementing the id-number??? Is that true?
Greetings from Germany
shavenne