So something extremely strange and scary happened the other night, short and simple someone was on my sharing list whom I never sent an invite!
I was scared at first thinking but the more I searched I never knew who this user was and it was extremely late at night for any of my family or friends to view anything.
I shut the server down and unplugged the Ethernet cable paranoid as hell than I changed my password to Plex thinking this person invited themselves.
Could there be a security loophole that hackers use to navigate to someone’s Plex and add themselves and view content?
The only thing I did differently that night was using the Plex app on the playstation for the first time, it required me to login via my phone and after that I watched an episode and as I was going to sleep heard my server kick off again.
That’s when I looked at who was up late and the unknown user login, I tried to stop the stream but was unable to right away so I just deleted from the sharing tab and shut off the server, unplugged the Ethernet after that.
I believe maybe that authentication during the ps app probably exploited my password somewhere I changed my password with a heavy authentication password but I have a feeling there might be a security exploit on the playstation Plex app.