Security Variability - Unauthorised Access to Users Plex server

I was able to get access to another Plex users account and PMS through remote.plex.tv/desktop without ever entering the password; or the email for that matter.

So, When I went to app.plex.tv/app yestartday (19/03/19) another user email address was pre-filled. Out of curiosity I pressed login expect to be promted for a password. This however never happened as was able to access to all the movie and personal images of this user. I was also able to see this users WAN IP address and login to the server directly via the port number (which I could find in the setting).

I will refer to this user a “Sven” from now on. I want to state that I have never met, chatted or had any other communication with Sven, till yesterday. Out of respect for another PMS user I emailed him and he has changed his password.

The only thing from troubleshooting that I could find is that I user PIA (Private internet access) to the Netherlands. This could be the reason that I have the problem. Possible to do with a shared IP address. 212.92.121.97

I work in IT but not Net-sec so I can understand quite a bit but not everything.

Any support help would be great.

Kind regards

James

The user has probably used wrong settings for local authentication, i.e. disabled auth for the PIA ip addresses :sweat_smile:

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.