+ Reply to Thread
Results 1 to 3 of 3

Thread: Soulseek P2P Application Vulnerable to Remote Takeover

  1. #1
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,549
    Activity Longevity
    11/20 19/20
    Today Posts
    1/5 ssss39549

    Soulseek P2P Application Vulnerable to Remote Takeover

    Soulseek is one the greatest music sharing networks that most people have never heard of, with a particular specialty in electronic music. Unfortunately, for nearly a year those using versions of the official client have been exposed to a highly critical vulnerability which can leave them open to remote takeover.
    Soulseek P2P Application Vulnerable to Remote Takeover | TorrentFreak
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    alpacino (31.05.09)

  3. #2
    Advanced User alpacino's Avatar
    Join Date
    18.03.09
    Location
    locked in Alchemilla Hospital
    P2P Client
    none, just the toolz
    Posts
    2,071
    Activity Longevity
    2/20 18/20
    Today Posts
    0/5 sssss2071
    Damn, and I use soulseek on a weekly basis. Thanks for the advice, will try this Nicotine plus as suggested on the article.
    it's hip to be square
    Reply With QuoteReply With Quote
    Thanks

  4. #3


    Join Date
    22.06.08
    Location
    astral planes
    P2P Client
    sbi finest
    Posts
    3,125
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss3125
    looks like it has been fixed:

    from slsk forums:

    There's a number of us monitoring this sort of thing and we all seem to have heard about it in the last two days. I'm not doubting mr. Laurent Gaffie had tried contacting us in the last year, but none of us had intercepted any communication of the sort. Anyway, not restricting search packet length is definitely an oversight on my part. There's a limit on general packet length but I can see how that wouldn't be sufficient. I've placed a 256 character limit on all manners of search (distributed, room, userlist) on both the old and new servers. This needs only be done server-side and doesn't require a client update. I hope this should effectively plug the security hole, but will keep looking for any further signs of vulnerability. Thanks, Nir
    Reply With QuoteReply With Quote
    Thanks

  5. Who Said Thanks:

    alpacino (01.06.09)

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •