+ Reply to Thread
Page 1 of 6 123 ... LastLast
Results 1 to 15 of 82

Thread: Critical Vulnerability Discovered in uTorrent

  1. #1
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458

    Critical Vulnerability Discovered in uTorrent

    A vulnerability described as ‘critical’ has been discovered in versions of uTorrent and the official BitTorrent client. The ‘buffer overflow’ vulnerability can be exploited to compromise a user’s computer for the execution of arbitrary code. It is suggested that users should immediately update to uTorrent version 1.8 RC7 or higher. There is currently no fix for the official client.

    ...

    ... “the vulnerability is caused due to a boundary error in the processing of .torrent files. This can be exploited to cause a stack-based buffer overflow by tricking the user into opening a .torrent file containing an overly long ‘created by’ field”.
    Critical Vulnerability Discovered in uTorrent | TorrentFreak
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    Aurion (13.08.08)

  3. #2

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    LOL u got to be kiddin me ?!! isnt uT a closed source client ?? how come out sources can access users hash info for example to compromise weak points off of the client
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    This is not the first time a potential vulnerability is discovered in uT ^^
    It doesn't matter if the product is open or closed source, hackers can still find things like this just like every software can be cracked
    For example old versions of IE had this bug where loading an image with huge "width" and "height" values defined in the IMG tag of an HTML document would crash the browser...
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  5. #4

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Logitech is searching Milw0rm.

    .................

    aaahhhh only for version 1.7.7:(
    Reply With QuoteReply With Quote
    Thanks

  6. #5
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    Mmm... what did you want to do?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  7. #6

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    By looking in the peerlist I see that much people still use uT 1.7.7:).

    @anon: nothing
    Reply With QuoteReply With Quote
    Thanks

  8. #7
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    It always takes a while for new versions to spread. But this time there's a good incentive to update...

    Quote Originally Posted by Logitech View Post
    @anon: nothing
    Make sure that's how it stays
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  9. #8

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Make sure that's how it stays
    anon of what tracker where you member of?
    Last edited by Logitech; 14.08.08 at 23:43.
    Reply With QuoteReply With Quote
    Thanks

  10. #9
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    Many, but what does it have to do with this...?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  11. #10

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    I was thinking about uploading some torrents with a shellcode in it.

    Edit: I edited my previous post maybe you understand why now.
    Last edited by Logitech; 14.08.08 at 23:43.
    Reply With QuoteReply With Quote
    Thanks

  12. Who Said Thanks:

    anon (14.08.08)

  13. #11
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    How would it be run?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  14. #12

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Quote Originally Posted by anon View Post
    How would it be run?
    My little secret
    Reply With QuoteReply With Quote
    Thanks

  15. #13
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    *.torrent shell code execution exploit by Logitech is released*
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  16. #14

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    @anon: I believe that anything could be done with any piece of software as long as it has a source code sheet !! anyway,hope no body else messes with uT since its my fave one at all times,secure,resource saving & very fast reliable bittorrent client !!

    @Logitech: lol maybe u need to share with us (joking if u dont want to for sure) that little secret Hunny !! maybe injecting a torrent file with a shellcode will make it more secure ?? dont know im just guessing
    Reply With QuoteReply With Quote
    Thanks

  17. #15
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    Logitech's shellcode would run his favorite trojan when the torrent is loaded
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread
Page 1 of 6 123 ... LastLast

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •