PDA

View Full Version : µTorrent exploit revealed



torrentslave
02-14-2007, 01:34 AM
http://www.zeropaid.com/bbs/../news/upload/images/thumb/8400.jpgAccording to IT security experts, the latest version of uTorrent is vulnerable to remote exploits.

Today brings news that the popular BitTorrent client server uTorrent (http://www.zeropaid.com/bbs/../news/6184/uTorrent+-+A+Beginner%27s+guide+to+BitTorrent+downloading) is vulnerable to hackers that can infiltrate your PC and execute arbitr ary code if a user opens a manipulated torrent tracker file.

The apparent "glitch" in the software is that torrent tracker fields may contain an "announce" field. Well, if this "announce" field is longer than 4800 bytes, an internal µTorrent (http://www.zeropaid.com/bbs/../news/6184/uTorrent+-+A+Beginner%27s+guide+to+BitTorrent+downloading) buffer overflows, thereby allowing hackers to run their exploits.

For now it's only µTorrent 1.6 build 474 that is affected but, older versions may also contain the bug, and a new version to fix the problem is not yet available.

http://filesharingtalk.com/vb3/images/smilies/news_source.gif Source: http://digg.com/tech_news/mTorrent_gets_hacked_Remote_exploit_revealed

__________________________________________________

got this info on another forum

gamer4eva
02-14-2007, 01:37 AM
That sucks.....going to switch now!!!!

Niteghost
02-14-2007, 01:48 AM
Just lost my appetite, SUCKS bigtime, I guess Azueus:( :( :( :( :( :( :(

Jab
02-14-2007, 01:49 AM
Apparently works on XP SP1 and w2k sp1-4

gamer4eva
02-14-2007, 01:53 AM
Well it only affects those with announce higher than 4800bytes whatever that means.....

Acidice
02-14-2007, 01:59 AM
hmm... how prominent is this? I really don't wanna switch to the cpu-consuming AZ :(

gamer4eva
02-14-2007, 02:00 AM
hmm... how prominent is this? I really don't wanna switch to the cpu-consuming AZ :(

Neither do i......:(

Shadowfire
02-14-2007, 02:05 AM
Heh, and with this, uT does downhill ........

gamer4eva
02-14-2007, 02:10 AM
Heh, and with this, uT does downhill ........

Utorrent began to go downhill when it sold out....:lol:

torrentslave
02-14-2007, 02:14 AM
yep sucks big harry balls!!!!

DefX
02-14-2007, 02:21 AM
this is very upsetting. what are good alternatives out there aside from azureus? Something that doesnt consume lots of RAM.

Alien5
02-14-2007, 02:24 AM
wait for the fix.

Jaits
02-14-2007, 02:38 AM
the tracker owners can perform the fix in the tracker to not allow the faulty torrent to be uploaded.... u shouldnt really be opening torrents that other ppl send u anyhow...

the current shellcode doesnt affect sp2 so most users will be safe....

vali
02-14-2007, 03:39 AM
the tracker owners can perform the fix in the tracker to not allow the faulty torrent to be uploaded.... u shouldnt really be opening torrents that other ppl send u anyhow...

the current shellcode doesnt affect sp2 so most users will be safe....



..........Safe? The only sharing that is safe, is the hand to hand sharing.

LOL

abu_has_the_power
02-14-2007, 06:21 AM
this shouldn't be a problem if you get your torrents from legit sites

nebcat
02-14-2007, 06:25 AM
Oh my god! Switching...Thanks for the heads up!

erRor67
02-14-2007, 06:37 AM
The latest beta fixes this problem.

ewerest
02-14-2007, 06:55 AM
"it only affects those with announce higher than 4800bytes"
and this kind of .torrent files are produced by porposely to hack you.so in the private trackers there is no need to worry about.

Sentient
02-14-2007, 09:41 AM
Heh, and with this, uT does downhill ........

Jesus, there's overreacting and then there's you guys. It doesn't even affect the latest build.

S!X
02-14-2007, 09:46 AM
ah excellent news.. they need a new final build in the works asap...

4play
02-14-2007, 10:55 AM
It really should be a simple fix for this. Im just wondering why there isnt a new version out already.

vipdiablo
02-14-2007, 11:26 AM
yep sucks

biggrizz
02-14-2007, 12:03 PM
This is a bit worrying.I hope something is done soon

Appzalien
02-14-2007, 12:14 PM
I'd heard that some devious character took over the utorrent servers and I remember commenting to the poster and replyers that it didn't matter because utorrent didn't automatically update itself, you would have to download a new version created by this new owner to be vulnerable. And as long as you remained at the last version before he took over you should be ok.

Now that I hear utorrent itself warning customers that "if you know whats good for you you better update" I'm skeptical that a hole even exists. If the posters from before were indeed right, and this guy is devious, then this warning sounds devious as well. I don't know which is worse using an app with a security hole that has never been exploited (although it probably will be now!) or updating to a new version perhaps created with the mpaa and riaa's blessing for all I know.

The third option seems best to me, dump utorrent and use a different p2p client.

Hairbautt
02-14-2007, 02:20 PM
Check nsane, µTorrent 1.6.1.488 Final (http://www.nsaneproductions.com/forums/?showtopic=5525). Besure to subscribe to thread.

mr. nails
02-14-2007, 02:45 PM
488 is released now. meh, i'll update sometime. lol, why are all u worried? do u save credit card numbers and/or bank account numbers on ur pc? if not.. what's the prob?

- Feature: Select upload/download speed for a torrent through the rightclick menu
- Feature: Added encryption box to speed guide
- Change: Don't check as many pieces at the same time.
- Change: Misc WebUI changes.
- Change: Switch to JSON for webinterface
- Fix: Problem with category list in the gui when updated from the webui
- Fix: WebUI not clearing state between requests.
- Fix: Redirect also index.html to guest.html
- Fix: Added On Now shows the time it's added, not loaded.
- Fix: JSON uses " instead of '
- Fix: (a) Upnp fix
- Fix: Show pause icon when checking is paused.
- Fix: Fixed problems with XML parser
- Fix: Don't allow two message boxes to be shown in the RSS window
- Fix: Changed some window titles
- Fix: Fix malformed .torrent exploit
- Fix: Boss key field is now larger

Exploit
02-14-2007, 02:49 PM
yeahh but still a beta :(

mr. nails
02-14-2007, 02:56 PM
yeahh but still a beta :(

it's official. not beta. just cuz it's not on the utorrent site yet doesn't mean it's beta. lol, i have my resources. u'll see.

Hairbautt
02-14-2007, 03:02 PM
yeahh but still a beta :(
It's posted and says "Final" :unsure:

reachnet
02-15-2007, 01:17 AM
I'd heard that some devious character took over the utorrent servers and I remember commenting to the poster and replyers that it didn't matter because utorrent didn't automatically update itself, you would have to download a new version created by this new owner to be vulnerable. And as long as you remained at the last version before he took over you should be ok.

Now that I hear utorrent itself warning customers that "if you know whats good for you you better update" I'm skeptical that a hole even exists. If the posters from before were indeed right, and this guy is devious, then this warning sounds devious as well. I don't know which is worse using an app with a security hole that has never been exploited (although it probably will be now!) or updating to a new version perhaps created with the mpaa and riaa's blessing for all I know.

The third option seems best to me, dump utorrent and use a different p2p client.

That's one of the best examples of "brain-FUD" I think I've ever seen. Congrats ! ;)
To believe or not to believe that is the question. ;)
If it's all the same with you, I think I'll upgrade anywayz ! ;)

erRor67
02-15-2007, 02:03 AM
yeahh but still a beta :(

it's official. not beta. just cuz it's not on the utorrent site yet doesn't mean it's beta. lol, i have my resources. u'll see.
Yes, its a final build. Download it here: http://download.utorrent.com/1.6.1/utorrent.exe

And just so you guys know, this exploit was fixed in a beta build back in July 2006. ;)

mr. nails
02-15-2007, 06:04 AM
I'd heard that some devious character took over the utorrent servers and I remember commenting to the poster and replyers that it didn't matter because utorrent didn't automatically update itself, you would have to download a new version created by this new owner to be vulnerable. And as long as you remained at the last version before he took over you should be ok.

Now that I hear utorrent itself warning customers that "if you know whats good for you you better update" I'm skeptical that a hole even exists. If the posters from before were indeed right, and this guy is devious, then this warning sounds devious as well. I don't know which is worse using an app with a security hole that has never been exploited (although it probably will be now!) or updating to a new version perhaps created with the mpaa and riaa's blessing for all I know.

The third option seems best to me, dump utorrent and use a different p2p client.

stole the quote....

yep, exactly. probably why i'll be installing azureus again anyhow. as, i've not yet intalled this "new" version of utorrent and i mite not.

lynx
02-15-2007, 09:10 AM
This exploit is officially fixed in 1.6.1 build 489, released yesterday.

As erRor67 says, rumour is that it was actually fixed (as a tidying of the code) in the initial release of the Beta back in July 2006, but they hadn't thought of it as a vulnerability so it wasn't mentioned until now.

I've been using the Beta since then and I'm very happy with it, the changes in this final release are minimal and nothing to do with the sellout to bittorrent.

Chip Monk
02-15-2007, 10:01 AM
Cheers for the info, lynx.

Is it best to remove an older version then do a fresh install or is it OK to just download the installer and run it.

kabloomz
02-15-2007, 03:22 PM
Cheers for the info, lynx.

Is it best to remove an older version then do a fresh install or is it OK to just download the installer and run it.


fresh install... dont forget to remember ur settings (if u use any other than default)...

Kab

Hairbautt
02-15-2007, 03:31 PM
Cheers for the info, lynx.

Is it best to remove an older version then do a fresh install or is it OK to just download the installer and run it.


fresh install... dont forget to remember ur settings (if u use any other than default)...

Kab
You can backup the the settings in the docs&settings/applicationdata/utorrent

mr. nails
02-15-2007, 03:46 PM
this final release are minimal and nothing to do with the sellout to bittorrent.

how do u know?

Hairbautt
02-15-2007, 03:54 PM
At nsane:



So, safe to use after µtorrent joinup with bittorrent?

Bittorrent, Inc bought the right to use uTorrent's core. They do not own uTorrent, or have any power to interfere with the development.

I just keep checking to see if anyone has problems, so far none.

mike7778
02-16-2007, 06:31 AM
HAS anyone had any problems with Utorrent?

S!X
02-16-2007, 08:54 AM
Cheers for the info, lynx.

Is it best to remove an older version then do a fresh install or is it OK to just download the installer and run it.

I just replaced my .exe file in the installation directory since this version doesn't have an installer.

mr. nails
02-16-2007, 08:59 AM
no official release in about a year and now 3 releases in 3 days. 490 is out. lol, have fun.

Jaits
02-17-2007, 08:23 PM
the tracker owners can perform the fix in the tracker to not allow the faulty torrent to be uploaded.... u shouldnt really be opening torrents that other ppl send u anyhow...

the current shellcode doesnt affect sp2 so most users will be safe....



..........Safe? The only sharing that is safe, is the hand to hand sharing.

LOL

maybe for u in terms of ur reality.... which i guess is quite limited....

Washy
02-18-2007, 10:18 AM
Has the issue been resolved with the latest release?

W.

mr. nails
02-18-2007, 11:22 AM
Has the issue been resolved with the latest release?

W.

i was never having an issue with version 1.6 build 474. i won't be updating anytime soon either. also, my build i'm using works with windows vista ultimate 64bit edition for those who need to know.

tailz
02-19-2007, 08:01 AM
Switch!

durex
02-19-2007, 09:41 AM
HAS anyone had any problems with Utorrent?

no problems, so far ...
:)