-
To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
rvt
I've spent some time looking into this issue.
The POC code on milw0rm relies on creating a malicious torrent file which the uT user opens. On any sites without public uploads, or those that clean the uploaded torrents, there is no real problem.
Another issue mentioned on torrentfreak recently revolves around an overflow bug in extended messaging.
When an attacker sends a long enough string for version info, and the user views the peers tab, uT will crash.
1.6.x versions are not vulnerable to this attack, as they never display the version info obtained from extended messaging in the peers tab.
1.7.x are vulnerable.
Have not tested 1.8.x
1.6.x still has some life in it yet :P
Quote:
Originally Posted by
rvt
1.6.1 (488) fine
1.6.1 (489) fine
1.6.1 (490) fine
1.7.0 (3353) bugged
1.7.1 (3360) bugged
1.7.2 (3458) bugged
1.7.3 (4470) bugged
1.7.4 (4482) bugged
1.7.5 (4602) bugged
That's in relation to the new bug that allows anyone to crash your uT.
For the old POC code from milw0rm, it only works if an attacker can get you to open a torrent file with a very large announce URL, because the announce URL contains the exploit. On private sites using passkeys, that announce URL is changed anyway so a torrent you donwload from them can never contain the exploit.
For public trackers, you can stay safe if you open the file in torrentspy before opening in uT.
http://torrentspy.sourceforge.net/
If the announce URL is not valid, opening it in torrentspy will show you that.
i like to know the reason behind banning of 1.6.1 which is safe according to an experienced staff/coder !
:mellow:
update :
bitme, bitmetv, blackcats-games, what, waffles ,revtt have all unbanned 1.6.1
:)
update 2 :
Quote:
Originally Posted by
rvt
Fix: remote crash bug (affects 1.7.x, and 1.8 builds released to date)
it doesnt affect 1.6.x
:)
-
Re: To BT site staff about utorrent 1.6.1 !
-
Re: To BT site staff about utorrent 1.6.1 !
Nice topic. Kinda want to know myself. I did obviously upgrade though. Not going to risk my account for not following orders.
-
Re: To BT site staff about utorrent 1.6.1 !
Because if you check utorrent site they say 1.6.1 is vulnerable and many just take the info from that. But if rvt info, can be backed up by another coder, maybe staff will reconsider bans.
Also great post LordS
-
Re: To BT site staff about utorrent 1.6.1 !
Edit: In regards to uT saying it affects 1.6.x, that is a lie put out to get people to upgrade.
One of the bittorrent devs said in their forum that it does not affect 1.6.x
http://forum.utorrent.com/viewtopic....298736#p298736
End Edit
It can be confirmed easily enough.
I have some php code for crashing uT posted at p2pg and tbdev. We have a fair amount of sites on p2pg, and they can spread the code out to other sysops/coders. The code is in the VIP section at tbdev to keep it out of the public eye. If any sysop wants a copy, drop me a PM.
The POC code for executing code on 1.6 is available at milw0rm. What it does is change the announce URL to a lot of code that doe not represent a real URL in any way. I would post an example, but it's full of all sorts of control characters and isn't pretty.
Any tracker using passkeys is going to replace that URL with their own one anyway, so none of these malformed torrents will be downloadable from private trackers.
On public trackers, these torrents will be deleted very quickly because the announce URL is not valid and so they cannot work on any client.
For anyone testing the milw0rm exploit, if you are getting segmentation faults, make sure the torrent file you use as input has a comment after the announce URL.
d8:announce10:01234567897:comment10:0123456789 << like that
The code uses the 7:comment part to work out where to split.
BTW, the milw0rm code does not work on XP SP2 far as I can tell.
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
rvt
Edit: In regards to uT saying it affects 1.6.x, that is a lie put out to get people to upgrade.
One of the bittorrent devs said in their forum that it does not affect 1.6.x
http://forum.utorrent.com/viewtopic....298736#p298736
It can be confirmed easily enough.
I have some php code for crashing uT posted at p2pg and tbdev. We have a fair amount of sites on p2pg, and they can spread the code out to other sysops/coders. The code is in the VIP section at tbdev to keep it out of the public eye. If any sysop wants a copy, drop me a PM.
The POC code for executing code on 1.6 is available at milw0rm. What it does is change the announce URL to a lot of code that doe not represent a real URL in any way. I would post an example, but it's full of all sorts of control characters and isn't pretty.
Any tracker using passkeys is going to replace that URL with their own one anyway, so none of these malformed torrents will be downloadable from private trackers.
On public trackers, these torrents will be deleted very quickly because the announce URL is not valid and so they cannot work on any client.
For anyone testing the milw0rm exploit, if you are getting segmentation faults, make sure the torrent file you use as input has a comment after the announce URL.
d8:announce10:01234567897:comment10:0123456789 << like that
The code uses the 7:comment part to work out where to split.
BTW, the milw0rm code does not work on XP SP2 far as I can tell.
thanks for the hard work rvt, it's great to know 1.6.1 is still good.
all we need to do now is convince staffers :)
-
Re: To BT site staff about utorrent 1.6.1 !
thanks a lot again rvt :)
ok so the ut forum itself says 1.6 is safe
and rvt has confirmed that private trackers wont be affected by this exploit
so what are we waiting for ? unban 1.6 :happy:
-
Re: To BT site staff about utorrent 1.6.1 !
still no comments from other bt staff ? huh
-
Re: To BT site staff about utorrent 1.6.1 !
Probably not until uTorrent them selves say it is safe again. Until then, probably not.
-
Re: To BT site staff about utorrent 1.6.1 !
BCG is allowing 1.6.#
we are banning all 1.7 earlier than 1.7.6
and we dont allow alpha/beta anyway so 1.8 is not allowed yet.
-
Re: To BT site staff about utorrent 1.6.1 !
Alpha's tend to be really buggy anyways. I would diverge users from them, unless your a developer or beta tester of course.
-
Re: To BT site staff about utorrent 1.6.1 !
i would like to go back to 1.6.1 just because 1.7.6 takes me 30 seconds or more before it actually starts downloading anything and ive even had a few times where it didnt connect to any peers until i restarted utorrent. could be a problem on my end, but it hasnt ever happened on 1.6.1. nice work rvt.
-
Re: To BT site staff about utorrent 1.6.1 !
^Never experienced anything similar...
-
Re: To BT site staff about utorrent 1.6.1 !
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
aysomc
i would like to go back to 1.6.1 just because 1.7.6 takes me 30 seconds or more before it actually starts downloading anything and ive even had a few times where it didnt connect to any peers until i restarted utorrent. could be a problem on my end, but it hasnt ever happened on 1.6.1. nice work rvt.
I agree. Also i can't use myspleen now. They banned ut 1.7.6. Bad client according to them. I now also have problems downloading from some trackers. It may change now though since alot of people are forced to upgrade since most trackers have now offically banned 1.6.1 (most not all).
-
Re: To BT site staff about utorrent 1.6.1 !
ffs, i was forced to upgrade to 1.7.6 cuz revTT allows no earlier versions.
TL also recommends upgrading.
i hope this situation is just temporary and they will allow again using 1.6.x versions. i agree with the ban on 1.7.x prior to 1.7.6 though.
-
Re: To BT site staff about utorrent 1.6.1 !
As pointed out by rvt, the vulnerability is exploited by crafting a specific tracker URL. Practically every private torrent site will change the URL by adding a passkey to it, therefore destroying any attempt at a malicious URL.
The only place where these exploits can actually be practised would be on the public trackers, because if anyone was stupid enough to try this on a private tracker, their details would be circulated quicker than a Scotsman could down a bottle of whisky.
-
Re: To BT site staff about utorrent 1.6.1 !
SCT have forced upgrading, so the massive userbase there, who are indeed shared amongst FSC and FTN will have upgraded. As long as a few big torrent sites force the move to 1.7.6 (what and waffles did as well?) i doubt many will remain with 1.6.1 (except those still caught up in the consipracy theories)
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
rvt
Edit: In regards to uT saying it affects 1.6.x, that is a lie put out to get people to upgrade.
One of the bittorrent devs said in their forum that it does not affect 1.6.x
Yes, its obvious. Even 1.6 has not such a vulnerability unless you are using xp without upgrades. My utorrent always crashed when my computer auto-shut down during power failures with xp with no service packs installed. However, since when i upgraded with sp2, there are no problems. Still i'm using 1.6, not even 1.6.1
Why trackers enforce it? I find only one reason. Many complain in the forums that their utorrent crashed and so they couldn't seed acc to tracker rules. The result is obvious. I always keep a back up copy of my utorrent settings, though i never needed to use it.
Another reason could be cheating. Staff might think they can beat cheaters cause they might have the old version based cheating clients. lol
However, i'm not against this forced upgrade, but if all trackers do it, it'd be appreciated.
...
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
pandabear
i doubt many will remain with 1.6.1 (except those still caught up in the consipracy theories)
It's not just about conspiracy theories anymore though is it?
Even if you disregard the fact that utorrent development is now partly funded by 20th Century Fox etc, this situation has proven that every version of the client since BitTorrent Inc took over has had serious flaws. That diminishes my confidence beyond just being paranoid.
None of the sites that I use have bought into the scaremongering about 1.6 yet, so I'll continue using it. Never had a problem with it so why change?
:cool:
-
Re: To BT site staff about utorrent 1.6.1 !
The staff might have their own reasons that they don't want to reveal? Or is it the only good version after utorrent 1.6.1 that they want all users use the same in order to ease check on cheaters?
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
that is a lie put out to get people to upgrade.
I was pretty damn sure about this.
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
TheFoX
As pointed out by rvt, the vulnerability is exploited by crafting a specific tracker URL. Practically every private torrent site will change the URL by adding a passkey to it, therefore destroying any attempt at a malicious URL.
The only place where these exploits can actually be practised would be on the public trackers, because if anyone was stupid enough to try this on a private tracker, their details would be circulated quicker than a Scotsman could down a bottle of whisky.
so why does some private trackers ban it ? :sadwalk:
they dont have good coders that can actually test this issue ?
maybe we should post this thread in every private tracker forum ! :mellow:
-
Re: To BT site staff about utorrent 1.6.1 !
i still hope sct and hdbits will change their minds again..
its quite stupid to read in the hdbits forum something like hey µ 1.6.1 is old, upgrade to 1.7.6!..
if they dont change it i will have to switch to another client i have no problems with as i always had funny time outs with 1.7.x versions.. and some other weird problems..
-
Re: To BT site staff about utorrent 1.6.1 !
version 1.7.6 is finally starting to act stable finally. Still miss utorrent 1.6 though. Seem to can't let it go i guess..
-
Re: To BT site staff about utorrent 1.6.1 !
I hate seeing that red bar when we click on files which is otherwise white in 1.6.1 lol
-
Re: To BT site staff about utorrent 1.6.1 !
Best to keep everything up to date, good move for bittorrent trackers
+1
-
Re: To BT site staff about utorrent 1.6.1 !
RevTT have also banned all version of utorrent except 176 :)
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
Forumas
RevTT have also banned all version of utorrent except 176 :)
why are you happy about it?
and that a site bans a well working versions of a client doesnt proof anything..
if a large amount of users wants to stick to µ 1.6.1 there is no point in saying hey we ban the client bc we can..
if you dont have vista and dont use https the rss-reader there is no point in getting the new version..
or have i missed a major improvement in all these many new versions?
-
Re: To BT site staff about utorrent 1.6.1 !
so bitmetv has allowed 1.6.1 ? correct ? :)
-
Re: To BT site staff about utorrent 1.6.1 !
They have alowed 1.6.1 to remain revtt an admin confirmed it bitmetv it's on the front page i think now most trackers will allow it to stay
-
Re: To BT site staff about utorrent 1.6.1 !
blame the +1 chain.
Let "A" be a person with an excellent reputation (say, staff of "high lvl" tracker or even say coders of utorrent) then the +1 chain is given as:
Quote:
Originally Posted by F
Quote:
Originally Posted by E
Quote:
Originally Posted by D
Quote:
Originally Posted by C
Quote:
Originally Posted by B
Quote:
Originally Posted by A
1.7.6 is better than 1.6.1
+1
+1
+1
+1
i forgot what comes after F :(
-
Re: To BT site staff about utorrent 1.6.1 !
http://x264.eu/
Quote:
uTorrent exploit
- it has come to light that the exploit actually does not affect 1.6.x so
1.6.1 is still the recommended version.
- interesting how it got so much worse after it was sold
http://x264.eu/pic/smilies/confused.gif
so more sites are sticking to the 1.6.1 version :)
-
Re: To BT site staff about utorrent 1.6.1 !
where can I find 1.6.1 build 490?
-
Re: To BT site staff about utorrent 1.6.1 !
probably oldversion.com (havnt checked but if its anywhere its there)
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
gatorade
where can I find 1.6.1 build 490?
http://www.download3000.com/download_19049.html
:)
-
Re: To BT site staff about utorrent 1.6.1 !
most trackers have unbanned 1.6.1, but why dont u just use the newer version?
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
FatBob
http://oldversion.com/program.php?n=utorrent
Oldversion.com has many old versions stored for your most popular programs. Great site, check it out.
-
Re: To BT site staff about utorrent 1.6.1 !
not on either of those two links
-
Re: To BT site staff about utorrent 1.6.1 !
Quote:
Originally Posted by
broomhead
most trackers have unbanned 1.6.1, but why dont u just use the newer version?
i havent see many trackers have unbanned 161 at all..can u tell some except waffles and what?
@sleepyy
its not true RevTT havent allowed or tell that they will allowed again 161..i have read forum and havent find anything abouth 161 be allowed there or i have missunderstand something else :P
@sokrates
Quote:
why are you happy about it?
and that a site bans a well working versions of a client doesnt proof anything..
if a large amount of users wants to stick to µ 1.6.1 there is no point in saying hey we ban the client bc we can..
if you dont have vista and dont use https the rss-reader there is no point in getting the new version..
or have i missed a major improvement in all these many new versions?
lol im not happy and i really dont care,but many major sites have banned 161 and that is telling me somthing:)
i have also used 161 before but i dont see point of not upgradeing to new version..:)