Category: General|Feb 26, 2018 | Author: Admin

uTorrent bug allows attackers to control your computer remotely

Share on

uTorrent is arguably the most popular BitTorrent client. The app allows users to connect to a peer-to-peer network and download/share files. In a recent turn of events, it is discovered that two versions of uTorrent are found susceptible to attacks. The revelation was done by Google Project Zero, and the developers have already been informed.

uTorrent is arguably the most popular BitTorrent client. The app allows users to connect to a peer-to-peer network and download/share files. In a recent turn of events, it is discovered that two versions of uTorrent are found susceptible to attacks. The revelation was done by Google Project Zero, and the developers have already been informed.

uTorrent vulnerability
While the patches are on the way, it is essential to know how the vulnerability allowed hackers to control key features on both a uTorrent desktop app for Windows and the uTorrent Web. That apart Malicious sites could simply exploit the vulnerability and inject their codes into the Windows Startup folder. Next time the computer boots it would automatically run the malicious code. With such an arrangement in place, attackers can exploit the flaw and access downloaded files and download histories as well.

Dave Rees, VP of Engineering at BitTorrent has said that the flaw has been already fixed in the beta release of the uTorrent Windows desktop app, but the same is yet to be done for the production version.Meanwhile, you can download the patched uTorrent/BitTorrent 3.5.3.44352. This makeshift arrangement should work fine until uTorrent releases an update/patch to the production version as well. However, on Tuesday the BitTorrent VP said that the uTorrent Web had been patched.

We highly encourage all uTorrent Web customers to update to the latest available build 0.12.0.502 available on our website and also via the in-application update notification.” -Dave Rees, uTorrent.

The statement came right after Project Zero researcher Tavis Ormandy warned that the flaws on the uTorrent Web remained unfixed. The proof of concept exploits covers both the uTorrent Web and the uTorrent desktop app. It explains how attackers can use a method usually referred to as domain name system rebinding and make an untrusted internet domain to resolve the local IP address of the computer that is running the vulnerable version of the uTorrent app. Later the malicious codes/payloads are transferred through the domain and will be executed on the computer.I would personally recommend uTorrent users to stop using the app until its fixed.

Sponsored Ads:

Comments:


Struggling with VPN

Category: Microsoft|May 3, 2024 | Author: Admin

This is how Huawei tricked its way into the US

Category: IT|May 2, 2024 | Author: Admin

Edge 125 arrives in Beta with sleeping tab improvements and other changes

Category: IT|May 1, 2024 | Author: Admin

Now the iPad opens

Category: Apple|Apr 30, 2024 | Author: Admin

Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin
more