Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 14-02-2007, 02:05 AM   #1 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Exclamation uTorrent “announce” URL Handling Buffer Overflow


A potentially very dangerous vulnerability has been discovered in the latest version of popular BitTorrent client uTorrent. This could be exploited by attackers to take complete control of an affected system. This issue is due to a buffer overflow error when handling a “torrent” file containing an overly long “announce” URL, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into opening a specially crafted torrent file or visiting a malicious web page.

All version of uTorrent are affected, including latest version 1.6 build 474 and prior. There’s already a working exploit for this floating on the internet. No fixed version has been released, as this is really fresh stuff. Although this exploit could be very dangerous, you need to download the “infected” torrent first and use it with this client. I recommend waiting for a new version of uTorrent (should be available within few hours, max days) and downloading only from trusted websites such as NewTorrents.info where are all torrents checked.

Quoted from www.rlslog.net [http://www.rlslog.net/utorrent-annou...fer-overflow/]
__________________
I'm like a bird... :)
goobimama is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 14-02-2007, 05:09 PM   #2 (permalink)
Laptoping
 
Sourabh's Avatar
 
Join Date: Aug 2004
Location: Mumbai
Posts: 2,211
Default Re: uTorrent “announce” URL Handling Buffer Overflow

There has been no update for utorrent ever since it was taken over by Bit Torrent Inc. So waiting for a new version without some DRM is being very optimistic. If there is no update to patch this, I will shift to FlashGet for torrents too.
__________________
You could think I'm wrong, but that's no reason to stop thinking.
Sourabh is offline  
Old 14-02-2007, 06:12 PM   #3 (permalink)
You gave been GXified
 
gxsaurav's Avatar
 
Join Date: Jan 2007
Location: New Delhi
Posts: 5,633
Default Re: uTorrent “announce” URL Handling Buffer Overflow

Switched to bitcomet here on Vista, utorrent was not givign full speed.
__________________
about.me/gxsaurav
gxsaurav is offline  
Old 14-02-2007, 06:41 PM   #4 (permalink)
Human Spambot
 
Arsenal_Gunners's Avatar
 
Join Date: May 2005
Posts: 3,116
Default Re: uTorrent “announce” URL Handling Buffer Overflow

Why don't you guys switch to BITcomet.I am getting speeds of around 35KBps
on my 256KBps connection in Vista.(MAX 30 on xp)
Arsenal_Gunners is online now  
Old 14-02-2007, 11:31 PM   #5 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default Re: uTorrent “announce” URL Handling Buffer Overflow

µTorrent 1.6.1 Build 488 - Final

Released 13 Feb, 2007.

Changes in Version 1.6.1 (build 488), 2007-02-13:
- Feature: Select upload/download speed for a torrent through the rightclick menu
- Feature: Added encryption box to speed guide
- Change: Don't check as many pieces at the same time.
- Change: Misc WebUI changes.
- Change: Switch to JSON for webinterface
- Fix: Problem with category list in the gui when updated from the webui
- Fix: WebUI not clearing state between requests.
- Fix: Redirect also index.html to guest.html
- Fix: Added On Now shows the time it's added, not loaded.
- Fix: JSON uses " instead of '
- Fix: (a) Upnp fix
- Fix: Show pause icon when checking is paused.
- Fix: Fixed problems with XML parser
- Fix: Don't allow two message boxes to be shown in the RSS window
- Fix: Changed some window titles
- Fix: Fix malformed .torrent exploit
- Fix: Boss key field is now larger

http://download.utorrent.com/1.6.1/utorrent.exe

Size: 173 KB
navjotjsingh is offline  
Old 14-02-2007, 11:33 PM   #6 (permalink)
Human Spambot
 
Arsenal_Gunners's Avatar
 
Join Date: May 2005
Posts: 3,116
Default Re: uTorrent “announce” URL Handling Buffer Overflow

^ 8+)=8)
:d
Arsenal_Gunners is online now  
Old 15-02-2007, 12:17 AM   #7 (permalink)
You gave been GXified
 
gxsaurav's Avatar
 
Join Date: Jan 2007
Location: New Delhi
Posts: 5,633
Default Re: uTorrent “announce” URL Handling Buffer Overflow

Quote:
Originally Posted by vimal_mehrotra
Why don't you guys switch to BITcomet.I am getting speeds of around 35KBps
on my 256KBps connection in Vista.(MAX 30 on xp)
Bitcomet is good for Vista, it sux on XP though....it nothing fast compared to utorrent in XP
__________________
about.me/gxsaurav
gxsaurav is offline  
Old 15-02-2007, 12:19 AM   #8 (permalink)
Human Spambot
 
Arsenal_Gunners's Avatar
 
Join Date: May 2005
Posts: 3,116
Default Re: uTorrent “announce” URL Handling Buffer Overflow

No,I got 9-10 kbps at max in utorrent in xp also.
Arsenal_Gunners is online now  
Old 15-02-2007, 10:17 PM   #9 (permalink)
In The Zone
 
busyanuj's Avatar
 
Join Date: Dec 2003
Posts: 488
Default Re: uTorrent “announce” URL Handling Buffer Overflow

thnx for informing
__________________
You are a living magnet. What you attract into your life is in harmony with your dominant thoughts.
busyanuj is offline  
Old 15-02-2007, 10:28 PM   #10 (permalink)
The Frozen Nova
 
casanova's Avatar
 
Join Date: Sep 2004
Location: Trespasser in Virtual Land
Posts: 1,641
Default Re: uTorrent “announce” URL Handling Buffer Overflow

uTorrent 1.6.1 Build 489 is out.
__________________
I dream of a better tomorrow... where chickens can cross roads and not have their motives questioned.

www.nerdweed.blogspot.com
casanova is offline  
Old 15-02-2007, 11:37 PM   #11 (permalink)
Wise Old Owl
 
nishant_nms's Avatar
 
Join Date: Sep 2005
Location: Pune
Posts: 1,346
Default Re: uTorrent “announce” URL Handling Buffer Overflow

was the bug fixed in new release?
__________________
AMD Athlon64 2800+|ASUS K8N-VM|2GB DDR400|Corsair VX450|Seagate ST3500320AS|Samsung SV0411N|LG 22xDVDRW|LG 700S|APC ES500|Altec Lancing AVS300|Logitech MX3200|Logitech QuickCam Connect|Philips SHM6105
nishant_nms is offline  
Old 16-02-2007, 09:29 AM   #12 (permalink)
The Frozen Nova
 
casanova's Avatar
 
Join Date: Sep 2004
Location: Trespasser in Virtual Land
Posts: 1,641
Default Re: uTorrent “announce” URL Handling Buffer Overflow

Nothing mentioned about that. Probably it wasn't. They released another build. uTorrent 1.6.1 Build 490.
This is the change log.
Quote:
--- 2007-02-13: Version 1.6.1 (build 490)
- Feature: Select upload/download speed for a torrent through the rightclick menu
- Feature: Added encryption box to speed guide

- Change: Don't check as many pieces at the same time.
- Change: Misc WebUI changes.
- Change: Switch to JSON for webinterface

- Fix: Problem with category list in the gui when updated from the webui
- Fix: WebUI not clearing state between requests.
- Fix: Redirect also index.html to guest.html
- Fix: Added On Now shows the time it's added, not loaded.
- Fix: JSON uses " instead of '
- Fix: (a) Upnp fix
- Fix: Show pause icon when checking is paused.
- Fix: Fixed problems with XML parser
- Fix: Don't allow two message boxes to be shown in the RSS window
- Fix: Changed some window titles
- Fix: Fix malformed .torrent exploit
- Fix: Boss key field is now larger
- Fix: PECompact bug causing crashes
They haven't mentioned about the flaw on the site nither in the change log. It should be fixed with the latest build as of now.
__________________
I dream of a better tomorrow... where chickens can cross roads and not have their motives questioned.

www.nerdweed.blogspot.com
casanova is offline  
Old 16-02-2007, 07:52 PM   #13 (permalink)
I am Optimus Prime
 
navjotjsingh's Avatar
 
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
Default Re: uTorrent “announce” URL Handling Buffer Overflow

What is happening with utorrent...earlier they stopped updating for more than 6 months and now in 2 days they updated it thrice...488,489 and 490!!
navjotjsingh is offline  
Old 16-02-2007, 10:00 PM   #14 (permalink)
Human Spambot
 
Arsenal_Gunners's Avatar
 
Join Date: May 2005
Posts: 3,116
Default Re: uTorrent “announce” URL Handling Buffer Overflow

^^they prepared these versions in 6 months and now releasing them one after the other
Arsenal_Gunners is online now  
Old 16-02-2007, 11:06 PM   #15 (permalink)
thunderbird.117
Guest
 
Posts: n/a
Default Re: uTorrent “announce” URL Handling Buffer Overflow

I think utorrent is finished once and for all. I left utorrent and started using azerues and iam loving it baby. .

I do not why this people say that it memory. It is hardly taking any memory.
 
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by icebags
- by Tenida
- by Sarath
- by Charan

Advertisement




All times are GMT +5.5. The time now is 12:36 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2