<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Critical Vulnerability Discovered in uTorrent</title>
	<atom:link href="http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/</link>
	<description>Torrent News, Torrent Sites and the latest Scoops</description>
	<lastBuildDate>Sun, 22 Nov 2009 10:34:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Rhys</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-488212</link>
		<dc:creator>Rhys</dc:creator>
		<pubDate>Fri, 22 Aug 2008 12:05:47 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-488212</guid>
		<description>I discovered this vulnerability by doing some basic reverse engineering of uTorrent quite some time ago.

The vulnerability occurs because the coders of uTorrent continue to use a known unsafe memory API to move blocks of information around.

Is it a deliberate attempt by RIAA/MPAA etc? No, it&#039;s just simply lazy coding.

Microsoft was hit by these same type of issues back in 2001-2003, but they took the time to update their code. uTorrent simply didn&#039;t. They need to improve their internal secure coding techniques and improve developer training.

No conspiracy here, just laziness.</description>
		<content:encoded><![CDATA[<p>I discovered this vulnerability by doing some basic reverse engineering of uTorrent quite some time ago.</p>
<p>The vulnerability occurs because the coders of uTorrent continue to use a known unsafe memory API to move blocks of information around.</p>
<p>Is it a deliberate attempt by RIAA/MPAA etc? No, it&#8217;s just simply lazy coding.</p>
<p>Microsoft was hit by these same type of issues back in 2001-2003, but they took the time to update their code. uTorrent simply didn&#8217;t. They need to improve their internal secure coding techniques and improve developer training.</p>
<p>No conspiracy here, just laziness.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pissed off</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-488044</link>
		<dc:creator>pissed off</dc:creator>
		<pubDate>Thu, 21 Aug 2008 22:37:14 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-488044</guid>
		<description>fuck this, I don&#039;t want to upgrade to 1.8, that&#039;s total bullshit that trackers are forcing us to switch to it, fucking bullshit, it&#039;s flawed.</description>
		<content:encoded><![CDATA[<p>fuck this, I don&#8217;t want to upgrade to 1.8, that&#8217;s total bullshit that trackers are forcing us to switch to it, fucking bullshit, it&#8217;s flawed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-486213</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sun, 17 Aug 2008 12:14:04 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-486213</guid>
		<description>Switch to Halite</description>
		<content:encoded><![CDATA[<p>Switch to Halite</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485919</link>
		<dc:creator>Marc</dc:creator>
		<pubDate>Sat, 16 Aug 2008 15:49:57 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485919</guid>
		<description>@70, yeah, since version 1.8 they have a trick built in.  you cant cap your upload speed too low or else it severely limits your download, which can be a problem in some cases when you run into a torrent that is really slow downloading for example. its built in, no way of changing that, if you cap below 4-5 or 6 k/s, depending on the version you are trying, it limits your download speed big time.  i tested this and then went back to 1.7.7, i am thinking of switching to something else anyway ... deluge is supposed to be good too ???</description>
		<content:encoded><![CDATA[<p>@70, yeah, since version 1.8 they have a trick built in.  you cant cap your upload speed too low or else it severely limits your download, which can be a problem in some cases when you run into a torrent that is really slow downloading for example. its built in, no way of changing that, if you cap below 4-5 or 6 k/s, depending on the version you are trying, it limits your download speed big time.  i tested this and then went back to 1.7.7, i am thinking of switching to something else anyway &#8230; deluge is supposed to be good too ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stuffies</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485891</link>
		<dc:creator>stuffies</dc:creator>
		<pubDate>Sat, 16 Aug 2008 14:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485891</guid>
		<description>Only n00bs would believe this bullshit.</description>
		<content:encoded><![CDATA[<p>Only n00bs would believe this bullshit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485883</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 16 Aug 2008 13:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485883</guid>
		<description>Hoe vindt u een kwetsbaarheid als het programma niet open source</description>
		<content:encoded><![CDATA[<p>Hoe vindt u een kwetsbaarheid als het programma niet open source</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485882</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 16 Aug 2008 13:53:34 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485882</guid>
		<description>Comment trouvez-vous une vulnÃ©rabilitÃ© si le programme n&#039;est pas open source</description>
		<content:encoded><![CDATA[<p>Comment trouvez-vous une vulnÃ©rabilitÃ© si le programme n&#8217;est pas open source</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485881</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 16 Aug 2008 13:51:40 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485881</guid>
		<description>How do you find a Vulnerability if the program is not open source</description>
		<content:encoded><![CDATA[<p>How do you find a Vulnerability if the program is not open source</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485371</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 15 Aug 2008 11:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485371</guid>
		<description>Did you try using different trackers #70</description>
		<content:encoded><![CDATA[<p>Did you try using different trackers #70</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonimus</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485265</link>
		<dc:creator>Anonimus</dc:creator>
		<pubDate>Fri, 15 Aug 2008 07:14:08 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485265</guid>
		<description>Why they want to upgrade to v1.8 of utorrent? I think v1.8 have some bugs and they want more users to have v1.8 this way they can exploit this bug :)))</description>
		<content:encoded><![CDATA[<p>Why they want to upgrade to v1.8 of utorrent? I think v1.8 have some bugs and they want more users to have v1.8 this way they can exploit this bug :)))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firon</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-485234</link>
		<dc:creator>Firon</dc:creator>
		<pubDate>Fri, 15 Aug 2008 05:46:27 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-485234</guid>
		<description>No such cap has been implemented at those upload speeds, #70.</description>
		<content:encoded><![CDATA[<p>No such cap has been implemented at those upload speeds, #70.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484808</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 14 Aug 2008 06:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484808</guid>
		<description>Thanks #69</description>
		<content:encoded><![CDATA[<p>Thanks #69</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phishybongwaters</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484805</link>
		<dc:creator>Phishybongwaters</dc:creator>
		<pubDate>Thu, 14 Aug 2008 06:49:45 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484805</guid>
		<description>ok, i love utorrent, and will probably always use it as my preferred client.

Here&#039;s the thing.  I just installed 1.8 and I have a few concerns.

first off, there is now a built in timer for the &#039;update tracker&#039; function, which stops me from hammering updates to the tracker to pickup more peers.  due to the type and quality of my connection, i need to cap the uploads pretty low until i complete the torrent, then i change the number of upload slots, uncap the upload, and update the tracker a few times.  now I can&#039;t, which leads directly to the next issue.

As stated i need to cap my upload speeds.  Most guides suggest 80%.  If you don&#039;t mind your download suffering, that&#039;s great.  I cap to 5k until it&#039;s done, then let it open wide for a few days or so.

well, my tests showed me something interesting.

Utorrent 1.7 with the upload capped to 5k, on a specific torrent, lets my download at 600kbps.

Utorrent 1.8 with the upload cap set to 25 or above lets me hit that 600kbps.  The very instant i cap it to anything lower than 25kbps, my download drops to 100kbps max, and sits there until i uncap the upload.

I tested and retested, same results every time on several torrents.  They&#039;ve changed the forced share ratio to guess your max upload (or go by the settings you provided) and it literally messes with your download unless you uncap to something around 75%.

bollox my friends, bollox.</description>
		<content:encoded><![CDATA[<p>ok, i love utorrent, and will probably always use it as my preferred client.</p>
<p>Here&#8217;s the thing.  I just installed 1.8 and I have a few concerns.</p>
<p>first off, there is now a built in timer for the &#8216;update tracker&#8217; function, which stops me from hammering updates to the tracker to pickup more peers.  due to the type and quality of my connection, i need to cap the uploads pretty low until i complete the torrent, then i change the number of upload slots, uncap the upload, and update the tracker a few times.  now I can&#8217;t, which leads directly to the next issue.</p>
<p>As stated i need to cap my upload speeds.  Most guides suggest 80%.  If you don&#8217;t mind your download suffering, that&#8217;s great.  I cap to 5k until it&#8217;s done, then let it open wide for a few days or so.</p>
<p>well, my tests showed me something interesting.</p>
<p>Utorrent 1.7 with the upload capped to 5k, on a specific torrent, lets my download at 600kbps.</p>
<p>Utorrent 1.8 with the upload cap set to 25 or above lets me hit that 600kbps.  The very instant i cap it to anything lower than 25kbps, my download drops to 100kbps max, and sits there until i uncap the upload.</p>
<p>I tested and retested, same results every time on several torrents.  They&#8217;ve changed the forced share ratio to guess your max upload (or go by the settings you provided) and it literally messes with your download unless you uncap to something around 75%.</p>
<p>bollox my friends, bollox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484764</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 14 Aug 2008 02:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484764</guid>
		<description>It&#039;s the same, every time a new version is released they say older version has bugs and their explanation is almost the same
Vulnerability,buffer overflow blah, blah
See here:
http://torrentfreak.com/utorrent-vulnerable-to-remote-exploits/</description>
		<content:encoded><![CDATA[<p>It&#8217;s the same, every time a new version is released they say older version has bugs and their explanation is almost the same<br />
Vulnerability,buffer overflow blah, blah<br />
See here:<br />
<a href="http://torrentfreak.com/utorrent-vulnerable-to-remote-exploits/" rel="nofollow">http://torrentfreak.com/utorrent-vulnerable-to-remote-exploits/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484749</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 14 Aug 2008 01:07:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484749</guid>
		<description>You can get ÂµTorrent v1.7.7 from here:

http://www.oldapps.com/

Or the older versions of any other bit torrent client</description>
		<content:encoded><![CDATA[<p>You can get ÂµTorrent v1.7.7 from here:</p>
<p><a href="http://www.oldapps.com/" rel="nofollow">http://www.oldapps.com/</a></p>
<p>Or the older versions of any other bit torrent client</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484690</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 13 Aug 2008 20:46:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484690</guid>
		<description>How do you downgrade back to 1.7.7?</description>
		<content:encoded><![CDATA[<p>How do you downgrade back to 1.7.7?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oneplusone</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484662</link>
		<dc:creator>oneplusone</dc:creator>
		<pubDate>Wed, 13 Aug 2008 19:11:38 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484662</guid>
		<description>Yeah, everyone knows Java&#039;s not very secure. 

10 JRE updates a week make me wonder why Azureus is considered so much safer by so many people.</description>
		<content:encoded><![CDATA[<p>Yeah, everyone knows Java&#8217;s not very secure. </p>
<p>10 JRE updates a week make me wonder why Azureus is considered so much safer by so many people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484644</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 13 Aug 2008 18:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484644</guid>
		<description>I don&#039;t recommend BitComet it abuses the optomistic unchoke function to take priority over others in the swarm, most closed trackers don&#039;t allow it.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t recommend BitComet it abuses the optomistic unchoke function to take priority over others in the swarm, most closed trackers don&#8217;t allow it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ngbg</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484565</link>
		<dc:creator>ngbg</dc:creator>
		<pubDate>Wed, 13 Aug 2008 13:36:10 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484565</guid>
		<description>Well, I did the update. If not I have no use of utorrent since IÂ´ll be BANNED in most torrentsites that is important to me, so...</description>
		<content:encoded><![CDATA[<p>Well, I did the update. If not I have no use of utorrent since IÂ´ll be BANNED in most torrentsites that is important to me, so&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Buggy</title>
		<link>http://torrentfreak.com/critical-vulnerability-discovered-in-utorrent-080812/#comment-484563</link>
		<dc:creator>Buggy</dc:creator>
		<pubDate>Wed, 13 Aug 2008 13:28:29 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=3719#comment-484563</guid>
		<description>I really don&#039;t know what people are complaining about with uTorrent. Version 1.8 has some nice new features, no bugs I&#039;ve ever seen and is definitely not sending information straight to the authorities. I understand people using other clients (except Vuze/Azureus that thing is a massive memory hog) but why bash uTorrent? The only other client I&#039;ve liked is BitComet but it doesn&#039;t appear to support RSS downloading which I&#039;ve really started to love.</description>
		<content:encoded><![CDATA[<p>I really don&#8217;t know what people are complaining about with uTorrent. Version 1.8 has some nice new features, no bugs I&#8217;ve ever seen and is definitely not sending information straight to the authorities. I understand people using other clients (except Vuze/Azureus that thing is a massive memory hog) but why bash uTorrent? The only other client I&#8217;ve liked is BitComet but it doesn&#8217;t appear to support RSS downloading which I&#8217;ve really started to love.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
