French Hadopi “3 Strikes” Anti-Piracy Company Hacked
The private company entrusted to carry out file-sharing network monitoring for the French government has been hacked. Trident Media Guard, which is responsible for gathering data for so-called 3 strikes warnings, now has some of its scripts and secrets out in the wild, an event which has the potential to upset the smooth of Hadopi.
Under France’s so-called Hadopi law, alleged copyright infringers will be reported to a judge once they have received three official warnings for illicit file-sharing. Those judges are empowered to hand down any one of a range of penalties, from fines through to disconnecting the infringer from the Internet.
However, to get caught sharing copyright material, Internet users have to be monitored on file-sharing networks by the rights holders. The entertainment companies entrusted that spying job to Trident Media Guard (TMG) but during the last few hours, much to the amusement of opponents of France’s approach to enforcement, TMG has been hacked.
Actually, hacked is probably too strong a word, since it appears TMG left the front door open.
“A virtual machine leaked a lot of information like scripts, p2p clients to generate fake peers, local physical addresses in the datacenter and even a password that could lead to a major global TMG security breach,” French security researcher Olivier Laurelli, aka Bluetouff, just informed TorrentFreak.

TorrentFreak obtained copies of the files leaked from the TMG server (image above, cropped) and we’re in the process of trying work out exactly what they do which may take some time.
One of the files is an executable called ‘server_interface’ while there are also batch files which appear to start two file-sharing clients, eMule and Shareaza. These are likely to be special versions, probably modified for conducting both monitoring and spoofing on eD2K and BitTorrent networks respectively. The screenshot below (of code labelled ‘Poster’ in action) also appears to be connected to the publishing of fakes on file-sharing networks.

Another file – cmd_auto_update_cmd_file.txt – is the one carrying the worrying password referred to by Bluetouff earlier.
TMG’s security appears to be so low that Bluetouff suggests that either Christmas has come early for people wanting a poke around around an anti-piracy system or it’s some kind of weird honeypot.
TorrentFreak was also supplied with a list of IP addresses which pulled up some interesting web interfaces but we won’t publish those nor the leaked files for now.
“It’s a huge fail that could impact the graduated response (repression), during the next days,” Bluetouff concludes.

Pingback: French Hadopi “3 Strikes” Anti-Piracy Company Hacked | Torrentfreak.com
Pingback: French Hadopi “3 Strikes” Anti-Piracy Company Hacked | Links Daily
Pingback: P2PTalk » French Hadopi “3 Strikes” Anti-Piracy Company Hacked
Pingback: Hackeada la compañia antipirateria a cargo de la ley francesa Hadopi (3 Strikes) [EN]
Pingback: === popurls.com === popular today
Pingback: French Hadopi “3 Strikes” Anti-Piracy Company Hacked | TorrentFreak | NotSoCrazyNews BETA
Pingback: French 3 Strikes Suspended Due To Anti-Piracy Security Alert | TorrentFreak
Pingback: French 3 Strikes Suspended Due To Anti-Piracy Security Alert | We R Pirates
Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sabado — Bitelia
Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sabado | Linkeando: La Isla Buscada
Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sabado |
Pingback: Frans three-strikesbeleid tijdelijk op non-actief na hack | Webtechnologie
Pingback: Se suspende la aplicación de ley HADOPI (3 avisos) francesa debido al hackeo del sabado | BytNews
Pingback: Frans three-strikesbeleid tijdelijk op non-actief na hack » Clippy.be
Pingback: P2PTalk » French 3 Strikes Suspended Due To Anti-Piracy Security Alert
Pingback: French 3 Strikes Suspended Due To Anti-Piracy Security Alert
Pingback: France Suspends 3 Strikes Monitoring Following Data Breach | Geek News and Musings
Pingback: HA-HA HADOPI se suspende por vulnerabilidad en su sistema — ALT1040
Pingback: En Vrac - WaWa Blog
Pingback: Anti-Piracy Outfit Will Not Sue Hadopi ‘Hacker’ | We R Pirates
Pingback: Anti-Piracy Outfit Will Not Sue Hadopi ‘Hacker’ | TorrentFreak
Pingback: Anonymous
Pingback: P2PTalk » Anti-Piracy Outfit Will Not Sue Hadopi ‘Hacker’
Pingback: Francia, l’HadopiWare di TMG è un #fail? - The New Blog Times
Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software | We R Pirates
Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software
Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software | TorrentFreak
Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software | Links Daily
Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software
Pingback: <i>Municipals Chop Force and Fire Departments Nationwide!</i> Online car insurance quotes at Online car insurance quotes
Pingback: UN disapproves of Three Strikes Digital Executions | Just Enrichment