TorrentFreak

The place where breaking news, BitTorrent and copyright collide

KTorrent Web Interface Vulnerable to Remote Takeover

Two vulnerabilities have been discovered in the web interface plugin for the KDE BitTorrent client, KTorrent. A malicious attacker sending specially crafted parameters to the interface could enable both remote code execution and arbitrary torrent uploads.

ktorrentDistributed under a GNU General Public license, KTorrent is a torrent client written in C++ for KDE. Feature wise, the client can compete with other popular clients, supporting protocol encryption, UDP trackers and web-seeding to name a few.

One feature, however, is posing a security threat to the user. According to a security alert, multiple serious vulnerabilities have been found in the client.

With a severity rated as ‘High’, the vulnerabilities are to be found in the client’s web interface plugin. Since the plugin does not successfully restrict access to the clients torrent upload functionality and fails to sanitize request parameters, it is vulnerable to exploitation.

The flaws can allow a malicious remote attacker to send specially crafted parameters to the web interface. This could enable remote arbitrary torrent uploads along with the possibility of remote code execution, within the same privileges as the KTorrent process itself.

A temporary workaround solution is to disable the web interface plugin. This can be achieved by clicking “plugins” in the config menu and unchecking the “Web Interface” checkbox.

Versions affected by this issue are 2.2.8 and earlier, so users updating to the latest version are protected from these security vulnerabilities.

Related Posts

Previous Post | Next Post

  • TorGuard

NewsBits

The latest news from around the web, not covered on the frontpage

  • Dutch ISPs Appeal Pirate Bay Blockade

    Two weeks ago the Court of The Hague ordered several ISPs to prevent subscribers from accessing...

  • TorrentFreak Censored by Orange’s Child Protection Filter

    The Internet is a scary place for kids, but luckily there’s censorship. In the UK mobile...

  • “How We Stopped SOPA”

    After the historic protests in January SOPA and PIPA were ‘shelved’. In a keynote speech at...

  • Supreme Court Refuses $675,000 File-Sharing Case

    The case of the RIAA vs. Joel Tenenbaum – aka the case that will not die...

  • MPAA: Piracy is NOT Theft After All

    For decades the entertainment industry used the word “theft” to refer to piracy. Most famous is...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

PopularArticles

A selection of some TorrentFreak's classics dug up from our archives.