TorrentFreak

The place where breaking news, BitTorrent and copyright collide

KTorrent Web Interface Vulnerable to Remote Takeover

Two vulnerabilities have been discovered in the web interface plugin for the KDE BitTorrent client, KTorrent. A malicious attacker sending specially crafted parameters to the interface could enable both remote code execution and arbitrary torrent uploads.

ktorrentDistributed under a GNU General Public license, KTorrent is a torrent client written in C++ for KDE. Feature wise, the client can compete with other popular clients, supporting protocol encryption, UDP trackers and web-seeding to name a few.

One feature, however, is posing a security threat to the user. According to a security alert, multiple serious vulnerabilities have been found in the client.

With a severity rated as ‘High’, the vulnerabilities are to be found in the client’s web interface plugin. Since the plugin does not successfully restrict access to the clients torrent upload functionality and fails to sanitize request parameters, it is vulnerable to exploitation.

The flaws can allow a malicious remote attacker to send specially crafted parameters to the web interface. This could enable remote arbitrary torrent uploads along with the possibility of remote code execution, within the same privileges as the KTorrent process itself.

A temporary workaround solution is to disable the web interface plugin. This can be achieved by clicking “plugins” in the config menu and unchecking the “Web Interface” checkbox.

Versions affected by this issue are 2.2.8 and earlier, so users updating to the latest version are protected from these security vulnerabilities.

Related Posts

Previous Post | Next Post

  • Mediaget
  • Download Torrents with BTguard

NewsBits

The latest news from around the web, not covered on the frontpage

  • RIAA: “Misinformation May Be a Dirty Trick, But It Works.”

    For years the RIAA has tried to convince the world that piracy is killing musicians. Supported...

  • Russia’s Largest BitTorrent Tracker Under Huge DDoS Attack

    RUTracker, Russia’s largest BitTorrent tracker, has been dealing with the effects of a DDoS attack over...

  • Reddit and WordPress Urge Congress to Shelve SOPA/PIPA

    A coalition of 70 groups, including Reddit and WordPress, are asking Congress to stop working on...

  • Turbobit.net Blocks US Visitors After MegaUpload Shutdown

    In the aftermath of the MegaUpload shutdown, file-hosting sites continue to change their services. After Uploaded.to,...

  • QuickSilverScreen Streaming Links Site Calls It Quits

    In the wake of the Megaupload raids and attacks on domains in the US and elsewhere,...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

RecommendedArticles

A selection of some TorrentFreak's classics dug up from our archives.