<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: KTorrent Web Interface Vulnerable to Remote Takeover</title>
	<atom:link href="http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/</link>
	<description>Breaking File-sharing, Copyright and Privacy News</description>
	<lastBuildDate>Tue, 28 Oct 2014 17:48:34 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.2</generator>
	<item>
		<title>By: Bit Torrent Vs Apple The Battle For Your Video Downloads &#124; Movies Blog</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-539664</link>
		<dc:creator><![CDATA[Bit Torrent Vs Apple The Battle For Your Video Downloads &#124; Movies Blog]]></dc:creator>
		<pubDate>Wed, 11 Mar 2009 05:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-539664</guid>
		<description><![CDATA[[...] KTorrent Web Inte&amp;#114face Vulne&amp;#114able t&amp;#111 Rem&amp;#111te Take&amp;#111ve&amp;#114 &#124; T&amp;#111&amp;#114&amp;#114entF&amp;... [...]]]></description>
		<content:encoded><![CDATA[<p>[...] KTorrent Web Inte&amp;#114face Vulne&amp;#114able t&amp;#111 Rem&amp;#111te Take&amp;#111ve&amp;#114 | T&amp;#111&amp;#114&amp;#114entF&#38;&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linux User</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-538842</link>
		<dc:creator><![CDATA[Linux User]]></dc:creator>
		<pubDate>Sat, 07 Mar 2009 12:30:08 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-538842</guid>
		<description><![CDATA[Just don&#039;t use web interface plug-in and all is well with no need to upgrade. Time to go back to sleep now.

Oh and for the windows trolls, keep being paytards Steve Ballmer just loves your money and the Black Hats love your OS as it has all the security of a Sri Lankan Cricket Team escort

:)]]></description>
		<content:encoded><![CDATA[<p>Just don&#8217;t use web interface plug-in and all is well with no need to upgrade. Time to go back to sleep now.</p>
<p>Oh and for the windows trolls, keep being paytards Steve Ballmer just loves your money and the Black Hats love your OS as it has all the security of a Sri Lankan Cricket Team escort</p>
<p>:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anon</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-537371</link>
		<dc:creator><![CDATA[anon]]></dc:creator>
		<pubDate>Tue, 03 Mar 2009 07:08:23 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-537371</guid>
		<description><![CDATA[And this is news?  This has been reported and fixed for ages.]]></description>
		<content:encoded><![CDATA[<p>And this is news?  This has been reported and fixed for ages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lars</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536929</link>
		<dc:creator><![CDATA[Lars]]></dc:creator>
		<pubDate>Mon, 02 Mar 2009 13:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536929</guid>
		<description><![CDATA[In the article it states, &quot;Versions affected by this issue are 2.2.8 and earlier&quot;.  However, the security warning in question affects &quot;versions &lt;= 2.2.8&quot;.  So, 2.2.8 is not at risk according to the security warning link and according to this bug report.

http://bugs.gentoo.org/show_bug.cgi?id=244741]]></description>
		<content:encoded><![CDATA[<p>In the article it states, &#8220;Versions affected by this issue are 2.2.8 and earlier&#8221;.  However, the security warning in question affects &#8220;versions &lt;= 2.2.8&#8243;.  So, 2.2.8 is not at risk according to the security warning link and according to this bug report.</p>
<p><a href="http://bugs.gentoo.org/show_bug.cgi?id=244741" rel="nofollow">http://bugs.gentoo.org/show_bug.cgi?id=244741</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: janet</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536761</link>
		<dc:creator><![CDATA[janet]]></dc:creator>
		<pubDate>Mon, 02 Mar 2009 02:41:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536761</guid>
		<description><![CDATA[it is wrong for a man have a rich woman or a woman have a wealthy man?It is an absolutely extramarital relationship. but more and more services come out on 

Internet focusing on this kind of relationship.such as__S e e k r i c h . c o m___it&#039;s the biggest dating site for wealthy and successful people.]]></description>
		<content:encoded><![CDATA[<p>it is wrong for a man have a rich woman or a woman have a wealthy man?It is an absolutely extramarital relationship. but more and more services come out on </p>
<p>Internet focusing on this kind of relationship.such as__S e e k r i c h . c o m___it&#8217;s the biggest dating site for wealthy and successful people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pclinuxos</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536661</link>
		<dc:creator><![CDATA[pclinuxos]]></dc:creator>
		<pubDate>Sun, 01 Mar 2009 15:55:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536661</guid>
		<description><![CDATA[well, ktorrent is not the only torrent client for linux (transmission, deluga, azureus, etc.).
linux&#039;s default user is not root[not like w.....s], so i don&#039;t think this is really a big security issue.]]></description>
		<content:encoded><![CDATA[<p>well, ktorrent is not the only torrent client for linux (transmission, deluga, azureus, etc.).<br />
linux&#8217;s default user is not root[not like w.....s], so i don&#8217;t think this is really a big security issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diego</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536552</link>
		<dc:creator><![CDATA[Diego]]></dc:creator>
		<pubDate>Sun, 01 Mar 2009 09:44:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536552</guid>
		<description><![CDATA[&gt;Written by enigmax on February 28, 2009 

&gt; admin - Mon, 10/20/2008 - 18:47
&gt; 3.1.4 released
&gt; Several security issues in the webinterface plugin

You&#039;re only more than 4 months late!]]></description>
		<content:encoded><![CDATA[<p>&gt;Written by enigmax on February 28, 2009 </p>
<p>&gt; admin &#8211; Mon, 10/20/2008 &#8211; 18:47<br />
&gt; 3.1.4 released<br />
&gt; Several security issues in the webinterface plugin</p>
<p>You&#8217;re only more than 4 months late!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rage</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536521</link>
		<dc:creator><![CDATA[Rage]]></dc:creator>
		<pubDate>Sun, 01 Mar 2009 06:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536521</guid>
		<description><![CDATA[@20:
The article refers to versions 2.2.8 and earlier. The latest version is 3.2]]></description>
		<content:encoded><![CDATA[<p>@20:<br />
The article refers to versions 2.2.8 and earlier. The latest version is 3.2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fleshTH</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536506</link>
		<dc:creator><![CDATA[fleshTH]]></dc:creator>
		<pubDate>Sun, 01 Mar 2009 05:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536506</guid>
		<description><![CDATA[I&#039;m slowly getting myself into linux, and i hate KDE, but for the record... this is a good article. I know of many users who are switching to ubuntu linux and use KDE (i know, that is kubuntu) because some dumbass told them it was better than  gnome. However, these people were windows users and aren&#039;t that great at working in linux yet. Also, did you read? there is no update yet, the best course of action is to disable the plugin. really people, get off your high horse.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m slowly getting myself into linux, and i hate KDE, but for the record&#8230; this is a good article. I know of many users who are switching to ubuntu linux and use KDE (i know, that is kubuntu) because some dumbass told them it was better than  gnome. However, these people were windows users and aren&#8217;t that great at working in linux yet. Also, did you read? there is no update yet, the best course of action is to disable the plugin. really people, get off your high horse.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rioting_pacifist</title>
		<link>/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536421</link>
		<dc:creator><![CDATA[rioting_pacifist]]></dc:creator>
		<pubDate>Sat, 28 Feb 2009 21:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536421</guid>
		<description><![CDATA[apt-get update; apt-get upgrade and forget (other commands are available).

its a shame that the webapplet has been desgined badly but if you have an unsecured web server running you cant really expect much better 
( even without this exploit you can upload a torrent containing a script called .xinitrc containing rm -fr ~/ to ~ and theres not much you can do)

perhaps some of the new kernel tricks can be employed in latter versions to drop ktorrent rights to only access certain directories ( and never set a +x bit) but the sensible thing would be to never have unsafe services open to unsecured connection (if your behind a closed firewall your prety safe even with the exploit)]]></description>
		<content:encoded><![CDATA[<p>apt-get update; apt-get upgrade and forget (other commands are available).</p>
<p>its a shame that the webapplet has been desgined badly but if you have an unsecured web server running you cant really expect much better<br />
( even without this exploit you can upload a torrent containing a script called .xinitrc containing rm -fr ~/ to ~ and theres not much you can do)</p>
<p>perhaps some of the new kernel tricks can be employed in latter versions to drop ktorrent rights to only access certain directories ( and never set a +x bit) but the sensible thing would be to never have unsafe services open to unsecured connection (if your behind a closed firewall your prety safe even with the exploit)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
