<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: KTorrent Web Interface Vulnerable to Remote Takeover</title>
	<atom:link href="http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/</link>
	<description>Torrent News, Torrent Sites and the latest Scoops</description>
	<lastBuildDate>Sun, 22 Nov 2009 09:06:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bit Torrent Vs Apple The Battle For Your Video Downloads &#124; Movies Blog</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-539664</link>
		<dc:creator>Bit Torrent Vs Apple The Battle For Your Video Downloads &#124; Movies Blog</dc:creator>
		<pubDate>Wed, 11 Mar 2009 05:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-539664</guid>
		<description>[...] KTorrent Web Inte&amp;#114face Vulne&amp;#114able t&amp;#111 Rem&amp;#111te Take&amp;#111ve&amp;#114 &#124; T&amp;#111&amp;#114&amp;#114entF&amp;... [...]</description>
		<content:encoded><![CDATA[<p>[...] KTorrent Web Inte&amp;#114face Vulne&amp;#114able t&amp;#111 Rem&amp;#111te Take&amp;#111ve&amp;#114 | T&amp;#111&amp;#114&amp;#114entF&#38;&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linux User</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-538842</link>
		<dc:creator>Linux User</dc:creator>
		<pubDate>Sat, 07 Mar 2009 12:30:08 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-538842</guid>
		<description>Just don&#039;t use web interface plug-in and all is well with no need to upgrade. Time to go back to sleep now.

Oh and for the windows trolls, keep being paytards Steve Ballmer just loves your money and the Black Hats love your OS as it has all the security of a Sri Lankan Cricket Team escort

:)</description>
		<content:encoded><![CDATA[<p>Just don&#8217;t use web interface plug-in and all is well with no need to upgrade. Time to go back to sleep now.</p>
<p>Oh and for the windows trolls, keep being paytards Steve Ballmer just loves your money and the Black Hats love your OS as it has all the security of a Sri Lankan Cricket Team escort</p>
<p>:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anon</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-537371</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Tue, 03 Mar 2009 07:08:23 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-537371</guid>
		<description>And this is news?  This has been reported and fixed for ages.</description>
		<content:encoded><![CDATA[<p>And this is news?  This has been reported and fixed for ages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lars</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536929</link>
		<dc:creator>Lars</dc:creator>
		<pubDate>Mon, 02 Mar 2009 13:36:48 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536929</guid>
		<description>In the article it states, &quot;Versions affected by this issue are 2.2.8 and earlier&quot;.  However, the security warning in question affects &quot;versions &lt;= 2.2.8&quot;.  So, 2.2.8 is not at risk according to the security warning link and according to this bug report.

http://bugs.gentoo.org/show_bug.cgi?id=244741</description>
		<content:encoded><![CDATA[<p>In the article it states, &#8220;Versions affected by this issue are 2.2.8 and earlier&#8221;.  However, the security warning in question affects &#8220;versions &lt;= 2.2.8&#8243;.  So, 2.2.8 is not at risk according to the security warning link and according to this bug report.</p>
<p><a href="http://bugs.gentoo.org/show_bug.cgi?id=244741" rel="nofollow">http://bugs.gentoo.org/show_bug.cgi?id=244741</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: janet</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536761</link>
		<dc:creator>janet</dc:creator>
		<pubDate>Mon, 02 Mar 2009 02:41:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536761</guid>
		<description>it is wrong for a man have a rich woman or a woman have a wealthy man?It is an absolutely extramarital relationship. but more and more services come out on 

Internet focusing on this kind of relationship.such as__S e e k r i c h . c o m___it&#039;s the biggest dating site for wealthy and successful people.</description>
		<content:encoded><![CDATA[<p>it is wrong for a man have a rich woman or a woman have a wealthy man?It is an absolutely extramarital relationship. but more and more services come out on </p>
<p>Internet focusing on this kind of relationship.such as__S e e k r i c h . c o m___it&#8217;s the biggest dating site for wealthy and successful people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pclinuxos</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536661</link>
		<dc:creator>pclinuxos</dc:creator>
		<pubDate>Sun, 01 Mar 2009 15:55:20 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536661</guid>
		<description>well, ktorrent is not the only torrent client for linux (transmission, deluga, azureus, etc.).
linux&#039;s default user is not root[not like w.....s], so i don&#039;t think this is really a big security issue.</description>
		<content:encoded><![CDATA[<p>well, ktorrent is not the only torrent client for linux (transmission, deluga, azureus, etc.).<br />
linux&#8217;s default user is not root[not like w.....s], so i don&#8217;t think this is really a big security issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diego</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536552</link>
		<dc:creator>Diego</dc:creator>
		<pubDate>Sun, 01 Mar 2009 09:44:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536552</guid>
		<description>&gt;Written by enigmax on February 28, 2009 

&gt; admin - Mon, 10/20/2008 - 18:47
&gt; 3.1.4 released
&gt; Several security issues in the webinterface plugin

You&#039;re only more than 4 months late!</description>
		<content:encoded><![CDATA[<p>&gt;Written by enigmax on February 28, 2009 </p>
<p>&gt; admin &#8211; Mon, 10/20/2008 &#8211; 18:47<br />
&gt; 3.1.4 released<br />
&gt; Several security issues in the webinterface plugin</p>
<p>You&#8217;re only more than 4 months late!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rage</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536521</link>
		<dc:creator>Rage</dc:creator>
		<pubDate>Sun, 01 Mar 2009 06:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536521</guid>
		<description>@20:
The article refers to versions 2.2.8 and earlier. The latest version is 3.2</description>
		<content:encoded><![CDATA[<p>@20:<br />
The article refers to versions 2.2.8 and earlier. The latest version is 3.2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fleshTH</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536506</link>
		<dc:creator>fleshTH</dc:creator>
		<pubDate>Sun, 01 Mar 2009 05:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536506</guid>
		<description>I&#039;m slowly getting myself into linux, and i hate KDE, but for the record... this is a good article. I know of many users who are switching to ubuntu linux and use KDE (i know, that is kubuntu) because some dumbass told them it was better than  gnome. However, these people were windows users and aren&#039;t that great at working in linux yet. Also, did you read? there is no update yet, the best course of action is to disable the plugin. really people, get off your high horse.</description>
		<content:encoded><![CDATA[<p>I&#8217;m slowly getting myself into linux, and i hate KDE, but for the record&#8230; this is a good article. I know of many users who are switching to ubuntu linux and use KDE (i know, that is kubuntu) because some dumbass told them it was better than  gnome. However, these people were windows users and aren&#8217;t that great at working in linux yet. Also, did you read? there is no update yet, the best course of action is to disable the plugin. really people, get off your high horse.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rioting_pacifist</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536421</link>
		<dc:creator>rioting_pacifist</dc:creator>
		<pubDate>Sat, 28 Feb 2009 21:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536421</guid>
		<description>apt-get update; apt-get upgrade and forget (other commands are available).

its a shame that the webapplet has been desgined badly but if you have an unsecured web server running you cant really expect much better 
( even without this exploit you can upload a torrent containing a script called .xinitrc containing rm -fr ~/ to ~ and theres not much you can do)

perhaps some of the new kernel tricks can be employed in latter versions to drop ktorrent rights to only access certain directories ( and never set a +x bit) but the sensible thing would be to never have unsafe services open to unsecured connection (if your behind a closed firewall your prety safe even with the exploit)</description>
		<content:encoded><![CDATA[<p>apt-get update; apt-get upgrade and forget (other commands are available).</p>
<p>its a shame that the webapplet has been desgined badly but if you have an unsecured web server running you cant really expect much better<br />
( even without this exploit you can upload a torrent containing a script called .xinitrc containing rm -fr ~/ to ~ and theres not much you can do)</p>
<p>perhaps some of the new kernel tricks can be employed in latter versions to drop ktorrent rights to only access certain directories ( and never set a +x bit) but the sensible thing would be to never have unsafe services open to unsecured connection (if your behind a closed firewall your prety safe even with the exploit)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ubuntu</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536355</link>
		<dc:creator>ubuntu</dc:creator>
		<pubDate>Sat, 28 Feb 2009 17:53:03 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536355</guid>
		<description>@ #10 scrilla

&quot;who cares? ktorrent is one of those crappy clients that the amatuers and wannabe hackers that use the inferior Linux OS use.&quot;

&quot;Real torrenters use Windows and leave the noobs to the Linux! :)&quot;

Hahahahaha. I bet you are one of those that turn off Vista UAC and use uTorrent with administrative privileges.</description>
		<content:encoded><![CDATA[<p>@ #10 scrilla</p>
<p>&#8220;who cares? ktorrent is one of those crappy clients that the amatuers and wannabe hackers that use the inferior Linux OS use.&#8221;</p>
<p>&#8220;Real torrenters use Windows and leave the noobs to the Linux! :)&#8221;</p>
<p>Hahahahaha. I bet you are one of those that turn off Vista UAC and use uTorrent with administrative privileges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jcidiot</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536338</link>
		<dc:creator>jcidiot</dc:creator>
		<pubDate>Sat, 28 Feb 2009 16:40:32 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536338</guid>
		<description>*tpb</description>
		<content:encoded><![CDATA[<p>*tpb</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jcidiot</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536337</link>
		<dc:creator>jcidiot</dc:creator>
		<pubDate>Sat, 28 Feb 2009 16:39:58 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536337</guid>
		<description>well, it gets pretty boring between the rpb trials....</description>
		<content:encoded><![CDATA[<p>well, it gets pretty boring between the rpb trials&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: author is an idiot</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536305</link>
		<dc:creator>author is an idiot</dc:creator>
		<pubDate>Sat, 28 Feb 2009 15:15:19 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536305</guid>
		<description>^ ^ ya, ya I misspelled flash, get over it....</description>
		<content:encoded><![CDATA[<p>^ ^ ya, ya I misspelled flash, get over it&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: author is an idiot</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536304</link>
		<dc:creator>author is an idiot</dc:creator>
		<pubDate>Sat, 28 Feb 2009 15:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536304</guid>
		<description>*** NEWS FLAH!! ***

Program vulnerability in windows xp service pack 1!!! 

All people with the latest version of windows xp service pack 2 and up will not be affected by this bug.

Pretty stupid huh?  I guess the author of this &#039;piece&#039; (pos that is) needs to stop smoking so much pcp before attempting to write articles.</description>
		<content:encoded><![CDATA[<p>*** NEWS FLAH!! ***</p>
<p>Program vulnerability in windows xp service pack 1!!! </p>
<p>All people with the latest version of windows xp service pack 2 and up will not be affected by this bug.</p>
<p>Pretty stupid huh?  I guess the author of this &#8216;piece&#8217; (pos that is) needs to stop smoking so much pcp before attempting to write articles.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gretta</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536295</link>
		<dc:creator>Gretta</dc:creator>
		<pubDate>Sat, 28 Feb 2009 14:33:32 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536295</guid>
		<description>This article is really non-newsworthy:

1. A tiny portion of BT users run ktorrent.

2. Ktorrent is Linux based meaning users keep up to date with security issues because they are technically adept.

3. Ktorrent doesn&#039;t run with root priviledges by default - meaning any hacks pulled off with this vulnerability are pointless.

4. Linux has an aplication manager that updates applications

Seriously - what gives?</description>
		<content:encoded><![CDATA[<p>This article is really non-newsworthy:</p>
<p>1. A tiny portion of BT users run ktorrent.</p>
<p>2. Ktorrent is Linux based meaning users keep up to date with security issues because they are technically adept.</p>
<p>3. Ktorrent doesn&#8217;t run with root priviledges by default &#8211; meaning any hacks pulled off with this vulnerability are pointless.</p>
<p>4. Linux has an aplication manager that updates applications</p>
<p>Seriously &#8211; what gives?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elonoir</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536227</link>
		<dc:creator>Elonoir</dc:creator>
		<pubDate>Sat, 28 Feb 2009 10:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536227</guid>
		<description>&gt;&quot;Yay for an operating system that had a kernel bug for 10 years.&quot;

Just to be sure for if you are bashing Linux to &#039;enlighten&#039; windows: You know MS Windows probably has bugs in there for 20years that won&#039;t ever get fixed right?

Just for the sake of letting you know: I currently run Windows XP.

And really: Never mind, never feed the troll monkey.</description>
		<content:encoded><![CDATA[<p>&gt;&#8221;Yay for an operating system that had a kernel bug for 10 years.&#8221;</p>
<p>Just to be sure for if you are bashing Linux to &#8216;enlighten&#8217; windows: You know MS Windows probably has bugs in there for 20years that won&#8217;t ever get fixed right?</p>
<p>Just for the sake of letting you know: I currently run Windows XP.</p>
<p>And really: Never mind, never feed the troll monkey.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: linuxnonfanboy</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536224</link>
		<dc:creator>linuxnonfanboy</dc:creator>
		<pubDate>Sat, 28 Feb 2009 10:28:45 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536224</guid>
		<description>See, there was a point behind having to elevate privileges 90% of the time to function normally. Now you won&#039;t get effected by this type of attack. Yay for an operating system that had a kernel bug for 10 years.</description>
		<content:encoded><![CDATA[<p>See, there was a point behind having to elevate privileges 90% of the time to function normally. Now you won&#8217;t get effected by this type of attack. Yay for an operating system that had a kernel bug for 10 years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scrilla</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536219</link>
		<dc:creator>scrilla</dc:creator>
		<pubDate>Sat, 28 Feb 2009 10:04:29 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536219</guid>
		<description>who cares? ktorrent is one of those crappy clients that the amatuers and wannabe hackers that use the inferior Linux OS use.

Real torrenters use Windows and leave the noobs to the Linux! :)</description>
		<content:encoded><![CDATA[<p>who cares? ktorrent is one of those crappy clients that the amatuers and wannabe hackers that use the inferior Linux OS use.</p>
<p>Real torrenters use Windows and leave the noobs to the Linux! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comment-536213</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 28 Feb 2009 09:29:57 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10422#comment-536213</guid>
		<description>&quot;K What???Do people really use this???&quot;

Yes, it&#039;s a good torrent client for KDE.</description>
		<content:encoded><![CDATA[<p>&#8220;K What???Do people really use this???&#8221;</p>
<p>Yes, it&#8217;s a good torrent client for KDE.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
