TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Major Vulnerability Found in Leaked Anti-Piracy Software

Trident Media Guard, the company entrusted by the French government to monitor file-sharing networks for copyright infringement, recently had some of their tools leaked onto the Internet following a security breach. Now researchers have published an analysis, with claims that an auto-update feature makes TMG’s servers vulnerable to remote code injection and execution.

TMGAs detailed in our earlier reports, anti-piracy company Trident Media Guard (TMG) recently failed to secure some of their systems. Blogger and security researcher Olivier Laurelli, aka Bluetouff, originally reported the breach which included a wide open virtual ‘test’ machine containing various tools. These, of course, spilled into the wild.

From the various files made available, some were easily viewable with a standard text editor, others – such as an executable called server_interface.exe – were more tricky. Thanks to a admittedly fairly hostile Full Disclosure security report we now have a clearer idea of what the package is capable of.

Penned by ‘CULT OF THE DEAD HADOPI’, the report refers to TMG as “Too Many Gremlins” along with reports not to expose them to bright lights. In it the server_interface.exe code is described as a Delphi service to which anyone can connect and start sending commands, no authentication (username/password) required. Perhaps even more worrying is a script which accepts auto-updates.

“An attacker can use the ‘Auto Update’ feature (\x82) to force the server to download updates from an evil FTP server he controls. Of course, a downloaded file is executed
just after the download,” write the researchers.

“Hence, anyone who wants to raise an army against Too Many Gremlins, look for an open port on TCP 8500,” they add.

The implication here is that if this software was present on all TMG servers, in addition to being able to turn them on and off at will a hacker could take them over with custom code of his own choosing, potentially creating “an army” which could be used to attack TMG or indeed, anyone else.

Commenting on the research, Bluetouff told TorrentFreak that the discovery of the vulnerabilities mean that the French 3 strikes program might already have been compromised.

“If TMG is vulnerable to injectioning on the system used to provide IP addresses to the HADOPI, the whole process is fu**** up,” he explained.

“Someone could for example inject the Culture Ministry’s IP range, or worse, gain access between TMG and HADOPI’s VPN by stealing certificates… then gain access to a huge amount of personal data,” he added.

“For instance we don’t know if this new ‘test server’ leak can compromise the LAN(S) of TMG with this exploit. Opacity is even for HADOPI. That’s why they went to audit TMG’s infrastructure with the CNIL [French Data Protection Office].”

“Anyway, this new episode shows that HADOPI was right to close their access,” he concludes.

That closure of access is a reference to Hadopi severing their Internet links to TMG once they found out about the leak and resorting to shifting IP addresses around by DVD and the postal system instead. That is hardly efficient and undoubtedly TMG will be working hard to get back into the 21st century.

Related Posts

Previous Post | Next Post

  • Anonymous

    Hey, idea. Turn TMG’s servers into a spam/ddos botnet, that will ddos Hadopi and themselves

    • MAFIAAFire

      LIKE!

    • Ryzzo

      This!

      Super Friends Unite!

      /cuethememusic

    • Ryzzo

      This!

      Super Friends Unite!

      /cuethememusic

  • bawlz

    boom goes the dynamite.

  • bawlz

    boom goes the dynamite.

  • Anonymous

    An FTP server open to the outside world that lets guests upload and run programs?! That’s the worst security I’ve ever heard of!

  • Flying Dutchman

    Step 1: Download 20 Terabytes of Pirated software.
    Step 2: Access TMG server.
    Step 3: Upload Downloaded stuff to TMG server.
    Step 4: Lodge a complaint to the local MAFIAA.
    Step 5: Enjoy the resulting Lulz.

    • Eric

      Just one program is enough you dont need 20tb.

      • http://eastsidehosting.com Repent Linux

        Well one might say, “An attack did this” so they’re nothing going to do anything.

        with a lot not saying 20 tb worth, just enough for there allocated space and hopefully and attempt to delete logs and then report them. They hopefully be able to prove anything. Therefore they will say “An attack did this” and like saying cried wolf and possibly might not take there word for it. If they did it the first time and did so…this can be an easy to set precedent for all cases that involve this. “I was attacked” The People Vs. TMG shows that lost and had to pay a hefty fine. :)

  • Anon

    Cult of dead hadopi, probably cult of dead cow, although I don’t think they are active anymore

  • http://twitter.com/linuxeomboy Gustavo Ferlizi

    HAHA! I’ve just shit my pants!

    • Subs

      Yeah, well done, but what did you think of the story?!

  • http://twitter.com/linuxeomboy Gustavo Ferlizi

    Well… uploading 20TB wouldn’t be very practical for most people….

    on my current connection (roughly 1.6MB/s), 20 TB takes almost 5 months to download…

    to upload (150KB/s), it could take as long as 3 years :s

    • Anon

      But multiple slow connections soon add up ;)

    • Whatever

      Seedboxes in a different setup ?

    • Whatever

      Seedboxes in a different setup ?

  • Christophe Thomas

    well this is France right … long lunch breaks and a fair amount of small talk – security is only for people that do not appreciate a good glass of red wine and proper cheese. We Frenchmen don’t even expect anyone to be interested in our wicked data and the whole HADOPI thingy will go away anyways with next presidential election – so why make a fuss about all this??

  • I am a sausage not a hotdog

    D’OH!!!

  • I am a sausage not a hotdog

    D’OH!!!

  • Dr_Fautus

    Its like the sony rootkit happening all over again. You know what they say about those not remembering the past, it’s a shame.

  • YarickZan

    See supposedly we’re supposed to be just fine with these people holding our personal data when the leave the front door wide open, and put a welcome mat on it to boot? I’m sorry none of these companies are responsible or intelligent enough to be doing this job. What would happen if this was say sensitive personal information like a social security number? These morons would have just given bigger criminals, the ones whose damage can actually be assessed not just estimated by a bunch of bullshit figures, a gold mine.

    In the end none of these companies should be able to hold this information.

    • Covenist5

      aint that the sad truth.

    • Bowser99

      If they had sensitive info accessible their company name would be Sony.

    • Bowser99

      If they had sensitive info accessible their company name would be Sony.

  • Devo590

    Do the bitches at tmg deserve this? Yes…yes they do.

  • John Space

    Coyote should stop buying ACME products if he really wants to catch the Roadrunner.

    • Derc

      LMFAO COOL!

  • Umeanme

    Implant uTorrent on there, operated on remote, it’s downloads to be deposited in an encrypted folder (with an easily crackable crypt code)…..they may as well put THEMSELVES on the most wanted list!

    HAHAHAHAHAHA!

  • Umeanme

    Implant uTorrent on there, operated on remote, it’s downloads to be deposited in an encrypted folder (with an easily crackable crypt code)…..they may as well put THEMSELVES on the most wanted list!

    HAHAHAHAHAHA!

  • Jmorse43508

    This is potentially as big of a fail for an anti-piracy firm as that of ACS:Law and MediaDefender.

    • Christophe Thomas

      hélas this is France – main stream media did not even talk about this … in 5 weeks it will be forgotten I am afraid.

      • Bowser99

        More than likely a gag order on the press… like they do in the U.S.

      • Bowser99

        More than likely a gag order on the press… like they do in the U.S.

  • Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software | Torrentfreak.com

  • Covenist5

    that’s what they get for trying to control people… Power to the people!

  • Haxor

    /me walks by whistling

  • Pingback: PrankVids news collection

  • Pingback: Major Vulnerability Found in Leaked Anti-Piracy Software … | Spyware For Phones Spy On Phones

  • Neilmc

    Remember back orifice…

  • Pingback: P2PTalk » French "three strikes" anti-piracy software riddled with flaws

  • http://disqus.com/ Rob8urcakes

    I wonder if HADOPI will sue TMG for breach of contract lol

  • Pingback: French "three strikes" anti-piracy software riddled with flaws | Information Technology Leader

  • Whatever

    “Someone could for example inject the Culture Ministry’s IP range, or worse……”

    Why is that bad (because it is followed by ‘or worse’) ?

  • Whatever

    “Someone could for example inject the Culture Ministry’s IP range, or worse……”

    Why is that bad (because it is followed by ‘or worse’) ?

  • Neilmill69

    Nice article.Thanks for sharing. Project Management Services

  • Pingback: Netzwelt-Ticker: Hacker verhöhnen französische Piratenjäger | Flash News

  • Pingback: 3 Count: First Hurdle

  • Revolution

    MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH MURDER THE RICH ER THE RICH MURDER THE RICH MURDER THE RICH

  • Pingback: French “three strikes” anti-piracy software riddled with flaws | Free downloads for all

  • BTGuard - BitTorrent Anonymously

NewsBits

Even more news...

  • The Pirate Bay Isn’t Down Completely, Just Having a Few Issues

    Twitter and Facebook, not to mention the TorrentFreak inbox, are currently alive with complaints that The...

  • Pirate Bay Founder Gottfrid Svartholm on Freedom of Speech

    Freedom of speech is a highly valued commodity, but should people be allowed to say whatever...

  • Blu-ray Anti-Piracy Tech Stops Discs and Promotes Purchases

    An anti-piracy system present in all official Blu-ray players since 2012 has received a fresh update...

  • Foxtel Breeds Pirates by Locking Up Game of Thrones

    One of the main reasons why people turn to piracy is the lack of legal alternatives....

  • UK Student Admits Breaching Sony Copyrights With Leak of PS3 SDK

    Last year an Internet user known as El Nomeo leaked version 3.70 of Sony’s Playstation3 SDK...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

PopularArticles

A selection of some TorrentFreak's classics dug up from our archives.