TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Seedboxes Beware: Major Bug in TorrentFlux-b4rt

A seedbox supplier is warning of a serious bug just discovered in TorrentFlux-b4rt. The exploit, found by one of their customers, allows a user on a shared server to obtain torrents uploaded by other users. This enables the attacker to obtain another user’s unique passkey and masquerade as them on private trackers

seedboxTorrentFlux-b4rt is a popular spin-off of TorrentFlux, an open source web based system for managing BitTorrent downloads on seedboxes. The main user interface is accessed via a web browser and it widely used by members of private BitTorrent trackers.

A member of support staff at Xirvik, a company selling seedboxes and other related services, told us a little about b4rt and the serious exploit one of their customers has just discovered.

“Torrentflux-b4rt is one of the major fully multi-user BitTorrent frontends that exist. It supports several clients (such as BitTornado and Transmission), the source code is available, and it’s been around for a long time.”

Xirvik told TorrentFreak that they have discovered a major bug in TorrentFlux-b4rt, one which could lead to users having access to other users’ torrents. While that might not initially sound that threatening, for private tracker users it constitutes quite a security breach. Contained in those .torrent files is the user’s unique torrent passkey which allows sharing on a private site. Getting access to this allows the attacker to masquerade as the other user on private trackers

A user can access another user’s torrents if he already knows the exact name of the torrent (easy to find from any search engine) and provided, of course, it is present on the server.

“Given a torrent with a name such as Ubuntu.8.10.Server-CANONICAL.torrent that already exists on the server, another user could upload another torrent with the name ubuntu.8.10.server-canonical.torrent (not necessarily all lowercase – just one different character is enough) and get access to the first file,” Xirvik explains.

Luckily Xirvik has not only found the bug and reported it, but have also worked on a fix which can be found here on the TorrentFlux-b4rt forums.

Related Posts

Previous Post | Next Post

  • TorGuard

NewsBits

The latest news from around the web, not covered on the frontpage

  • Look! We got a Medal for Defending the Internet

    Yeah I have to admit, we are awesome… In fact, TorrentFreak is so great that we...

  • Filecrop Bans Porn “Out of Respect for Women”

    The popular cyberlocker Filecrop decided to disable access to all porn on its site. An interesting...

  • Dutch ISPs Appeal Pirate Bay Blockade

    Two weeks ago the Court of The Hague ordered several ISPs to prevent subscribers from accessing...

  • TorrentFreak Censored by Orange’s Child Protection Filter

    The Internet is a scary place for kids, but luckily there’s censorship. In the UK mobile...

  • “How We Stopped SOPA”

    After the historic protests in January SOPA and PIPA were ‘shelved’. In a keynote speech at...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

PopularArticles

A selection of some TorrentFreak's classics dug up from our archives.