TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Seedboxes Beware: Major Bug in TorrentFlux-b4rt

A seedbox supplier is warning of a serious bug just discovered in TorrentFlux-b4rt. The exploit, found by one of their customers, allows a user on a shared server to obtain torrents uploaded by other users. This enables the attacker to obtain another user’s unique passkey and masquerade as them on private trackers

seedboxTorrentFlux-b4rt is a popular spin-off of TorrentFlux, an open source web based system for managing BitTorrent downloads on seedboxes. The main user interface is accessed via a web browser and it widely used by members of private BitTorrent trackers.

A member of support staff at Xirvik, a company selling seedboxes and other related services, told us a little about b4rt and the serious exploit one of their customers has just discovered.

“Torrentflux-b4rt is one of the major fully multi-user BitTorrent frontends that exist. It supports several clients (such as BitTornado and Transmission), the source code is available, and it’s been around for a long time.”

Xirvik told TorrentFreak that they have discovered a major bug in TorrentFlux-b4rt, one which could lead to users having access to other users’ torrents. While that might not initially sound that threatening, for private tracker users it constitutes quite a security breach. Contained in those .torrent files is the user’s unique torrent passkey which allows sharing on a private site. Getting access to this allows the attacker to masquerade as the other user on private trackers

A user can access another user’s torrents if he already knows the exact name of the torrent (easy to find from any search engine) and provided, of course, it is present on the server.

“Given a torrent with a name such as Ubuntu.8.10.Server-CANONICAL.torrent that already exists on the server, another user could upload another torrent with the name ubuntu.8.10.server-canonical.torrent (not necessarily all lowercase – just one different character is enough) and get access to the first file,” Xirvik explains.

Luckily Xirvik has not only found the bug and reported it, but have also worked on a fix which can be found here on the TorrentFlux-b4rt forums.

Related Posts

Previous Post | Next Post

  • Mediaget
  • Download Torrents with BTguard

NewsBits

The latest news from around the web, not covered on the frontpage

  • RIAA: “Misinformation May Be a Dirty Trick, But It Works.”

    For years the RIAA has tried to convince the world that piracy is killing musicians. Supported...

  • Russia’s Largest BitTorrent Tracker Under Huge DDoS Attack

    RUTracker, Russia’s largest BitTorrent tracker, has been dealing with the effects of a DDoS attack over...

  • Reddit and WordPress Urge Congress to Shelve SOPA/PIPA

    A coalition of 70 groups, including Reddit and WordPress, are asking Congress to stop working on...

  • Turbobit.net Blocks US Visitors After MegaUpload Shutdown

    In the aftermath of the MegaUpload shutdown, file-hosting sites continue to change their services. After Uploaded.to,...

  • QuickSilverScreen Streaming Links Site Calls It Quits

    In the wake of the Megaupload raids and attacks on domains in the US and elsewhere,...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

RecommendedArticles

A selection of some TorrentFreak's classics dug up from our archives.