<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TorrentFreak &#187; Ktorrent</title>
	<atom:link href="http://torrentfreak.com/tag/ktorrent/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com</link>
	<description>Torrent News, Torrent Sites and the latest Scoops</description>
	<lastBuildDate>Sat, 21 Nov 2009 21:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>KTorrent Web Interface Vulnerable to Remote Takeover</title>
		<link>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/</link>
		<comments>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 06:21:26 +0000</pubDate>
		<dc:creator>enigmax</dc:creator>
				<category><![CDATA[Bittorrent Clients]]></category>
		<category><![CDATA[KDE]]></category>
		<category><![CDATA[Ktorrent]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=10422</guid>
		<description><![CDATA[Two vulnerabilities have been discovered in the web interface plugin for the KDE BitTorrent client, KTorrent. A malicious attacker sending specially crafted parameters to the interface could enable both remote code execution and arbitrary torrent uploads.]]></description>
			<content:encoded><![CDATA[<p><img src="http://torrentfreak.com/images/ktorrent.jpg" align="right" alt="ktorrent" />Distributed under a GNU General Public license, KTorrent is a torrent client written in C++ for <a href="http://www.kde.org/">KDE</a>. Feature wise, the client can compete with other popular clients, supporting protocol encryption, UDP trackers and web-seeding to name a few.</p>
<p>One feature, however, is posing a  security threat to the user. According to a security <a href="http://www.gentoo.org/security/en/glsa/glsa-200902-05.xml">alert</a>, multiple serious vulnerabilities have been found in the client.</p>
<p>With a severity rated as &#8216;High&#8217;, the vulnerabilities are to be found in the client&#8217;s web interface plugin. Since the plugin does not successfully restrict access to the clients torrent upload functionality and fails to sanitize request parameters, it is vulnerable to exploitation.</p>
<p>The flaws can allow a malicious remote attacker to send specially crafted parameters to the web interface. This could enable remote arbitrary torrent uploads along with the possibility of remote code execution, within the same privileges as the KTorrent process itself.</p>
<p>A temporary workaround solution is to disable the web interface plugin. This can be achieved by clicking &#8220;plugins&#8221; in the config menu and unchecking the &#8220;Web Interface&#8221; checkbox.</p>
<p>Versions affected by this issue are 2.2.8 and earlier, so users updating to the <a href="http://ktorrent.org/">latest version</a> are protected from these security vulnerabilities.</p>
<p>Article from: <a href="http://torrentfreak.com">TorrentFreak</a>, check out our new blog at <a href="http://freakbits.com">FreakBits</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://torrentfreak.com/ktorrent-web-interface-vulnerable-to-remote-takeover-090228/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Multiple Vulnerabilities Discovered in Ktorrent</title>
		<link>http://torrentfreak.com/multiple-vulnerabilities-discovered-in-ktorrent/</link>
		<comments>http://torrentfreak.com/multiple-vulnerabilities-discovered-in-ktorrent/#comments</comments>
		<pubDate>Wed, 02 May 2007 12:34:27 +0000</pubDate>
		<dc:creator>enigmax</dc:creator>
				<category><![CDATA[Bittorrent Clients]]></category>
		<category><![CDATA[arbitrary_code]]></category>
		<category><![CDATA[bittorrent_client]]></category>
		<category><![CDATA[cpp]]></category>
		<category><![CDATA[Ktorrent]]></category>
		<category><![CDATA[torrent_file]]></category>
		<category><![CDATA[www_google]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/multiple-vulnerabilities-discovered-in-ktorrent/</guid>
		<description><![CDATA[<a href="http://ktorrent.pwsp.net/">Ktorrent</a>, the popular open-source BitTorrent client for Linux has been discovered to contain multiple vulnerabilities which can result in a hacker remotely executing arbitrary code.]]></description>
			<content:encoded><![CDATA[<p><img src="http://TorrentFreak.com//images/ktorrent.gif" align="right" alt="Ktorrent" /><br />
According to <a href="http://www.securityfocus.com/archive/1/467291/30/0/threaded">Security Focus</a>, Ktorrent versions 2.1.3 and below have a security flaw which allows for the remote execution of arbitrary code.</p>
<p>The vulnerabilities were discovered in the components chunkcounter.cpp and torrent.cpp and can be exploited by getting a user to use a modified torrent file, resulting in the possible control of the OS with the same privileges as the Ktorrent user.</p>
<p>There is currently no work-around for the flaws but the situation can be remedied by upgrading to the latest version of Ktorrent, <a href="http://ktorrent.pwsp.net/index.php?page=downloads">version 2.1.4</a>.</p>
<p>KTorrent is a BitTorrent client written in C++ for <a href="http://www.google.com/url?sa=t&#038;ct=res&#038;cd=1&#038;url=http%3A%2F%2Fwww.kde.org%2F&#038;ei=yn44RtXkDIrA0QTP0fiQDA&#038;usg=AFrqEzddO3IrcRj-QVINDSmW-equ6OVQUg&#038;sig2=zvoy36Ql4OTqbZc1Y5feDA">KDE</a>, offering mainline DHT and ÂµTorrent compatible peer exchange, port forwarding via UPnP and <a href="http://torrentfreak.com/ktorrent-supports-encryption/">protocol encryption</a> for getting round those pesky traffic-shaping ISP&#8217;s.</p>
<p>KTorrent version 2.2 will be released later this month and will include <a href="http://ktorrent.blogspot.com/2007/04/v22-teaser.html">new features</a> such as multiple tabs, moving finished downloads to another directory, and diskspace preallocation. Another good reason to upgrade!</p>
<p>Article from: <a href="http://torrentfreak.com">TorrentFreak</a>, check out our new blog at <a href="http://freakbits.com">FreakBits</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://torrentfreak.com/multiple-vulnerabilities-discovered-in-ktorrent/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
