<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TorrentFreak &#187; Trident Media Guard</title>
	<atom:link href="https://torrentfreak.com/tag/trident-media-guard/feed/" rel="self" type="application/rss+xml" />
	<link>https://torrentfreak.com</link>
	<description>Breaking File-sharing, Copyright and Privacy News</description>
	<lastBuildDate>Wed, 29 Oct 2014 20:38:50 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.2</generator>
	<item>
		<title>Major Vulnerability Found in Leaked Anti-Piracy Software</title>
		<link>https://torrentfreak.com/major-vulnerability-found-in-leaked-anti-piracy-software-110525/</link>
		<comments>https://torrentfreak.com/major-vulnerability-found-in-leaked-anti-piracy-software-110525/#comments</comments>
		<pubDate>Wed, 25 May 2011 11:28:17 +0000</pubDate>
		<dc:creator><![CDATA[enigmax]]></dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[Bluetouff]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[Trident Media Guard]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=35587</guid>
		<description><![CDATA[Trident Media Guard, the company entrusted by the French government to monitor file-sharing networks for copyright infringement, recently had some of their tools leaked onto the Internet following a security breach. Now researchers have published an analysis, with claims that an auto-update feature makes TMG's servers vulnerable to remote code injection and execution.<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img src="http://torrentfreak.com/images/tmg.jpg" align="right" alt="TMG">As detailed in our earlier <a href="http://torrentfreak.com/french-hadopi-3-strikes-anti-piracy-company-hacked-110514/">reports</a>, anti-piracy company Trident Media Guard (TMG) recently failed to secure some of their systems. Blogger and security researcher Olivier Laurelli, aka Bluetouff, originally reported the breach which included a wide open virtual &#8216;test&#8217; machine containing various tools. These, of course, spilled into the wild.</p>
<p>From the various files made available, some were easily viewable with a standard text editor, others &#8211; such as an executable called server_interface.exe &#8211; were more tricky. Thanks to a admittedly fairly hostile <a href="http://seclists.org/fulldisclosure/2011/May/434">Full Disclosure</a> security report we now have a clearer idea of what the package is capable of.</p>
<p>Penned by &#8216;CULT OF THE DEAD HADOPI&#8217;, the report refers to TMG as &#8220;Too Many Gremlins&#8221; along with reports not to expose them to bright lights. In it the server_interface.exe code is described as a Delphi service to which anyone can connect and start sending commands, no authentication (username/password) required. Perhaps even more worrying is a script which accepts auto-updates.</p>
<p>&#8220;An attacker can use the &#8216;Auto Update&#8217; feature (\x82) to force the server to download updates from an evil FTP server he controls. Of course, a downloaded file is executed<br>
just after the download,&#8221; write the researchers.</p>
<p>&#8220;Hence, anyone  who wants to raise an army against Too Many Gremlins, look for an open port on TCP 8500,&#8221; they add. </p>
<p>The implication here is that if this software was present on all TMG servers, in addition to being able to turn them on and off at will a hacker could take them over with custom code of his own choosing, potentially creating &#8220;an army&#8221; which could be used to attack TMG or indeed, anyone else.</p>
<p>Commenting on the research, Bluetouff told TorrentFreak that the discovery of the vulnerabilities mean that the French 3 strikes program might already have been compromised.</p>
<p>&#8220;If TMG is vulnerable to injectioning on the system used to provide IP addresses to the HADOPI, the whole process is fu**** up,&#8221; he explained.</p>
<p>&#8220;Someone could for example inject the Culture Ministry&#8217;s IP range, or worse, gain access between TMG and HADOPI&#8217;s VPN by stealing certificates&#8230; then gain access to a huge amount of personal data,&#8221; he added.</p>
<p>&#8220;For instance we don&#8217;t know if this new &#8216;test server&#8217; leak can compromise the LAN(S) of TMG with this exploit. Opacity is even for HADOPI. That&#8217;s why they went to audit TMG&#8217;s infrastructure with the CNIL [French Data Protection Office].&#8221;</p>
<p>&#8220;Anyway, this new episode shows that HADOPI was right to close their access,&#8221; he concludes.</p>
<p>That closure of access is a reference to Hadopi severing their Internet links to TMG once they found out about the leak and resorting to shifting IP addresses around by DVD and the postal system instead. That is hardly efficient and undoubtedly TMG will be working hard to get back into the 21st century.</p>
<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://torrentfreak.com/major-vulnerability-found-in-leaked-anti-piracy-software-110525/feed/</wfw:commentRss>
		<slash:comments>43</slash:comments>
		</item>
		<item>
		<title>French 3 Strikes Suspended Due To Anti-Piracy Security Alert</title>
		<link>https://torrentfreak.com/french-3-strikes-suspended-due-to-anti-piracy-security-alert-110517/</link>
		<comments>https://torrentfreak.com/french-3-strikes-suspended-due-to-anti-piracy-security-alert-110517/#comments</comments>
		<pubDate>Tue, 17 May 2011 07:14:25 +0000</pubDate>
		<dc:creator><![CDATA[enigmax]]></dc:creator>
				<category><![CDATA[Hot Off The Press]]></category>
		<category><![CDATA[hadopi]]></category>
		<category><![CDATA[Trident Media Guard]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=35243</guid>
		<description><![CDATA[Following a weekend security breach at Trident Media Guard, the outfit spearheading data collection for France's 3 strikes anti-piracy drive, the country's HADOPI agency has severed interconnection with the company. This means that, pending an enquiry, French file-sharers are no longer being tracked, a major embarrassment for the government.<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img src="http://torrentfreak.com/images/tmg.jpg" align="right" alt="tmg">On Saturday evening, with the invaluable assistance of blogger and security researcher Olivier Laurelli, aka Bluetouff, TorrentFreak first reported that Trident Media Guard (TMG), the private company entrusted to carry out file-sharing network monitoring for the French government, had been hacked.</p>
<p>As became evident, the term &#8216;hacked&#8217; was probably overly generous to TMG, since according to Bluetouff the company had left the equivalent of its front door open.</p>
<p>“A virtual machine leaked a lot of information like scripts, p2p clients to generate fake peers, local physical addresses in the datacenter and even a password that could lead to a major global TMG security breach,&#8221; he explained.</p>
<p>TorrentFreak obtained and listed some of the files in question in our <a href="http://torrentfreak.com/french-hadopi-3-strikes-anti-piracy-company-hacked-110514/">earlier report</a>, but as the contents of the leak were examined in more detail, it became evident that TMG had not only leaked out its own data, but that belonging to the subjects of their monitoring.</p>
<p>The day after our report, Guillaume Champeau of <a href="http://www.numerama.com">Numerama</a>, a publication which follows French file-sharing issues in-depth, contacted TorrentFreak to say he had been able to show that IP addresses linked to the 3-strikes process may also have been leaked. He informed the HADOPI agency of his find which led to them to report that they were taking the matter &#8220;very seriously&#8221;.</p>
<p>Indeed, that concern has been followed by an announcement from Eric Walter, the secretary-general of HADOPI. Walter, a friend of French President Nicolas Sarkozy, who  now confirms that &#8220;as a precaution Hadopi has decided to temporarily suspend its interconnection with TMG.&#8221;</p>
<p>What this effectively means is that since TMG is the only company licensed to do this work for the government, from now on and pending a review, the French 3 strikes regime for dealing with illicit file-sharing is suspended. Data gathered before Saturday evening, however, can still be used.</p>
<p>This suspension will be seen by some as a major embarrassment for President Sarkozy. France has taken a particularly hard-line approach to unlawful file-sharing and the government has continually brushed aside calls from the public and various watchdogs to consider more carefully the privacy and related rights issues connected with such a regime.</p>
<p><strong>Update:</strong> According to French news sources the three strikes regime is set to continue, but data will not be transferred to Hadopi via the usual electronic transfers, but on physical media.</p>
<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://torrentfreak.com/french-3-strikes-suspended-due-to-anti-piracy-security-alert-110517/feed/</wfw:commentRss>
		<slash:comments>63</slash:comments>
		</item>
		<item>
		<title>BitTorrent Spammers Chosen to Spy On French Pirates</title>
		<link>https://torrentfreak.com/bittorrent-spammers-chosen-to-spy-on-french-pirates-100126/</link>
		<comments>https://torrentfreak.com/bittorrent-spammers-chosen-to-spy-on-french-pirates-100126/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 22:01:32 +0000</pubDate>
		<dc:creator><![CDATA[Ernesto]]></dc:creator>
				<category><![CDATA[All]]></category>
		<category><![CDATA[hadopi]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[Trident Media Guard]]></category>

		<guid isPermaLink="false">http://torrentfreak.com/?p=21007</guid>
		<description><![CDATA[The French anti-piracy outfit Trident Media Guard has been chosen by the entertainment industry to track and report illegal downloaders in France. The company, known globally for its pollution of BitTorrent and other file-sharing networks with fake data, will assist in the recently passed Hadopi three-strikes law.<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></description>
				<content:encoded><![CDATA[<p><img src="http://torrentfreak.com/images/tmg.jpg" align="right" alt="tmg">Starting in a few months, French file-sharers are set to be tracked and reported to the authorities in an attempt to lower the country&#8217;s piracy rate. </p>
<p>Under the new Hadopi law, alleged copyright infringers will be reported to a judge once they have received three warnings. The judge will then review the case and hand down any one of a range of penalties, from fines through to disconnecting the Internet connection of the infringer.</p>
<p><a href="http://www.tmg.eu">Trident Media Guard</a>, the investigative company that will be responsible for tracking down alleged infringers, was <a href="http://www.zdnet.fr/actualites/internet/0,39020774,39712516,00.htm">presented</a> to the public today. Interestingly enough this private company was not appointed by the government but by the entertainment industries, including the major record labels and movie studios. </p>
<p>Among file-sharers Trident Media Guard (TMG) is not a new name. In fact, thousands if not millions of people have run into them already as they are known to hinder illegal downloads by spreading fake data. For their &#8216;revolutionary&#8217; anti-P2P technology they have submitted a <a href="http://www.faqs.org/patents/app/20090210492">patent application</a> which is currently under review. </p>
<p>Aside from polluting file-sharing networks, the company will now also be responsible for tracking and reporting pirates to the authorities. TMG has the capacity to record up to 25,000 infringements a day, and according to initial estimates 10,000 offenders a day are expected to receive a warning.</p>
<p>TMG&#8217;s tracking technology will cover a wide range of file-sharing networks, with four of them being monitored as a priority. There is little doubt that BitTorrent, eDonkey and Gnutella will be the major targets, but according to TMG it is also possible to monitor Rapidshare, newsgroups and streaming services. </p>
<p>How they will be able to monitor these non-P2P services remains a mystery for now, but it suggests some form of privacy invasion. Unlike with BitTorrent, a third party can&#8217;t simply see what a user is downloading as they do when they actively monitor a user&#8217;s P2P connections. </p>
<p>In the UK the ISP Virgin Media is trialling a technique which involves <a href="http://torrentfreak.com/deep-packet-inspection-080629/">Deep Packet Inspection</a> to monitor the level of illicit file-sharing across a percentage of its customer base.</p>
<p>Because systems like this are believed to breach the privacy of individual Internet users, the European Commission has been asked to review <a href="http://news.bbc.co.uk/2/hi/technology/8480699.stm">its legality</a>.</p>
<p>Thus far no details have been published on the data gathering techniques of TMG, but considering the enormous opposition against the Hadopi law there is little doubt that their every move will be closely watched.</p>
<p>Source: <a href="https://torrentfreak.com">TorrentFreak</a>, for the latest info on <a href="http://torrentfreak.com/category/copyright-issues/">copyright</a>, <a href="http://torrentfreak.com/category/pirate-talk/">file-sharing</a> and <a href="http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/">anonymous VPN services</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://torrentfreak.com/bittorrent-spammers-chosen-to-spy-on-french-pirates-100126/feed/</wfw:commentRss>
		<slash:comments>110</slash:comments>
		</item>
	</channel>
</rss>
