Monday, February 26, 2018

Flaw in Popular μTorrent Software Lets Hackers Control Your PC Remotely


If you have installed world's most popular torrent download software, μTorrent, then you should download its latest version for Windows as soon as possible.

Google's security researcher at Project Zero

discovered

a serious remote code execution vulnerability in both the 'μTorrent desktop app for Windows' and newly launched 'μTorrent Web' that allows users to download and stream torrents directly into their web browser.

μTorrent Classic and μTorrent Web apps run in the background on the Windows machine and start a locally hosted HTTP RPC server on ports 10000 and 19575, respectively, using which users can access its interfaces over any web browser.

However, Project Zero researcher Tavis Ormandy found that several issues with these RPC servers could allow remote attackers to take control of the torrent download software with little user interaction.

According to Ormandy, uTorrent apps are vulnerable to a hacking technique called the "domain name system rebinding" that could allow any malicious website a user visits to execute malicious code on user's computer remotely.

To execute DNS rebinding attack, one can simply create a malicious website with a DNS name that resolves to the local IP address of the computer running a vulnerable uTorrent app.

"This requires some simple DNS rebinding to attack remotely, but once you have the secret you can just change the directory torrents are saved to, and then download any file anywhere writable," Ormandy explained.

Proof-of-Concept Exploits for uTorrent Software Released Publicly

Ormandy also provided proof-of-concept exploits for

μTorrent Web

and μTorrent desktop (

1

and

2

), which are capable of passing malicious commands through the domain in order to get them to execute on the targeted computer.

Last month, Ormandy demonstrated same attack technique against the

Transmission BitTorrent app

.

Ormandy reported BitTorrent of the issues with the uTorrent client in November 2017 with a 90-days disclosure deadline, but a patch was made public on Tuesday—that's almost 80 days after the initial disclosure.

What's more? The re-issued new security patches the same day after Ormandy found that his exploits continued to work successfully in the default configuration with a small tweak.

"This issue is still exploitable," Ormandy said. "The vulnerability is now public because a patch is available, and BitTorrent have already exhausted their 90 days anyway." 
"I see no other option for affected users but to stop using uTorrent Web and contact BitTorrent and request a comprehensive patch."

Patch your uTorrent Software NOW!

The company assured its users that all vulnerabilities reported by Ormandy it two of its products had been

addressed

with the release of:

  • μTorrent Stable 3.5.3.44358
  • BitTorrent Stable 7.10.3.44359
  • μTorrent Beta 3.5.3.44352
  • μTorrent Web 0.12.0.502

All users are urged to update their software immediately.



from The Hacker News http://ift.tt/2F6ZaOp

Ransomware: Get ready for the next wave of destructive cyberattacks

Brazilian and German development banks agree blockchain partnership


The Brazilian Economic and Social Development Bank (BNDES) and Germany's development bank KfW have approved a memorandum of understanding around the improvement of blockchain software TruBudget.

The software developed by KfW is aimed at improving transparency and efficiency in public resources that finance development projects. It uses a distributed ledger to provide access to records of budgetary spending on schools and hospitals from the point of payment to subsequent transactions including procurement, contracting and implementation of a project.

Under the partnership, KfW will offer BNDES access to its software repository and will manage all the other tools required to work on the improvement of TruBudget, as well as technical support to the Brazilian bank.

"The bank will not use [TruBudget] for commercial purposes nor will it claim intellectual property for the software or for its improved version," BNDES said in a statement.

"During the joint execution of the project, KfW intends to formalize TruBudget's license on a open source basis," The statement added.

Before May, BNDES intends to do a pilot of TruBudget on the Amazon Fund, which makes non-reimbursable financial operations and has KfW as one of its donors.



from Latest Topic for ZDNet in... http://ift.tt/2sS9TY8

PhishMe acquired by private equity troupe, rebrands as Cofense

IBM Security Bulletin: Daeja ViewONE Virtual is affected by a Cross-Site Scripting vulnerability

IBM Daeja ViewONE Virtual is vulnerable to Persistent Cross-site Scripting attack

CVE(s): CVE-2018-1399

Affected product(s) and affected version(s):

IBM Daeja ViewONE Virtual 4.1.5, IBM Deaja ViewONE Virtual 5.0.1, 5.0.2 and 5.0.3

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22013094
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/138435

The post IBM Security Bulletin: Daeja ViewONE Virtual is affected by a Cross-Site Scripting vulnerability appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2HMFq1i

IBM Security Bulletin: IBM Lotus Protector for Mail Security is affected by a publicly disclosed vulnerability in BIND

IBM Lotus Protector is affected by a publicly disclosed vulnerability in BIND. IBM has addressed this vulnerability.

CVE(s): CVE-2017-3145

Affected product(s) and affected version(s):

IBM Lotus Protector for Mail Security 2.8.1.0
IBM Lotus Protector for Mail Security 2.8.3.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22013558
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137694

The post IBM Security Bulletin: IBM Lotus Protector for Mail Security is affected by a publicly disclosed vulnerability in BIND appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2GLEWHx

IBM Security Bulletin: IBM Protector is affected by Open Source XMLsoft Libxml2 Vulnerabilities

IBM Protector is affected by Open Source XMLsoft Libxml2 Vulnerabilities. IBM Protector has addressed this vulnerability.

CVE(s): CVE-2017-16931, CVE-2017-16932

Affected product(s) and affected version(s):

IBM Lotus Protector for Mail Security 2.8.1.0
BM Lotus Protector for Mail Security 2.8.3.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22013890
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/135488
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/135489

The post IBM Security Bulletin: IBM Protector is affected by Open Source XMLsoft Libxml2 Vulnerabilities appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2HJI2wV