NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Linux

Linux


Transmission 1.61 Plugs CSRF Hole

The CSRF exploit was discovered in Transmission's web interface

By Daniel Pop-Silaghi, Linux Editor

13th of May 2009, 11:00 GMT

Adjust text size:


Transmission's Web Interface Controls
Enlarge picture
As you all know, Canonical's popular Ubuntu Linux distribution ships with Transmission as the default BitTorrent client. One of the newest features of Transmission is a web-based interface, accessible from your Internet browser. And though there aren't many users interested in or aware of this alternative way of managing torrents, it is
enabled by default in Transmission's preferences.

Unfortunately, a pretty serious vulnerability in this new feature affects all Transmission versions prior to the just released 1.61. The CSRF (Cross-Site Request Forgery) hole was discovered by security researcher Mike Bailey and was documented on his blog. The Cross-Site Request Forgery attack lures users into opening web pages containing malicious requests that allow the attacker to perform various actions (password change, downloads, important information changes) on behalf of the unaware victim.

Mike Bailey better explains how this hole can affect a Linux machine: "Basically, it allows me to first change the download destination to one of my choosing, then download a torrent of my choosing. This is bad – I could force a user to download a new .bashrc file or overwrite their entire home directory." He also created a proof-of-concept to demonstrate how this works. Fortunately, the Transmission team was quick to respond and released the 1.61 version that fixes this vulnerability. Still, Canonical has yet to push the update through their channels, even though this is quite a serious security issue.

Mike Bailey also notes that a similar exploit was found in Azureus' (another popular P2P and BitTorrent client, now known as Vuze) web interface: "Nate McFeters talked about doing the same thing through an XSS hole in the Azureus web interface in his talk, "the Internet is Broken", at Black Hat 2008."

Download Transmission 1.61 right now from Softpedia.

TAGS:

Transmission | Ubuntu | security | exploit | CSRF
Read by 2,521 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.5/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Sabily 9.04 - Ubuntu for Muslims

Zenwalk 6.0 Live Edition Released

Slack Mini Server 1.4.3 Features LZMA Support

Ubuntu One: Free Online Storage

Softpedia Linux Weekly, Issue 44

Parted Magic 4.1 Brings GParted 0.4.5

How to Install OpenOffice.org 3.1 on Ubuntu 9.04

Available Now: KDE 4.2.3

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM