BitTorrent Client Transmission Suffers Remote Takeover Vulnerability

Transmission, one of the most used non-commercial BitTorrent clients, has a vulnerability that allows outsiders to gain control over people’s computers. The flaw affects users who have remote control enabled with the default password. The vulnerability was revealed by a Google researcher, who plans to disclose similar remote code execution flaws in other torrent clients as well.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and more. We also have VPN discounts, offers and coupons

With millions of active users, Transmission is one of the most used BitTorrent clients around, particularly for Mac users.

The application has been around for more than a decade and has a great reputation. However, as with any other type of software, it is not immune to vulnerabilities.

One rather concerning flaw was made public by Google vulnerability researcher Tavis Ormandy a few days ago. The flaw allows outsiders to gain access to Transmission via DNS rebinding. This ultimately allows attackers to control the BitTorrent client and execute custom code.

Ormandy has published a patch, which was also shared with the private Transmission security list at the end of November. Transmission, however, has yet to address the issue in an update.

The relatively slow response was the reason why Ormandy decided to make it public before Project Zero’s usual 90-day window expired, Ars highlights. This allows other projects to address the vulnerability right away.

“I’m finding it frustrating that the transmission developers are not responding on their private security list,” Google’s vulnerability researcher writes. “I’ve never had an opensource project take this long to fix a vulnerability before, so I usually don’t even mention the 90 day limit if the vulnerability is in an open source project.”

A member of the Transmission developer team informed Ars that they will address this ASAP, noting that the issue only affects users who have remote control enabled with the default password. This means that people who disable it or change their password can easily ‘patch’ it until the official update comes out.

Interestingly, this isn’t the last BitTorrent related vulnerability Ormandy plans to expose. According to one of his tweets on the matter, this is just the “first of a few remote code execution flaws in various popular torrent clients.”

Judging from a message the researcher sent late November, uTorrent is on the list as well. Apparently, the company’s security email address wasn’t set up correctly at the time, so BitTorrent inventor Bram Cohen has been acting as a forwarding service.

uTorrent?

Source: TF, for the latest info on copyright, file-sharing, torrent sites and more. We also have VPN discounts, offers and coupons

World of Warcraft: Schwierigkeitsgrad skaliert in ganz Azeroth

Mit dem letzten großen Update für die Erweiterung Legion erscheint eine größere Änderung für ganz World of Warcraft: Der Schwierigkeitsgrad passt sich weitgehend dem Level des Spielers an – auch in Dungeons. (WoW, MMORPG)

Mit dem letzten großen Update für die Erweiterung Legion erscheint eine größere Änderung für ganz World of Warcraft: Der Schwierigkeitsgrad passt sich weitgehend dem Level des Spielers an - auch in Dungeons. (WoW, MMORPG)

Open Source: Microsoft liefert Curl in Windows 10 aus

Das Betriebssystem Windows 10 ist um eine wichtige Open-Source-Anwendung reicher: Curl. Es läuft nicht nur in Waschmaschinen und Autos, sondern auch schon über 20 Jahre auf Windows. Microsoft übernimmt jetzt die Pflege eigener Builds. (Open Source, Mic…

Das Betriebssystem Windows 10 ist um eine wichtige Open-Source-Anwendung reicher: Curl. Es läuft nicht nur in Waschmaschinen und Autos, sondern auch schon über 20 Jahre auf Windows. Microsoft übernimmt jetzt die Pflege eigener Builds. (Open Source, Microsoft)

Beware a bottled booger blast—they can blow up your throat, doctors warn

An otherwise healthy 34-year-old man throttled a sneeze—and had regrets.

Enlarge / Picture shows a woman about to sneeze holding a handkerchief in her hand. (credit: Getty | Bettmann)

Ah… AHHH… Choose wisely when it comes to handling that impending sneeze. Holding one in can lead to some serious damage, British doctors report Monday in BMJ Case Reports.

In their rare-disease case report, they relay the tale of an otherwise healthy 34-year-old male who managed to tear a hole the back of his throat trying to extinguish a snot explosion.

The man showed up in an emergency room with an alarming popping sensation and swelling in his throat. He was also in terrible pain and could barely talk. Subsequent X-rays and CT scans revealed that he had bubbles of air throughout his neck, including along his spine. The doctors also noted a crackling, grating sound coming from both sides of his throat down to his chest, which is a sign of gas trapped inside tissue.

Read 5 remaining paragraphs | Comments

Boeing und SpaceX: Experten warnen vor Sicherheitsmängeln bei Raumfähren

Die US-Raumfahrtbehörde Nasa will endlich wieder US-Astronauten in US-Raumschiffen zur ISS bringen. Doch eine Expertenkommission schätzt die Raumfähre von Boeing und SpaceX für bemannte Flüge zur ISS als nicht sicher genug ein. (Raumschiff, Technologie…

Die US-Raumfahrtbehörde Nasa will endlich wieder US-Astronauten in US-Raumschiffen zur ISS bringen. Doch eine Expertenkommission schätzt die Raumfähre von Boeing und SpaceX für bemannte Flüge zur ISS als nicht sicher genug ein. (Raumschiff, Technologie)

An appreciation of games that click back and change the gamers who love them

From The Dig to Pillars of Eternity, gaming does something no other pop culture medium can.

Don't worry, no Ouya games snuck into this discussion. (It just happens to have a timeless, sleek controller because famous designer Yves Béhar came up with the concept.)

Warning: This piece contains mild spoilers by referencing plot points for The Dig, Mass Effect, and Pillars of Eternity.

Anybody with a passing familiarity with video games or those who play them knows that games are more than technology. But classifying games as simply some pop culture ephemera that typifies trends and norms also doesn’t perfectly describe them. To really get to the essence of games and the narratives they create, you need to find folks like me—or, more precisely, me sitting at a computer at age eight. That kid, to poach unnecessarily from Deep Space Nine, is both “the dreamer and the dream.”

To be less abstract, academic Walter Ong once wrote an essay titled “Writing is a Technology That Restructures Thought,” in which he argued that literacy was not a measure of intelligence, savvy, or know-how. Rather, Ong saw technology as something that restructures the brains of those who think with it, feel with it, and use it.

Read 30 remaining paragraphs | Comments

Destiny 2 keeps on failing to bring me back

Microtransactions won’t satisfy these post-holiday doldrums.

Enlarge / I'm sorry, it's just not doing it for me anymore guys. I don't know what to tell ya... (credit: Activision)

It’s the second week of January and I’m playing Suikoden II, which turns 20 this year. That’s not completely absurd in the lull between the holiday season and the next glut of big new releases that demand my immediate attention. If there was ever a time for me to play a game from 1998, it’s now.

But then I remember that Destiny 2 came out last September—and its first expansion just a few weeks ago. And then some old, familiar jaws are chewing at the back of my mind, reminding me that, by all rights, I should be filling my temporarily free hours by tooling around Mercury and The Leviathan. I want to give myself over to the same satisfying, mechanical repetition that Destiny gave me for hundreds of hours over two years—more time than just about any other game I’ve played.

But I can’t.

Read 13 remaining paragraphs | Comments

Artist transforms herself into a virtual assistant and obeys your commands

Would we rather have a human servant or Alexa? Lauren McCarthy decided to find out.

Courtesy of Lauren McCarthy

We love to talk about how our virtual assistants fail us. They allow parrots to order fire on Amazon and play porn channels to kids. Obviously, it's going to be quite some time before these machines will be as good as human assistants. That's why the quest to create personalities for assistive technology is a serious business. Google has a “personality team” working on providing Assistant with a more human-like personality. Now artists are testing the limits of these technologies too, asking what would happen if humans actually behaved the way our virtual assistants do.

Artist and UCLA professor Lauren McCarthy’s project, LAUREN, is a performance piece that examines how home automation effects social interactions within a home. The artist installs customized software and hardware in a willing participant’s home.

Read 16 remaining paragraphs | Comments

Tencent: Lego will mit Tencent in China digital expandieren

Lego hat große Pläne in China: Gemeinsam mit dem Internetunternehmen Tencent soll in dem Land das hauseigene soziale Bastelnetzwerk Lego Life aufgebaut werden, außerdem soll es gemeinsam produzierte Spiele und eine Videoplattform geben. (Lego, Games)

Lego hat große Pläne in China: Gemeinsam mit dem Internetunternehmen Tencent soll in dem Land das hauseigene soziale Bastelnetzwerk Lego Life aufgebaut werden, außerdem soll es gemeinsam produzierte Spiele und eine Videoplattform geben. (Lego, Games)

Beta-Update: Gesichtsentsperrung für Oneplus Three und 3T verfügbar

Oneplus hat eine neue Beta-Firmware für das Oneplus Three und 3T verfügbar gemacht: Besitzer der Smartphones können damit die Gesichtsentsperrung nutzen, die der Hersteller erstmals auf dem Oneplus 5T vorgestellt hatte. (Oneplus, Smartphone)

Oneplus hat eine neue Beta-Firmware für das Oneplus Three und 3T verfügbar gemacht: Besitzer der Smartphones können damit die Gesichtsentsperrung nutzen, die der Hersteller erstmals auf dem Oneplus 5T vorgestellt hatte. (Oneplus, Smartphone)