Jump to content
Not connected, Your IP: 18.118.140.108
Sign in to follow this  
zhang888

Private Tracker users (SceneAccess) got deanonimized using BBcode injection

Recommended Posts

Hello, you might have heard about a recent "vulnerability" that is making some headlines,

specifically the one that allowed a private tracker user to embed an object to a 3d party location,

where he set up a sniffer with logs on his own server.

 

The full story is available on TorrentFreak:

 

https://torrentfreak.com/private-tracker-member-data-leaked-via-bbcode-exploit-160313/

 

 

Now, if you ask yourself why did Air implement the external resource redirect warning - this was

done in order to mitigate such issues, as well as many more. Another great addition by Air is the

image proxy - so now if you load an Avatar or a signature, or try to embed anything using BBcode,

that URL will be pre-processed and in case an image will be found, an external script will pick up

this image from the remote server without exposing your real IP.

 

So AirVPN community was never vulnerable to such attack classes in the first place

 

 

 

This is another good example why it is mandatory to use VPNs when you access torrent trackers or

any other content on the internet where a 3d party may log or analyze your activities.


Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees.

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image
Sign in to follow this  

×
×
  • Create New...