gfxgfx
 
Please login or register.

Login with username, password and session length
 
gfx gfx
gfx
76793 Posts in 13502 Topics by 1651 Members - Latest Member: Arnold99 December 03, 2024, 01:41:40 am
*
gfx*gfx
gfx
WinMX World :: Forum  |  Discussion  |  WinMx World News  |  Huge Security Flaw Makes VPNs Useless for BitTorrent
gfx
gfxgfx
 

Author Topic: Huge Security Flaw Makes VPNs Useless for BitTorrent  (Read 1630 times)

0 Members and 1 Guest are viewing this topic.

Offline Blitzen

  • Forum Member
Huge Security Flaw Makes VPNs Useless for BitTorrent
« on: June 17, 2010, 09:58:39 pm »

http://torrentfreak.com/huge-security-flaw-makes-vpns-useless-for-bittorrent-100617

Quote
Millions of BitTorrent users who have chosen to hide their identities through a VPN service may not be as anonymous as they would like to be. Due to a huge security flaw, those who use IPv6 in combination with a PPTP-based VPN such as Ipredator are broadcasting information linking to their real IP-address on BitTorrent.

As pressure from anti-piracy outfits on governments to implement stricter copyright laws increases, millions of file-sharers have decided to protect their privacy by going anonymous. In Sweden alone an estimated 500,000 Internet subscribers are hiding their identities. Many of these use PPTP-based VPNs such as The Pirate Bay’s Ipredator or Relakks.

Thus far, these services were believed to adequately hide a user’s IP-address from people they connect to in BitTorrent swarms, but this is not always the case. At the Telecomix Cipher conference a security flaw was revealed that allows third parties to find the true IP-address of someone connected through a VPN.

The security risk is caused by a lethal combination of IPv6 and PPTP-based VPN services, which are very common. IPv6 is the Internet protocol that will succeed IPv4. The protocol is promoted by Windows 7 and Vista, among others, and most people are using it without even realizing it.

The technical details of the vulnerability, explained in this talk (see below), reveal that the true IP-address of users using IPv6 can be easily traced. Even worse, it seems that the Swedish Anti-piracy Bureau may already be using this flaw to gather data on ‘anonymous’ BitTorrent users.

The vulnerability is not limited to BitTorrent either. It can expose people who believe that they are hiding their real IP-address through nearly every connection.

In addition to this gaping hole in VPNs such as Ipredator and Relakks, the talk exposes several other weaknesses from a privacy point of view. Among other things, it is fairly easy to find MAC-addresses and computer names of people who use the same VPN.

The people who run Ipredator are aware of the issue, and TorrentFreak was informed that their users will be notified about the problem. Other VPNs using the same system may want to do the same. From our understanding of the issue, turning IPv6 off should alleviate the threat and make users fully anonymous again.


Offline Max™

  • MX Hosts
  • *****
  • If Im Not Back later... Wait Longer
    • Maxtech
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #1 on: June 18, 2010, 07:39:43 am »
Big brother IS watching you, even when you are hiding, it seems



Try Connecting, the attacks may let you  https://patch.winmxconex.com/

Offline White Stripes

  • Core
  • *****
  • ***
  • Je suis aimé
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #2 on: June 18, 2010, 08:58:10 am »
broken/unfinished ipv6 stacks that dont even need to be on in the first place (shame on ubuntu.. as for windows... uh.. its windows... what do you expect?).... and broken vpn software... wow.... i call this one a serious clusterfsck of bugs that make for a nasty info leak...


btw, theres something called RSS; http://en.wikipedia.org/wiki/RSS --- cross posting so much from torrentfreak seems unneeded...

personally i use google reader ( http://google.com/reader ) for my rss cos i can move from machine to machine and still see my unread articles but many standalone apps and browsers work just as well (odd that firefox doesnt have builtin RSS tho but i think there is an addon for it...)

also; wmw news supports rss ;) now if only wmw news would just send the first post of the thread rather than the whole thread... would make a nice feature... or a wmw blog perhaps? dunno... what do you guys think?

Offline Lagerlout666

  • Forum Member
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #3 on: June 18, 2010, 01:35:23 pm »
The default feed is for the 5 most recent posts:

http://yourdomainname.com/forum/index.php?action=.xml

There are also several "sub-actions" available to the above action, specifying exactly what to display. The most important sub-actions are:

Recent Posts (displays the most recent posts that you can see)
"Sub-action": recent
Default: Shows 5 most recent posts

Available options:
limit=x - display the "x" most recent posts (if number is less than 5, it will display 5. If number is larger than 255, it will display 255).
board=y - display only the recent posts from board "y"
boards=x,y,z - display only the recent posts from the specified boards
c=x or c=x,y,z - display only the recent posts from boards in the specified category/categories

Example: http://yourdomainname.com/forum/index.php?action=.xml;sa=recent;board=72;limit=10
 
You can syndicate these links by giving your readers the URLs to your RSS feeds.


I use this for my search page gives me the news at the bottom :-D
The Solution to 99% of winmx problems

nap.winmxgroup.net        -ONLINE again YAY!!!!!! :D

Praise's daily at the church of "Kopimi"

Offline Blitzen

  • Forum Member
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #4 on: June 18, 2010, 02:00:29 pm »
 @Stripes  so are you saying you would like to see no more news posts from torrentfreak ?

Offline Max™

  • MX Hosts
  • *****
  • If Im Not Back later... Wait Longer
    • Maxtech
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #5 on: June 18, 2010, 05:41:42 pm »
Just to confirm, Firefox does have a number of rss plugin's available,



Try Connecting, the attacks may let you  https://patch.winmxconex.com/

Offline GhostShip

  • Ret. WinMX Special Forces
  • WMW Team
  • *****
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #6 on: June 18, 2010, 07:27:07 pm »
Using windows 7 seems to be the biggest part of this exploit  :lol:

Offline White Stripes

  • Core
  • *****
  • ***
  • Je suis aimé
Re: Huge Security Flaw Makes VPNs Useless for BitTorrent
« Reply #7 on: June 19, 2010, 04:41:11 am »
@tiny; WOW much infos! very cool :) and many thx! but no subaction for the first post of eachthread instead of the most recent discussion in one thread? (why i suggested a blog) btw, limit actually let me goto 1 on this forum ;)
(after some experementation i think i would need a seperate script to parse the rss feed from the forum to do what i want)

@blitzen; i didnt mean it that way... i mean you should look around a bit more... covering only one site does not unbiased or full news make... and my RSS quip was moreso saying that 'old news is old' .... by the time it shows here ive already read it from the RSS feed of torrentfreak in google reader before seeing it here... ...and.... admittedly i was a bit grumpy when i made that post (my bad and i apologise)...  but as far as news goes... look around... be nosy... find verifiable stuff on other sites that arent as well known... or hidden deep in sites that are well known... major outlets will occasionally make reports on things that are surprising... and some tiny sites will have some surprising infos...

@all using an RSS reader (of the users choice) connected to various p2p news sites (sites that report on more than p2p usually let you select a subject from which to get news) is something i highly recommend... might be something that one site gets that another misses... ...and normally you get the info as soon as the article is published so you are right on top of the latest... (a good idea esp if the latest is a bit of a 'red alert' situation)...

WinMX World :: Forum  |  Discussion  |  WinMx World News  |  Huge Security Flaw Makes VPNs Useless for BitTorrent
 

gfxgfx
gfx
©2005-2024 WinMXWorld.com. All Rights Reserved.
SMF 2.0.19 | SMF © 2021, Simple Machines | Terms and Policies
Page created in 0.016 seconds with 24 queries.
Helios Multi © Bloc
gfx
Powered by MySQL Powered by PHP Valid XHTML 1.0! Valid CSS!