LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-16-2018, 01:34 AM   #1
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
[bittorrent] client(s) vulnerable.


this concerns me and my bittorrent client, Transmission.

https://arstechnica.com/information-...your-computer/
 
Old 01-17-2018, 02:02 AM   #2
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
i also use transmission-daemon, but was thinking of switching to rtorrent.
anyhow, authentication enabled.
 
Old 01-17-2018, 09:12 AM   #3
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Original Poster
Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
Quote:
Fedora Update System 2018-01-17 01:56:29 EST
transmission-2.92-11.fc26 has been pushed to the Fedora 26 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/upda...018-b3d58d82a0
my transmission were updated today:

# transmission-gtk -v
transmission-gtk 2.92 (14714)

i suspect that this version (fedora 27) is patched.
 
Old 01-18-2018, 01:26 AM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
i _think_ my version is patched now...:
https://bugs.archlinux.org/task/57086
the 2 comments seem conflicting, and i'm not sure what the final situation is (was the patch in the second comment applied? does that mean i do not need to password protect my transmission-daemon anymore?)

according to https://github.com/transmission/transmission/pull/468 the issue is fixed, but how?

i think i'll just assume that people are sensible and the change has already trickled down to my arch box.

but i'm keeping the password enabled anyhow.
 
Old 01-18-2018, 05:09 AM   #5
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Original Poster
Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
ive got openbsd bridge that allows only few known ports (http[s], dns, dhcp, steam, battle.net, irc) out/in from/to my network, ive got udp port 9091 blocked by default pf rules, does that mean that i were not vulnerable ?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
best Bittorrent client? shinystuffrox Linux - Desktop 33 11-11-2008 02:10 PM
which bittorrent client you using?? manas Linux - Software 8 04-09-2007 06:22 PM
Bittorrent client Sir Loin Linux - Software 3 02-19-2007 08:31 PM
Bittorrent client joeljkp Linux - Server 1 10-31-2006 03:26 AM
bittorrent client Ryan450 Linux - Software 9 09-19-2004 07:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration