Jump to content

uTorrent Forums Hacked, Passwords Compromised


Batu69

Recommended Posts

he uTorrent community forums have been hacked, exposing the private details of hundreds of thousands of users. The hackers were able to get their hands on the user database, and a warning issued by the software maker says that passwords should be considered compromised.

 

With well over 150 million active users a month uTorrent is by far the most used BitTorrent client around.

In addition, the software also has a dedicated community forums with tens of thousands of visitors per day, and over 388,000 registered members.

 

According to a recent security alert these users would be to update their passwords, as the forum database has been compromised by hackers.

The uTorrent team, which is part of BitTorrent Inc, was alerted to the issue by one of their vendors earlier this week. While the vulnerability didn’t originate at the uTorrent forums, it was indirectly compromised.

 

“The vulnerability appears to have been through one of the vendor’s other clients, however it allowed attackers to access some information on other accounts. As a result, attackers were able to download a list of our forum users,” uTorrent writes.

 

The security alert is posted in the forums but as far as we know users haven’t been notified individually. There is no mention of the massive security breach on uTorrent and BitTorrent’s social media accounts either.

 

uTorrent forums with security warning
 
utorrcomprom-768x523.png
 

According to the uTorrent team it’s not entirely clear what data has been compromised by the hack. The company’s vendor has made some changes to mitigate the fallout, but the hashed passwords are likely compromised.

 

“We are investigating further to learn if any other information was accessed. Our vendor has made backend changes so that the hashes in the file do not appear to be a usable attack vector,” the uTorrent team writes.

 

“As a precaution, we are advising our users to change their passwords. While the passwords may not be used as a vector on the forums, those hashed passwords should be considered compromised,” they add.

 

In addition, users are strongly advised to update their passwords at other sites, if the ones they’re using are identical to the one deployed on the forum.

While uTorrent no longer reports the number of forum users, a few months ago it listed 388,358 members who together wrote over half a million posts.

 

The uTorrent forums use the Invision Power Board software. The same software also powers the separate BitTorrent forums, which given the lack of a security notice doesn’t appear to be compromised.

 

TorrentFreak asked BitTorrent Inc. at which vendor the hack originated and whether it intends to communicate the issue to forum users in a more direct manner, but we have yet to hear back.

 

Article source

Link to comment
Share on other sites


  • Replies 3
  • Views 1.1k
  • Created
  • Last Reply
knowledge-Spammer

now this is not good  program may get a big update aswell now i think

vulnerability  are going to be a big problem soon u can see it happen  everywere

 

Link to comment
Share on other sites


2 hours ago, Batu69 said:

The uTorrent community forums have been hacked, exposing the private details of hundreds of thousands of users.

Which is why you should never use RL data for anything on the net, bar for your bank, shopping, income tax and friends/relatives.

Once a patient asked me my name during one of those ~48 hour ER shifts, and I panicked. It was on the tip of my tongue, but all I could think of were my nicks.

My nurse saved the day .......

;)

Reminder - email the DSM that they're missing an item. Under an alias, of course.

Link to comment
Share on other sites


Recently Yahoo Mail informed us that due to "security concerns" it was advising us to change our passwords. Today I received the email below..as blatant a phishing scam as you could create. Notice that apart from the ridiculous threat to block my account if I don't click the link in the email, the sender's email address is at the top and it's a hotmail account!! I guess this is related to the "security concerns" that Yahoo were warning us about. Hope no-one here falls for this, and I hope "mmchiuri" takes a long walk on a short pier.:D:D:D

 

 

To
  • ******************@yahoo.com
 

Message body

Dear *****************@yahoo.com,
 
This is a courtesy notice from Admin Team, and it is to inform you that your email account has exceeded it's mail quota on the database server. 
 
Your email account will be blocked from sending and receiving emails if your email account is not verified within 48 hours.
 
Please click on your email below and click Unblock to verify your account.
***************@yahoo.com
 
Thanks,

Yahoo Team

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...