This seems like a major security issue, since some browsers (Chrome, at the very least, and probably others) can be set to automatically open a torrent client when links to .torrent files are clicked. Is it possible someone hijacked this IP? Edit: 1. Seems the IP belongs to a CDN (edgecast).
In what scenario is opening a torrent client a major security issue?
Twitter Tweet Button URL randomly resolves to a .torrent file
21–30 of 47 posts
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#22Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#23Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#24platform.twitter.com is hosted at Amazon S3 (via an additional CDN). All S3 files by default can be distributed with torrent, if the URL is appended with ?torrent S3 servers will act as a tracker and seeds.
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#25Earlier quoted context omitted.
In what scenario is opening a torrent client a major security issue?
It implies downloading a file onto the users machine without user consent which is, in itself, a problem. More importantly, an attacker could craft a torrent file that exploits vulnerabilities in the torrent client. If, just by visiting a site, an attacker can download an arbitrary file onto your machine and then have it automatically opened in a known program you're in big trouble.
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#26platform.twitter.com is hosted at Amazon S3 (via an additional CDN). All S3 files by default can be distributed with torrent, if the URL is appended with ?torrent S3 servers will act as a tracker and seeds.
Relevent FAQ from Amazon S3 FAQ page : http://aws.amazon.com/s3/faqs/#What_is_the_BitTorrent_TM_pro...
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#27Again: this is just my guess.
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#28Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#29Earlier quoted context omitted.
In what scenario is opening a torrent client a major security issue?
It implies downloading a file onto the users machine without user consent which is, in itself, a problem. More importantly, an attacker could craft a torrent file that exploits vulnerabilities in the torrent client. If, just by visiting a site, an attacker can download an arbitrary file onto your machine and then have it automatically opened in a known program you're in big trouble.
If users have their browsers configured to automatically start the download of any .torrent files without confirmation, twitter giving bogus .torrent is no more dangerous than $malware_site linking a .torrent. So that's not a security issue on twitter's site.
And anyway, I still fail to see how downloading a file (through bittorent or otherwise) constitutes a security breach on its own. Unless of course the bittorent client auto-executes binaries when it's done downloading, but that's just silly (and still nothing to do with twitter's security policy).
Re: Twitter Tweet Button URL randomly resolves to a .torrent file
#30Earlier quoted context omitted.
It implies downloading a file onto the users machine without user consent which is, in itself, a problem. More importantly, an attacker could craft a torrent file that exploits vulnerabilities in the torrent client. If, just by visiting a site, an attacker can download an arbitrary file onto your machine and then have it automatically opened in a known program you're in big trouble.
I don't understand, if the user is prompted to download the file using an external application it's no different than a direct download. If users have their browsers configured to automatically start the download of any .torrent files without confirmation, twitter giving bogus .torrent is no more dangerous than $malware_site linking a .torrent. So that's not a security issue on twitter's site. And anyway, I still fai…
1. User configures browser to automatically start torrent downloads when a ".torrent" link is clicked
2. User clicks twitt button which leads to a torrent file
3. The file is downloaded and opened in a torrent client
At this point, one could imagine a specifically crafted torrent file which exploits some vulnerability of the torrent client to gain (say) arbitrary code execution and now the user is, to use a mild term, screwed.
This attack could be used by any malicious site, really, but it's easier to get people to click a twitt button rather than some link on some site and besides, by preforming the attack this way the attacker would infect a sizable chunk of all internet sites (any site that uses the twitt button).