https://github.com/hotio/qbittorrent/pkgs/container/qbittorr...
Based on https://github.com/hotio/base
Should be tracable via GitHub Actions logs for anyone signed on - if it is indeed supply-chain and not a qbittorrent exploit or something else.
11–20 of 53 posts
https://github.com/hotio/qbittorrent/pkgs/container/qbittorr...
Based on https://github.com/hotio/base
Should be tracable via GitHub Actions logs for anyone signed on - if it is indeed supply-chain and not a qbittorrent exploit or something else.
Ps. I do have such binary on my machine as well, ps -ef | grep netservlet root 3708105 3665360 0 08:06 pts/2 00:00:00 grep netservlet
If the web UI is exposed that could explain how it got infected: https://torrentfreak.com/qbittorrent-web-ui-exploited-to-min...
You all really think that hotio snuck a crypto miner in somehow with all clearly open source code - and not a single person but OP noticed for years?
Omg! I am one of the user! Good find. I maily use for built-in VPN facility, gluetun do not cut out. But now time to re-think. I thought my 2000+ linux iso was causing medium CPU usage. But still lack of GPU, on my unraid server with 50+ docker containers running 24/7 CPU load is 2.31 2.04 2.00 so I wonder mining ever triggered? Ps. I do have such binary on my machine as well, ps -ef | grep netservlet root 3708105 36…
Code and CI is all open source.
hotio maintains a lot of Docker images. I suspect that if this is the case, there are a lot of people who would be affected https://hotio.dev/containers/base/
Finally made an account on hackernews for this after years of reading. I just checked my Unraid server, I'm running five docker containers from Hotio - Prowlarr, Sonarr, Radarr, Overseerr, and Tautulli. If I remember correctly, I originally chose Hotio's configs due to there being a few extra settings missing from the standard images in the Unraid store. This was all to avoid learning anything about docker at the tim…
OP's system got compromised.
According to some messages on Hotio’s Discord server from 2023-11-25, qBitTorrent moved from fixed admin credentials to randomized at initialization. I think MrHotio’s message about that crypto miner was likely a joke about people installing the older vulnerable version and the efficiency of unauthorized people installing xrig on servers with default credentials.
If author was pinned to an old version of the docker image and their server had internet-visible IP, they probably got their server infected because of weak security defaults in the app installed on the image.
Edit: Scion9066’s comment shows that dBitTorrent’s previous release version patches multiple security bugs, so vulnerabilities might apply to all versions older than about 1 week, not my guess of 2 years.
hotio maintains a lot of Docker images. I suspect that if this is the case, there are a lot of people who would be affected https://hotio.dev/containers/base/
His system was compromised - hotio's containers are all clean
If the web UI is exposed that could explain how it got infected: https://torrentfreak.com/qbittorrent-web-ui-exploited-to-min...
In my case, web UI was behind qbittorrent auth + authelia, haven't seen suspected logs that would trace it back to that, really interesting though!
Perhaps take a class in sarcasm?