14-Year Vulnerability in qBittorrent Leaves Millions Exposed to RCE Attacks (securityonline.info)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 31 Oct 16:38
https://sh.itjust.works/post/27422162

#cybersecurity

threaded - newest

n3m37h@sh.itjust.works on 31 Oct 17:05 next collapse

Will be updating tonight, cheers

ThePantser@lemmy.world on 31 Oct 17:18 next collapse

I switched back to nzb full time last week. Don’t need to run a VPN and it is more stable. It’s still cheaper than streaming with 2 paid indexers and 2 paid servers.

kitnaht@lemmy.world on 31 Oct 18:05 next collapse

Paid indexers? Isn’t everything on the DHT anyhow? And a VPN is only $2/mo.

devfuuu@lemmy.world on 31 Oct 21:37 collapse

not including the full speed and no need to think about seeds. I miss using usenet, should go back to it.

Robust_Mirror@aussie.zone on 01 Nov 05:28 collapse

I do stremio + torrentio addon + real Debrid.

Interface and features on par with any modern streaming service (continue watching, new episode alerts, library, categories, search etc), every show and movie all in one app, full speed, no need for VPN or worry about seeds (I’ve found shows with 0 seeds that work because it was cached on real Debrid) for $3/month.

Also supports a ton of devices/TV’s. Dead simple to use once it’s set-up, my parents and in laws both use it with no issue on Chromecast with Google TV after I set it up for them.

Oh and if you don’t want to pay you can forget real Debrid and it’ll still stream torrents at the cost of slightly worse loading times (but entirely usable, I did it for 3 years) but if you live somewhere that you feel the need to use a VPN for that, unless you also use the VPN for something else putting that money into real Debrid instead is worth it.

doc@fedia.io on 31 Oct 18:00 next collapse

Upgrade to 5.0.1 to patch.

ryannathans@aussie.zone on 31 Oct 21:59 next collapse

Bit overblown given you need to be on windows, actively MITM attacked and manually updating Python via qbittorrent

JoeKrogan@lemmy.world on 31 Oct 22:00 next collapse

Thanks for posting OP 👍

higgsboson@dubvee.org on 31 Oct 23:33 next collapse

Nice… I was putting off 5.0.0 because I never install major releases until there’s been a patch. I worked in software too long to trust.

deltapi@lemmy.world on 01 Nov 05:55 collapse

Wow this sure is overstated. The biggest actual risk here is ISPs doing deep inspection and getting data from private trackers.

Not nothing, but the ‘RCE’ they are claiming relies on an edge case and a lot of manual work on the part of a potential attacker who would also need to be able to intercept your traffic on the off chance you run qbit on windows and use qbit to install python.

This, to me, is a big nothing burger.