Later archive addition
uTorrent Web: DNS rebinding and remote code execution
Project Zero documents multiple uTorrent Web and Classic JSON-RPC flaws reachable from any website. DNS rebinding and exposed authentication material let a malicious origin control localhost RPC services, read downloads and settings, change file destinations, and in the Web client write an executable into a startup location for code execution.
Record
- Researcher
- taviso
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of taviso, first published at the original source. Preserved copies are kept so the citation survives its host.