Web Hack List

Collected research

CSRFing the uTorrent plugin

Farfromr00tin: uTorrent Pwn3d

Chained CSRFs against uTorrent's local Web UI: setsetting points 'move completed downloads to' at the All Users Startup folder, then add-url makes uTorrent fetch an attacker torrent, so the payload lands where Windows runs it at boot. Settings are stored unescaped too, giving persistent XSS on getsettings; from localhost it runs in IE's Local Intranet zone, where WScript.Shell runs the file.

Record

Document
Farfromr00tin: uTorrent Pwn3d
Researcher
Rob
Published by
r00tin.blogspot.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rob, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .