BitTorrent exploits could let rogue websites control your PC
BitTorrent's peer-to-peer app and its lightweight uTorrent counterpart are susceptible to particularly nasty hijacking flaws. Google researcher Tavis Ormandy recently detailed a host of DNS rebinding exploits in Windows versions of the software that lets attackers resolve web domains to the user's computer, essentially giving the intruders the keys to the kingdom. They could execute remote code, download malware to Windows' startup folder (making it launch on the next reboot), grab downloaded files and look at your download history. The flaws touch on all unpatched versions, including uTorrent Web . Thankfully, fixes are either here or around the bend. Although Ormandy was concerned by the lack of communication after reporting the fix in December, BitTorrent engineering VP Dave Rees told Engadget that the flaws in the conventional client have been fixed in beta versions released last week. Those on the stable releases should see it this week. Ormandy was initially conce...