Web Hack List

Other nomination

CSRFing the uTorrent plugin

Chained CSRFs against uTorrent's local Web UI: setsetting points 'move completed downloads to' at the All Users Startup folder, then add-url makes uTorrent fetch an attacker torrent, so the payload lands where Windows runs it at boot. Settings are stored unescaped too, giving persistent XSS on getsettings; from localhost it runs in IE's Local Intranet zone, where WScript.Shell runs the file.

Record

Researcher
Rob

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rob, first published at the original source. Preserved copies are kept so the citation survives its host.