• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Here’s How to Fix * TorrentFreak

2 September 2023
in Mining
Reading Time: 5 mins read
A A
0
Here’s How to Fix * TorrentFreak
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

While BitTorrent client functionality hasn’t fundamentally changed over the past 20 years, developers of leading clients haven’t let their software stagnate.

A good example is the excellent qBittorrent, a feature-rich open source client which still receives regular updates. In common with similar clients, qBittorent can be found on GitHub along with its source and installation instructions.

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Elsewhere on the same platform, users were recently trying to work out how a standard qBittorrent install suddenly led to the appearance of unwanted cryptocurrency mining software on the same machine.

[crypto-donation-box]

Proxmox and LXC

For those unfamiliar with Proxmox VE, it’s an environment for virtual machines that once tried becomes very useful, extremely quickly. It’s also free for mere mortals and in most circumstances, very easy to install and get up and running.

tteck-proxmoxWith help from various Proxmox ‘helper scripts’ offered by tteck on GitHub (small sample to the right), even beginners can install any of dozens of available software packages in a matter of seconds using LXC containers.

Even if none of that makes sense, it doesn’t matter. Those who want qBittorrent installed, for example, can copy and paste a single line of text into Proxmox…and that’s it. Given that the whole process is almost always flawless, user issues are very rare, so to hear of a possible malware infection came as a real shock recently

Cryptominer Discovery

In summary, a Proxmox user deployed a tteck script to install qBittorrent and then a month later found his machine being worked hard by cryptomining software known as xmrig. While he investigated the problem, tteck removed the qBittorrent LXC script as a basic precaution, but it soon became clear that neither Proxmox or tteck’s script had anything to do with the problem.

The unwelcome software was indeed installed maliciously, but due to a series of avoidable events, rather than a genius hack.

When a qBittorrent installation like this completes and the software is launched, access to qBittorent takes place through a web interface accessible from most web browsers. By default, qBittorrent uses port 8080 and since many users like to access their torrent clients from remote networks, qBittorrent uses UPnP (Universal Plug and Play) to automate port forwarding, thereby exposing the web interface to the internet.

qbit-webui

Having this working in record time is all very nice, but that doesn’t mean it’s safe. To ensure that only the operator of the client can access the web interface, qBittorrent allows the user to configure a username and a password for authentication purposes.

This generally means that random passers-by will need to possess these credentials before being able to do damage. In this case, the default admin username and password were not changed and that allowed an attacker to easily access the web interface.

Attacker Told qBittorrent to Run an External Program

To allow users to automate various tasks related to downloading and organizing their files, qBittorrent has a feature that can automatically run an external program when a torrent is added and/or when a torrent is finished.

The options here are limited only by the imagination and skill of the user but unfortunately the same applies to any attacker with access to the client’s web interface.

qbitt-external

In this case the attacker told the qBittorrent client to run a basic script on completion of a torrent. The script accessed the domain http://cdnsrv.in from where it downloaded a file called update.sh and then ran it. The consequences of that are explained in detail by tteck, but the main points are a) unauthorized cryptomining on the host machine and b) the attacker maintaining root access via SSH key authentication.

Easily Avoided

The default admin username for qBittorrent is ‘admin’ while the default password is ‘adminadmin’. Had these common-knowledge defaults been changed following install, the attacker would still have found the web interface but would’ve had no useful credentials for conventional access.

More fundamentally, possession of the correct credentials would’ve had limited value if the qBittorrent client hadn’t used UPnP to expose the web interface in the first place. Taking another step back, if UPnP hadn’t been enabled in the user’s router, qBittorrent would’ve had no access to UPnP, and wouldn’t have been able to forward ports or expose the interface to the internet.

In summary: disable UPnP in the router and only enable it once its function is fully understood and when absolutely necessary. Never leave default passwords unchanged, and if something doesn’t need to be exposed to the internet, don’t expose it unnecessarily.

Cryptohopper
ADVERTISEMENT

Finally, it’s worth mentioning that tteck‘s response, to a problem that had nothing to do with Proxmox or his scripts, has been first class. Anyone installing the qBittorrent LXC from here will find the default admin password changed and UPnP disabled automatically.

Any time saved can be spent on automated installs of Plex, Tautulli, Emby, Jellyfin, Jellyseerr, Overseerr, Navidrome, Bazarr, Lidarr, Prowlarr, Radarr, Readarr, Sonarr, Tdarr, Whisparr, and many, many more.

Proxmox: An Open Source Type 1 Hypervisorproxmox-ss

Source link

Tags: FixHeresTorrentFreak
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Why VC Spectra Leaves Stellar & Chainlink in the Dust

Next Post

Carbonbase, HBAR Foundation and ImpactX Launch Asia’s First Digital Carbon Registry

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Carbonbase, HBAR Foundation and ImpactX Launch Asia’s First Digital Carbon Registry

Carbonbase, HBAR Foundation and ImpactX Launch Asia's First Digital Carbon Registry

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
ADA Price Holds Key Support Despite 0M Whale Sell-Off

ADA Price Holds Key Support Despite $140M Whale Sell-Off

11 September 2025
Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance

Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance

11 September 2025
BNB Hits New All-Time High Above 7 Amid Strong Futures Activity – Coinspeaker

BNB Hits New All-Time High Above $907 Amid Strong Futures Activity – Coinspeaker

11 September 2025
CryptoQuant Predicts BNB To Hit ,000

CryptoQuant Predicts BNB To Hit $1,000

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • ADA Price Holds Key Support Despite $140M Whale Sell-Off
  • Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance
  • BNB Hits New All-Time High Above $907 Amid Strong Futures Activity – Coinspeaker
  • CryptoQuant Predicts BNB To Hit $1,000
  • Morning Minute: Solana's New Path to ATH – Yahoo Finance

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 114,011.00
  • ethereumEthereum (ETH) $ 4,400.88
  • xrpXRP (XRP) $ 2.99
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 897.38
  • solanaSolana (SOL) $ 226.14
  • usd-coinUSDC (USDC) $ 0.999809
  • staked-etherLido Staked Ether (STETH) $ 4,393.60
  • dogecoinDogecoin (DOGE) $ 0.248160
  • tronTRON (TRX) $ 0.344742
  • cardanoCardano (ADA) $ 0.874234
  • wrapped-stethWrapped stETH (WSTETH) $ 5,336.36
  • chainlinkChainlink (LINK) $ 23.56
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,740.77
  • hyperliquidHyperliquid (HYPE) $ 54.13
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,832.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.59
  • stellarStellar (XLM) $ 0.384945
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.992931
  • avalanche-2Avalanche (AVAX) $ 28.80
  • wrapped-eethWrapped eETH (WEETH) $ 4,730.03
  • bitcoin-cashBitcoin Cash (BCH) $ 591.60
  • wethWETH (WETH) $ 4,402.13
  • hedera-hashgraphHedera (HBAR) $ 0.234417
  • leo-tokenLEO Token (LEO) $ 9.57
  • litecoinLitecoin (LTC) $ 114.44
  • crypto-com-chainCronos (CRO) $ 0.256323
  • the-open-networkToncoin (TON) $ 3.16
  • usdsUSDS (USDS) $ 0.999696
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999652
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 113,965.00
  • polkadotPolkadot (DOT) $ 4.16
  • whitebitWhiteBIT Coin (WBT) $ 43.27
  • uniswapUniswap (UNI) $ 9.78
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199781
  • mantleMantle (MNT) $ 1.62
  • ethenaEthena (ENA) $ 0.751277
  • moneroMonero (XMR) $ 271.71
  • aaveAave (AAVE) $ 302.06
  • bitget-tokenBitget Token (BGB) $ 4.89
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000010
  • okbOKB (OKB) $ 193.62
  • bittensorBittensor (TAO) $ 355.09
  • nearNEAR Protocol (NEAR) $ 2.69
  • jito-staked-solJito Staked SOL (JITOSOL) $ 278.27
  • memecoreMemeCore (M) $ 1.97