Jump to content

Torrent Site Proxies Rife With Malware Injecting Scripts


NelsonG

Recommended Posts

[img]http://torrentfreak.com/images/warning.png[/img]In many countries including the UK, Italy, Denmark and France, the leading torrent sites are no longer freely accessible.

These court-ordered blockades requested by the music and movie industries are becoming widespread, but so are the tools to circumvent them.

For every domain name blocked, many proxies and mirrors emerge. These sites allow people to access the blocked sites and effectively bypass the restrictions put in place by the court.

Initially, the proxy sites were launched to help users gain access to their favorite torrent sites. However, more recently the demand for circumvention tools is being abused by people who are out to make hard cash.

Instead of offering a simple workaround, many proxies add their own scripts. In some cases these scripts are harmless, but according to security researcher [url="http://gaborszathmari.me/"]Gabor Szathmari[/url] the majority serve questionable content.

Szathmari examined a sample of 6,158 proxy sites and found that over 99% added their own code. Only 21 sites in the sample did not modify the original site.

“99.7% of the tested torrent mirrors are injecting additional JavaScript into the web browsing traffic. A great share of these scripts serve content with malicious intent such as malware and click-fraud,” he notes.

The researcher informs TF that many of the researched proxies are suspicious because they use code that is either obfuscated or has a lot of random redirects. These scripts pretty much all use the proxyads.net domain name.

[img]http://torrentfreak.com/images/number-of-script-injecting-proxies.png[/img]

Taking a closer look at the proxies reveals that several of the ads link to malware. In addition, one of the scripts generated fake views of car racing videos in the background.

The original torrent sites, including The Pirate Bay, KickassTorrents and ExtraTorrent, are aware of the problem and are trying to minimize the damage by blocking suspicious proxies and mirrors.

“It’s a serious issue. We have been fighting against it for a long time,” the ExtraTorrent team informs TF.

“Most unauthorized proxy websites loaded ExtraTorrent in a frame and added malware JavaScript code or replaced ET’s banners with others,” they add.

ExtraTorrent has been able to block several proxies, but they can’t do anything against those that use a cached version of the site. To guide users in the right direction they therefore publish a list of [url="http://i.imgur.com/0DnvXgk.png"]official mirrors[/url] on their site.

Copyright holders often warn that pirate sites may serve malware, but this research suggests that they are only making the problem worse by censoring the original sites.

“I am an advocate for unfiltered Internet, and this example shows that censorship can violate the security of end-users,” Szathmari tells TF.

Of course, some of the original sites may also run dubious ads, but the malicious proxies appear to be much worse and should be avoided.

“I would advise downloaders to always use the original sites or the official proxy sites whenever possible,” the researcher says.

“If the original sites are blocked by the ISP, I would recommend to bypass the filtering with a reputable VPN service that does not modify traffic, or a reputable mirror that does not alter the website in any way.”

Szathmari published the full findings and his research methodology in a recent [url="https://blog.gaborszathmari.me/2015/08/05/malware-injecting-torrent-mirrors/"]blog post[/url].

Source: [url="https://torrentfreak.com"]TorrentFreak[/url], for the latest info on copyright, file-sharing, [url="http://torrentfreak.com/top-popular-torrent-sites-2015-150104/"]torrent sites[/url] and the [url="http://torrentfreak.com/anonymous-vpn-service-provider-review-2015-150228/"]best VPN services[/url].

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=P2cmzQB_V4U:aXU2VPRz3CU:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=P2cmzQB_V4U:aXU2VPRz3CU:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=P2cmzQB_V4U:aXU2VPRz3CU:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/P2cmzQB_V4U[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/P2cmzQB_V4U/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...