7 ms·
Twitter Tweet Button URL randomly resolves to a .torrent file
- psz 13y agoplatform.twitter.com is hosted at Amazon S3 (via an additional CDN). All S3 files by default can be distributed with torrent, if the URL is appended with ?torrent S3 servers will act as a tracker and seeds.
- gingerjoos 13y agoRelevent FAQ from Amazon S3 FAQ page : http://aws.amazon.com/s3/faqs/#What_is_the_BitTorrent_TM_protocol_and_how_do_I_use_it_with_Amazon_S3 http://aws.amazon.com/s3/faqs/#What_is_the_BitTorrent_TM_pro...
- jonaldomo 13y agoPlease upvote this to get it to the top.
- untog 13y agoWow, that's amazing. I had no idea Amazon offered that. I also have no idea when I'll ever use it, but still. Damn cool.
- toomuchtodo 13y agoNot only can S3 serve the file as a torrent, if you provide it as a torrent link and have disabled read access to the file, S3 will still serve as the tracker as long as other peers in the swarm have a full copy of the file to serve.
- deleted 13y ago[deleted]
- vdaniuk 13y agoThat is a cool feature, actually.
- MichaelAza 13y agoThis seems like a major security issue, since some browsers (Chrome, at the very least, and probably others) can be set to automatically open a torrent client when links to .torrent files are clicked. Is it possible someone hijacked this IP? Edit: 1. Seems the IP belongs to a CDN (edgecast).
- simias 13y agoIn what scenario is opening a torrent client a major security issue?
- MichaelAza 13y agoIt implies downloading a file onto the users machine without user consent which is, in itself, a problem. More importantly, an attacker could craft a torrent file that exploits vulnerabilities in the torrent client. If, just by visiting a site, an attacker can download an arbitrary file onto your machine and then have it automatically opened in a known program you're in big trouble.
- ryoshu 13y agoThe torrent file it downloads is a binary, so it's most likely an auto-open exploit.
- simias 13y agoI don't understand, if the user is prompted to download the file using an external application it's no different than a direct download. If users have their browsers configured to automatically start the download of any .torrent files without confirmation, twitter giving bogus .torrent is no more dangerous than $malware_site linking a .torrent. So that's not a security issue on twitter's site. And anyway, I still fail to see how downloading a file (through bittorent or otherwise) constitutes a security breach on its own. Unless of course the bittorent client auto-executes binaries when it's done downloading, but that's just silly (and still nothing to do with twitter's security policy).
- th0br0 13y agoCan not reproduce from Germany (manually added the hosts entry)
- toretore 13y agoSo that's what that was. Happened to me yesterday.
- saze 13y agoreproduced from France a couple times yesterday
- deleted 13y ago[deleted]
- program 13y agoReproduced from Italy just a couple of minutes ago.
- thehodge 13y agoDon't twitter use torrents to deploy across multiple servers?
- glennos 13y agoThey do (or at least used to). This came to mind for me too. The platform they developed is called Murder: https://blog.twitter.com/2010/murder-fast-datacenter-code-deploys-using-bittorrent https://blog.twitter.com/2010/murder-fast-datacenter-code-de...
- dud3z 13y agoYou can reproduce it by pretending that the IP is "68.232.35.139" by modifying your own /etc/hosts file, not funny indeed.
- bagosm 13y agoReproduced a couple minutes ago in Greece. Oh the bug? I didn't check it out yet.
- laveur 13y agoI had this happen when I loaded an article from TechCrunch just a couple of minutes ago. USA here.
- Uchikoma 13y agoHappens to me today on Spiegel.de - one of the largest German sites (news site)
- agumonkey 13y agopeople are digging for http responses https://gist.github.com/gregclermont/6669056 https://gist.github.com/gregclermont/6669056
- deleted 13y ago[deleted]
- blahpro 13y agoMy guess: many CDNs allow you to exclude the querystring from the cache key, so it's possible that one person requested the URL with ?torrent in the querystring (which causes S3 to serve a .torrent response) and that the request hit a cold cache. The response with type application/x-bittorrent was then cached under the querystring-less cache key, causing it to be served to anyone else hitting that edge node with the path /widgets/tweet_button.html. Again: this is just my guess.
- gazarsgo 13y agoI thought Twitter was all private DC, did platform previously point to S3?
- blahpro 13y agoplatform.twitter.com is currently CNAMEd to EdgeCast CDN. It looks like the CDN is sitting in front of Amazon S3; http://platform.twitter.com/blahblahblah http://platform.twitter.com/blahblahblah gives an S3-like 403 response.
- StavrosK 13y agoThis is my exact guess as well. I would be surprised if it turned out to be something else.
- gregclermont 13y agoThis visualization of the domain name resolution for platform.twitter.com might help to understand the issue. I don't know how to interpret it however. http://dnsviz.net/d/platform.twitter.com/dnssec/ http://dnsviz.net/d/platform.twitter.com/dnssec/
- gregparadee 13y agoJust happened to me on Businessinsider.
- samspenc 13y agoHappened to me on a tech news website earlier today (forget which one exactly)
- Amadou 13y agoThis is what TorrentFreak had to say about it: http://torrentfreak.com/twitter-bug-requires-users-to-torrent-its-tweet-button-130923/ http://torrentfreak.com/twitter-bug-requires-users-to-torren... TL;DR is Twitter uses bittorrent internally, this is probably just an error in letting an internal configuration leak to the outside world.
- sdfjkl 13y agoNow you just need browser support for downloading HTTP bodies via BitTorrent. Not actually a bad idea for sufficiently large ones :)
- jgv 13y agoJust got this visiting this article page on TechCrunch => http://techcrunch.com/2013/09/23/facetime-audio-is-apples-biggest-little-feature-addition-in-ios-7/ http://techcrunch.com/2013/09/23/facetime-audio-is-apples-bi... Chrome automatically downloaded it => http://cl.ly/image/2u3R2m3j3j1E http://cl.ly/image/2u3R2m3j3j1E
- mathattack 13y agoSame. Chrome automatically downloaded it for me too. Twice.
- ahamdy 13y agoreproduced in Egypt, this thing is all over the place
- harvestmoon 13y agoI also have this bug on BusinessInsider and other sites. Does not look good. Surprised there isn't more coverage of this.