Torrent clients and BitTorrent Sync can be used for DRDoS attacks
Popular torrent clients and BitTorrent Sync can be used to launch a DRDoS attack. An attacker can use different protocols in torrent clients and the Sync application to increase and target Internet traffic.
Researchers from City University London state that BitTorrent’s Micro Transport Protocol, Distributed Hash Table, Message Stream Encryption and BitTorrent Sync can all be used to amplify and direct traffic through peers. Thus, a distributed reflective denial of service attack, or DRDoS, can be performed. An attacker can use this technique to increase his bandwidth by a factor of 50 to 120. The exploit is quite easy as the protocols do not withstand ip . very well
spoofing. The researchers say there are “millions of potential amplifiers” online.
The Torrent clients uTorrent, Mainline and Vuze are said to be the most vulnerable. The researchers have already informed several involved parties. For example, BitTorrent has already eliminated the vulnerability in a beta version of its official client, but other parties such as Vuze and uTorrent have not yet patched their client, Torrentfreak writes.