Jump to content

Some more fake µTorrent clients?


taulin

Recommended Posts

ive been noticing some fake or pretend µtorrent clients on my tracker recently, information is as follows

fakeutorrentgn4.png

this is how it looks in the peers list, they all seem to be coming from israel and note the given version, always something over 3000 given

the announce string looks like this:

/tracker/announce.php?info_hash=%88%DBBbC%3B%AA%28%85%EF%90jd%07%29gB%F4%C5%16&peer_id=%B5Torrent%2F3045%20%20%20%20%20%20%20&port=2048&uploaded=16220160&downloaded=8110080&left=94668691&compact=1&numwant=2000

note the request amount, 2000 peers, the port is always 2048 as well. the peer id given equates to "µTorrent/3045 " as well (effectively malformed peer ids), only recently have these clients actually started downloading/uploading which leads me to think they are mainly just peer harvesting

Link to comment
Share on other sites

  • 2 weeks later...

Dch48

Does not really belong to this topic since this client is successfully detected as FAKE.

132.239.17.225 resolves to planetlab2.ucsd.edu

PlanetLab guys are eavesdropping on pretty every popular torrent at least since the beginning of 2008. Purposes unknown. Those planetlab clients do not even try to download or upload anything.

Link to comment
Share on other sites

PlanetLab themselves are not spies. They offer a grid for other applications to run, mostly from the research sector. coblitz.codeen.org, coralcdn.org also run on PlanetLab -- and I would assume countless other projects. One of those projects is eavesdropping on BitTorrent.

For what kind of research, I do not know. I would give PlanetLab themselves the benefit of the doubt though -- and you could try asking them about it.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...