Page Index Toggle Pages: 1 Send TopicPrint
Normal Topic Akamai Security Vulnerabilities (Read 1730 times)
YouHaveBeenWarned
Korthos Resident
*
Offline


I Love Drama!

Posts: 2
Joined: Mar 13th, 2014
Akamai Security Vulnerabilities
Mar 13th, 2014 at 5:20pm
Print Post  
We all know that Akamai netsessions was originally designed to be peer to peer to enable Akamai to offload traffic from their servers.

Peer to peer is notorious for being a significant security vulnerability on any computer on which it is installed. Akamai received significant push back from potential customers, and to placate people nerfed netsessions to run in a non peer mode.

Unfortunately, Akamai did a half ass job on the task, as their heart really wasn't in it. They couldn't even be bothered to craft a separate EULA for the non peer to peer version. As it turns out, they didn't refactor the app to pull out the peer to peer support. Instead, they just used a switch to branch around the security vulnerabilities.

The kicker is, they didn't compile separate executables. Instead, it is just a configuration option, read at start up. Where is it read from? Well, where do you store configuration information on Windows? Yep, right where anyone can easily alter it, and flip on peer to peer mode.

Who would do that? Anyone who can wedge a small piece of executable code on your system, and then need a open conduit, bypassing the firewall (because the firewall gives Akamai full access), to send and receive any data it wants to from your computer.

What bytes do you need to twiddle to make this work? Sorry, I'm not going to tell you that. If you really want to do something nefarious, you are going to have to work out that part for yourselves......
  
Back to top
 
IP Logged
 
rest
One Man Wolfpack
*
Offline



Posts: 7223
Joined: Aug 13th, 2010
Gender: Male
Re: Akamai Security Vulnerabilities
Reply #1 - Mar 13th, 2014 at 5:21pm
Print Post  
This just in: water is wet.

  
Back to top
 
IP Logged
 
Rasczak
Stormreaver Piker
*
Offline


Instant Human...Just Add
Coffee

Posts: 668
Location: South, Way South
Joined: Oct 4th, 2010
Gender: Male
Re: Akamai Security Vulnerabilities
Reply #2 - Mar 14th, 2014 at 5:26am
Print Post  
People can break into my computer and steal my stuff?
  
Back to top
 
IP Logged
 
Illiterate
Titan Demolisher
****
Offline


Yataaaa

Posts: 359
Location: France
Joined: Jul 31st, 2010
Gender: Male
Re: Akamai Security Vulnerabilities
Reply #3 - Mar 14th, 2014 at 7:12am
Print Post  
If you let something modify your registry, then it can probably do many other things. No need to enable p2p on akamai when you can already do whatever you want.
  
Back to top
 
IP Logged
 
jaggedmonk
Waterworks Kobold
**
Offline


I Love Drama!

Posts: 126
Joined: Mar 12th, 2014
Re: Akamai Security Vulnerabilities
Reply #4 - Mar 14th, 2014 at 12:53pm
Print Post  
I took the other path and just use pyLOTRO so I could uninstall Akamai.  Its not needed in any way for DDO to update and run.  Some people on the other forum have posted problems with getting rid of Akamai, but I didn't have any such problems and after a couple reboots still havn't seen Akamai reinstall or running anywhere and couldn't find any of its folders on my drive.
  
Back to top
 
IP Logged
 
mudfud
Shroud Slacker
***
Offline


I Love Drama!

Posts: 1123
Joined: Nov 17th, 2011
Re: Akamai Security Vulnerabilities
Reply #5 - Mar 14th, 2014 at 1:13pm
Print Post  
Well none of this can be real, turbine says it's not possible.

Well except rest comment. We all know water is wet.
  
Back to top
 
IP Logged
 
Luxgolg
Shroud Slacker
***
Offline


So many bugs

Posts: 1221
Location: Over there
Joined: Oct 2nd, 2012
Gender: Male
Re: Akamai Security Vulnerabilities
Reply #6 - Mar 14th, 2014 at 2:05pm
Print Post  
This sounds like Microsoft Windows
  

Frog on all servers, but Cannith is home.
Back to top
 
IP Logged
 
Realism51
Korthos Resident
*
Offline


I Love Drama!

Posts: 74
Joined: Mar 14th, 2014
Re: Akamai Security Vulnerabilities
Reply #7 - Mar 14th, 2014 at 9:05pm
Print Post  
Akamai is the pipeline that the NSA used to exploit numbers and information from the German gov a while back. Surprised that a lot of malware written to work on Akamai structures only  effects chrome browser. Gives me more of a reason to dump the dang thing. Now if only TOR was faster at connections.
  
Back to top
 
IP Logged
 
Page Index Toggle Pages: 1
Send TopicPrint