Torrent Invites! Buy, Trade, Sell Or Find Free Invites, For EVERY Private Tracker! HDBits.org, BTN, PTP, MTV, Empornium, Orpheus, Bibliotik, RED, IPT, TL, PHD etc!



Results 1 to 1 of 1
Like Tree2Likes
  • 2 Post By jimmy7

Thread: MetalKettle Addon Repository Vulnerable After GitHub ‘Takeover’

  1. #1
    Donor
    jimmy7's Avatar
    Reputation Points
    855498
    Reputation Power
    100
    Join Date
    Jan 2016
    Posts
    32,787
    Time Online
    640 d 20 h 33 m
    Avg. Time Online
    5 h 6 m
    Mentioned
    3337 Post(s)
    Quoted
    917 Post(s)
    Liked
    34147 times
    Feedbacks
    115 (100%)

    MetalKettle Addon Repository Vulnerable After GitHub ‘Takeover’

    A popular third-party Kodi repository has become vulnerable after an outsider re-registered the GitHub account of its developer, who previously deleted his accounts. Former Kodi-addon developer MetalKettle urges people to delete his repository, stating that it's no longer safe.

    A few weeks ago MetalKettle, one of the most famous Kodi addon developers of recent times, decided to call it quits.

    Worried about potential legal risks, he saw no other option than to halt all development of third-party Kodi addons.

    Soon after this announcement, the developer proceeded to remove the GitHub account which was used to distribute his addons. However, he didn’t realize that this might not have been the best decision.

    As it turns out, GitHub allows outsiders to re-register names of deleted accounts. While this might not be a problem in most cases, it can be disastrous when the accounts are connected to Kodi add-ons that are constantly pinging for new updates.

    In essence, it means that the person who registered the Github account can load content onto the boxes of people who still have the MetalKettle repo installed. Quite a dangerous prospect, something MetalKettle realizes as well.

    “Someone has re-registered metalkettle on github. So in theory could pollute any devices with the repo still installed,” he warned on Twitter.

    “Warning : if any users have a metalkettle repo installed on their systems or within a build – please delete ASAP,” he added.

    MetalKettle warning


    https://torrentfreak.com/images/MKwarning.png

    It’s not clear what the intentions of the new MetalKettle user are on GitHub, if he or she has any at all. But, people should be very cautious and probably remove it from their systems.

    The real MetalKettle, meanwhile, alerted TVAddons to the situation and they have placed the repository on their Indigo blacklist of banned software. This effectively disables the repository on devices with Indigo installed.

    GitHub on their turn may want to reconsider their removal policy. Perhaps it’s smarter to not make old usernames available for registration, at least not for a while, as it’s clearly a vulnerability.

    This is also shown by another Kodi repo controversy that appeared earlier today. An old GitHub account that was reportedly deleted earlier, resurfaced today pushing a new version of the Exodus addon.

    According to some sources, the GitHub account is operated by the original Exodus developers and perfectly safe, but others warn that the name was reregistered in bad faith.

    Source: Torrentfreak.com


LinkBacks (?)

  1. 09-15-2017, 09:08 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •