Clients such as µTorrent and qBittorrent have WebUI enabled by default. This script crawls through the IPs and Detects if a client has a WebUI open or not which is accessible over the internet.
A malicious actor can brute force the WebUI Login without any limitations or Restrictions and Download malware on the target system.
- Add a torrent for downloading.
- Click The Active Torrent File
- From the available options such as General, Trackers, and Peers. Select "Peer"
- Press CTRL+A to select all the available peers in that list
- Right Click and Select "Copy IP:Port"
- Paste that into the
ips.txt
file - run
npm install
- run
node OpenIP.js
- Go to Preferences > WebUI and Enable WebUI
- Enter username and Password under the authentication Tab
- Fill in the
config.json
file - Run the
OpenIP.js
- Choose Option 2
- Auto Fetch from qBittorrent Client API
- Auto Detect Active Torrents and Fetch Info Hash
- Live Listening to the Peer List
- Integrate Patator and Hashmob Data
- Considering adding a Star