Most P2P Sites Vulnerable Due to Inadequate Login Information Encryption
Content Author: Administrator, Update: December-27-24. View Count : 143
A significant number of domestic Peer-to-Peer (P2P) sites are still transmitting login information (ID and password) without encryption, leaving them vulnerable to security risks.
Bang Jun-sik, a 2nd-year student from Yatap High School in Bundang, reported discovering this issue on many P2P sites that can be easily accessed through search engines. He explained that users' login information, such as IDs and passwords, was being transmitted without encryption. “When logging in through public networks like Wi-Fi in public spaces, a simple packet analysis program like Wireshark can allow someone on the same network to easily view a user's ID and password,” he said.
The P2P sites identified with this vulnerability, where user login information is transmitted unencrypted, include 'XDisk', 'FileX', 'FileXX', 'XXXFile', and others.
Bang Jun-sik further mentioned that after attempting to log in with random ID and password combinations on these sites, he was able to confirm that the IDs and passwords were exposed without encryption through packet analysis using Wireshark’s "Follow TCP Stream."
This vulnerability can be resolved by using SSL (Secure Socket Layer) web server certificates. By installing a web server certificate on a vulnerable site, all transmitted information on the website would be securely encrypted with the 'https://' protocol. Therefore, sites with SSL installed can prevent information theft due to sniffing (sniffing) when users input personal information such as login details or registration information in public spaces.
Failing to encrypt login information such as IDs and passwords while transmitting is a violation of Article 28 of the Information and Communications Network Act (failure to implement technical and managerial measures). As a result, offenders may face administrative penalties, including fines of up to 30 million KRW under Article 76, Section 1 of the Act.
Most of the P2P sites investigated in this case exhibit these issues, and since these sites often feature point-based reward systems or cash-like systems, exposing users' IDs and passwords could lead to financial losses, making this a serious problem.
Meanwhile, with the summer holiday season approaching, many users are expected to visit P2P sites to download TV programs, apps, movies, and videos. Attackers may intentionally upload popular programs with malware, creating a vulnerability that could infect users with malicious code. This makes it crucial for users to exercise caution when using such platforms.




