Bitcoin Forum

Other => Off-topic => Topic started by: fbueller on May 30, 2015, 11:11:53 AM



Title: Uninstall Hola - you'll see why.
Post by: fbueller on May 30, 2015, 11:11:53 AM
Looks like Hola - the free VPN service for unblocking the likes of Netflix, exposes an API on your localhost. This can be access by JS, and it seems the API lets anyone who knows this read arbitrary files from your filesystem (oh noez, our wallets), run completely arbitrary code on your machine, and to boot, they have a unique ID for each Hola installation meaning you can be tracked across the net.

They also have some shocking practices as to how they monetize this huge VPN - the lease access to a 40 million machine botnet.

Details here: http://adios-hola.org


Title: Re: Uninstall Hola - you'll see why.
Post by: Sutters Mill on May 30, 2015, 01:32:40 PM
Saw it on RT today http://rt.com/usa/263261-adios-hola-vulnerability-blake/

I think people should be careful with what proxy they use. Many proxy services keep user data which could be leaked or even given to authorities if they so requested it.


Title: Re: Uninstall Hola - you'll see why.
Post by: kolloh on May 30, 2015, 04:18:11 PM
Yep, pretty bad that using this software turned your machine into part of a botnet.