Author Topic: Winamp 3 & 5 exploit  (Read 1064 times)

0 Members and 1 Guest are viewing this topic.

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Winamp 3 & 5 exploit
http://www.theregister.co.uk/2004/08/26/winamp_brown_alert/

Be careful with those new skins I guess. This one's in the wild.
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline Blue Lion

  • Star Shatterer
  • 210
I still use Winamp 2

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
The danger of the exploit is that you can be exploited by clicking a link that's to a .jpg or something like that. The trick is done by using a php script that's camouflaged as a .jpg or something, you click and it leads you to a xml winamp skin file that can run code.

So the only way to prevent this is to keep your browsers from automatically opening winamp skins and don't click on suspicious links.
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 

Offline ionia23

  • 26
  • "YES, I did finally see 'The Matrix' 12 years late
It amazes me.  All this **** because some dickhead wants to sell me Viagra.

Spamming and all it's variants should be an unappealable capital offense.
"Why does it want me to say my name?"

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
I read a story once about how anti-spam people managed to get hold of a spammers home address.

What they did is sign him up for every piece of junk snail mail they could. Apparently this guy recieved kilograms of junk snail mail a day.

I just laughed myself silly at the sheer poetic justice :D
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline ionia23

  • 26
  • "YES, I did finally see 'The Matrix' 12 years late
Quote
Originally posted by karajorma
I read a story once about how anti-spam people managed to get hold of a spammers home address.

What they did is sign him up for every piece of junk snail mail they could. Apparently this guy recieved kilograms of junk snail mail a day.

I just laughed myself silly at the sheer poetic justice :D


I did something like that to a spammer out of Canada once who was selling bulk-email services (spam for spammers).  Call the "Staffed 24 hours a day" customer service number and filled up his voice mail.  The message changed when it was full giving me his real name.


Didn't take long to get his home address. and social security number, and criminal record.

Amazing what you can find out about a person.  Didn't do anything, just posted his home number in bestiality classified ads with a request to call between 1 and 5 a.m.

And sent the Mormons to his house a lot.

if i were truly creative, and willing to do the homework, turning off his utilities would have been a laugh riot.  Of course, his number is disconnected now :).
"Why does it want me to say my name?"

  
Quote
Security firm Secunia describes the flaw as "extremely critical". Pending the availability of a fix, Secunia advises WinAmp users to use an alternative product


Notice how Secunia made an extra effort not to advise people to use another browser.
Can the reason that we fear the unknown be that we know ourselves too well?       -The Outer Limits

<*)}}}><  HAPPY FISHIE!!

 

Offline Flipside

  • əp!sd!l£
  • 212
'The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction.'

True, but they drop the big hint ;)

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
It's possible to exploit this with other browsers anyway. If you have wsz files associated with automatic winamp opening on Mozilla, it'll work just the same.

Another cause of the problem is people's tendency to run on admin accounts, so an exploit like this can kill everything. That's a Windows + various other programs design flaw.
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 
Quote
Originally posted by Kamikaze
Another cause of the problem is people's tendency to run on admin accounts, so an exploit like this can kill everything. That's a Windows + various other programs design flaw.


True, but the only way around that would be to terminalize Windows, thus destroying any flexability gained with a PC.  And with the rise of .Net, the day that we all log on to our Windows account from a broadband monitor is getting closer.
Can the reason that we fear the unknown be that we know ourselves too well?       -The Outer Limits

<*)}}}><  HAPPY FISHIE!!