P2P-Zone

P2P-Zone (http://www.p2p-zone.com/underground/index.php)
-   Peer to Peer (http://www.p2p-zone.com/underground/forumdisplay.php?f=5)
-   -   Uh Oh - Music File Flaws Could Threaten Traders (http://www.p2p-zone.com/underground/showthread.php?t=14521)

JackSpratts 19-12-02 01:22 AM

Uh Oh - Music File Flaws Could Threaten Traders
 
Robert Lemos

A security firm on Wednesday warned that people using Windows XP or popular music player WinAmp could fall prey to a vulnerability, enabling a modified music file to take control of a person's PC.

Flaws in both pieces of software could introduce malicious MP3 or Windows Media files--which sound identical to unmodified music--into the file-swapping systems, said George Kurtz, CEO of Foundstone.

"These particular vulnerabilities are definitely attack vectors for any people or entity that is looking to go after those that are taking part in file-swapping activities," he said.
http://news.com.com/2100-1001-978403.html

- js.

TankGirl 19-12-02 02:20 AM

Thanks for the heads up, Jack! :tu:

If you use WinAmp, better upgrade it to the latest 3.0C version from their site.

- tg ;)

goldie 19-12-02 08:09 AM

Not only sad but dirty lowdown
 
I love my old, decrepit winamp.

I hate to change it.

:m:

Postscript: i'll have to check back for the lite and standard versions.

theflaco 19-12-02 09:15 AM

Quote:

Originally posted by TankGirl
Thanks for the heads up, Jack! :tu:

If you use WinAmp, better upgrade it to the latest 3.0C version from their site.

- tg ;)

763 thread posters & 26922 viewers canīt be wrong

winamp 3.0 = not sooo good.


theflaco

JackSpratts 19-12-02 09:45 AM

Quote:

Originally posted by theflaco
763 thread posters & 26922 viewers canīt be wrong

winamp 3.0 = not sooo good.


theflaco

Quote:

Originally posted by goldenrod
I love my old, decrepit winamp.

I hate to change it.


me too. :(

- js.

goldie 19-12-02 10:17 AM

just reading through the bitchiing threads and
 
am really surprised at the hostility between the users and the moderators :S

I really think these peeps have a legimate bitch although many of the rants could have been more mildly phrased - the point is, many are very unhappy with 3.0. I can understand why.

Whether the program is free or not, Winamp developers, if wise, should highlight the particulars of legitimate bitches and use it fine tune the program (which i believe they are since a lite and standard version are on the way).

One particular rant comes to mind..........<won't c&p it for obvious reasons> where the ranter says many users thought 3.0 would be an upgraded (improved) version of 2.8. Instead, they get a totally different playa loaded with bloated processes and pretty pictures.

Don't know about most of you guys here - I tried the 3.0 betas and found it intolerable. I didn't bitch about it on the forums but I tell ya, my puter sure heard a wealth of interesting cuss-word combinations.

There's a place for bloat (for instance, sometimes I like to load my MMJB Plus and WMP <X-tra large w/a twist) but for everyday use, nothing beats winamp 2.8 for great on-the-fly listening pleasure.

It's a crying shame that in order to prevent a malicious mp3 file from going Rambo on your box, you have to install 3.0!

Since (according to that board) they're still working with 2.8, they'll come up with a fix for it and not neglect the tried and true.

<sigh>

GR, thanking her lucky stars the moderators here aren't so crabby and hostile.

:tu:

naz 19-12-02 10:22 AM

im keeping my 2.8, if my computer blows up so be it

theknife 19-12-02 11:34 AM

I hated 3.0 and went back and got 2.81...

Malk mentions here that the 3.0 and the latest 2.8 build fixed this hole. Anyone know offhand if 2.81 (d/l'd about 2 months ago) is considered to be a safe version?

ssj4_android 19-12-02 12:33 PM

Don't tell me this is the minibrowser bug from a while ago.

spstn 19-12-02 02:11 PM

I went to the winamp site and found no indication of this problem anywhere.

I downloaded the 2.81 executable anyways, and comparing it to the old one I found out that the new one is 28 bytes bigger, but I'm not sure that's indication of anything. It looks like they are both the same executable.

So, there's anyone that has certified info about all this mess?

Where's the horse's mouth when you need it?



:S:

daddydirt 19-12-02 02:45 PM

from the Breaking News section of the WinAmp forums here

2.81 has been rebuilt with the fix. Download it from http://classic.winamp.com/download/

thinker 19-12-02 03:49 PM

Winamp...PWAHAHA!!!

spstn 20-12-02 12:16 AM

Thanks
 
Tanks to daddydirt for the links.

There are other people there as confused as I was. It looks like Nullsoft is neither happy with this flaw nor with the cold reception of Winamp 3, so is going the hush-hush route about all this.

Oh well, is always hard to compete against MS and Real.

When I reinstall 2.81 I'm gonna be checking the replacement of "in_mp3" that now should show: "Nullsoft MPEG Audio Decoder 2.81b", according to one of the posters in Nullsoft's forum.

Winamp (2.80s) is one of the last few things in the net where simplicity and beauty in execution go hand to hand, so keep your executables secure and handy, because the future looks ugly.



:S:

JackSpratts 20-12-02 12:50 AM

Re: Thanks
 
Quote:

Originally posted by spstn

Winamp (2.80s) is one of the last few things in the net where simplicity and beauty in execution go hand to hand, :S:

that's so true spstn.

- js.


All times are GMT -6. The time now is 11:16 AM.

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Đ www.p2p-zone.com - Napsterites - 2000 - 2024 (Contact grm1@iinet.net.au for all admin enquiries)