P2P-Zone  

Go Back   P2P-Zone > Peer to Peer
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Peer to Peer The 3rd millenium technology!

Reply
 
Thread Tools Search this Thread Display Modes
Old 19-12-02, 01:22 AM   #1
JackSpratts
 
JackSpratts's Avatar
 
Join Date: May 2001
Location: New England
Posts: 10,017
Default Uh Oh - Music File Flaws Could Threaten Traders

Robert Lemos

A security firm on Wednesday warned that people using Windows XP or popular music player WinAmp could fall prey to a vulnerability, enabling a modified music file to take control of a person's PC.

Flaws in both pieces of software could introduce malicious MP3 or Windows Media files--which sound identical to unmodified music--into the file-swapping systems, said George Kurtz, CEO of Foundstone.

"These particular vulnerabilities are definitely attack vectors for any people or entity that is looking to go after those that are taking part in file-swapping activities," he said.
http://news.com.com/2100-1001-978403.html

- js.
JackSpratts is offline   Reply With Quote
Old 19-12-02, 02:20 AM   #2
TankGirl
Madame Comrade
 
TankGirl's Avatar
 
Join Date: May 2000
Location: Area 25
Posts: 5,587
Wink

Thanks for the heads up, Jack!

If you use WinAmp, better upgrade it to the latest 3.0C version from their site.

- tg
TankGirl is offline   Reply With Quote
Old 19-12-02, 08:09 AM   #3
goldie
yea, it's me.
 
goldie's Avatar
 
Join Date: Jan 2002
Location: usa
Posts: 2,093
Cry Not only sad but dirty lowdown

I love my old, decrepit winamp.

I hate to change it.



Postscript: i'll have to check back for the lite and standard versions.

Last edited by goldie : 19-12-02 at 08:21 AM.
goldie is offline   Reply With Quote
Old 19-12-02, 09:15 AM   #4
theflaco
 
theflaco's Avatar
 
Join Date: Aug 2000
Posts: 768
Default

Quote:
Originally posted by TankGirl
Thanks for the heads up, Jack!

If you use WinAmp, better upgrade it to the latest 3.0C version from their site.

- tg
763 thread posters & 26922 viewers can´t be wrong

winamp 3.0 = not sooo good.


theflaco
theflaco is offline   Reply With Quote
Old 19-12-02, 09:45 AM   #5
JackSpratts
 
JackSpratts's Avatar
 
Join Date: May 2001
Location: New England
Posts: 10,017
Default

Quote:
Originally posted by theflaco
763 thread posters & 26922 viewers can´t be wrong

winamp 3.0 = not sooo good.


theflaco
Quote:
Originally posted by goldenrod
I love my old, decrepit winamp.

I hate to change it.

me too.

- js.
JackSpratts is offline   Reply With Quote
Old 19-12-02, 10:17 AM   #6
goldie
yea, it's me.
 
goldie's Avatar
 
Join Date: Jan 2002
Location: usa
Posts: 2,093
Default just reading through the bitchiing threads and

am really surprised at the hostility between the users and the moderators :S

I really think these peeps have a legimate bitch although many of the rants could have been more mildly phrased - the point is, many are very unhappy with 3.0. I can understand why.

Whether the program is free or not, Winamp developers, if wise, should highlight the particulars of legitimate bitches and use it fine tune the program (which i believe they are since a lite and standard version are on the way).

One particular rant comes to mind..........<won't c&p it for obvious reasons> where the ranter says many users thought 3.0 would be an upgraded (improved) version of 2.8. Instead, they get a totally different playa loaded with bloated processes and pretty pictures.

Don't know about most of you guys here - I tried the 3.0 betas and found it intolerable. I didn't bitch about it on the forums but I tell ya, my puter sure heard a wealth of interesting cuss-word combinations.

There's a place for bloat (for instance, sometimes I like to load my MMJB Plus and WMP <X-tra large w/a twist) but for everyday use, nothing beats winamp 2.8 for great on-the-fly listening pleasure.

It's a crying shame that in order to prevent a malicious mp3 file from going Rambo on your box, you have to install 3.0!

Since (according to that board) they're still working with 2.8, they'll come up with a fix for it and not neglect the tried and true.

<sigh>

GR, thanking her lucky stars the moderators here aren't so crabby and hostile.

goldie is offline   Reply With Quote
Old 19-12-02, 10:22 AM   #7
naz
-
 
naz's Avatar
 
Join Date: Mar 2001
Posts: 1,319
Default

im keeping my 2.8, if my computer blows up so be it
__________________
I’ve been a little down because today my doctor diagnosed me with John Travolta Syndrome. It’s a condition where your face or head grows laterally, getting wider year by year. It’s not so much of a problem and it’s nothing to be ashamed of, it’s just a condition. In fact mine is good because it means my brain is getting bigger too. But not that Travolta guy, his head is mostly fat. The doctors said I am much smarter than John Travolta and I believe them.
naz is offline   Reply With Quote
Old 19-12-02, 11:34 AM   #8
theknife
my name is Ranking Fullstop
 
theknife's Avatar
 
Join Date: Dec 2001
Location: Promontorium Tremendum
Posts: 4,391
Default

I hated 3.0 and went back and got 2.81...

Malk mentions here that the 3.0 and the latest 2.8 build fixed this hole. Anyone know offhand if 2.81 (d/l'd about 2 months ago) is considered to be a safe version?
theknife is offline   Reply With Quote
Old 19-12-02, 12:33 PM   #9
ssj4_android
Redefining Reality
 
ssj4_android's Avatar
 
Join Date: Feb 2002
Posts: 406
Default

Don't tell me this is the minibrowser bug from a while ago.
ssj4_android is offline   Reply With Quote
Old 19-12-02, 02:11 PM   #10
spstn
No Nonsense Nonsense
 
Join Date: May 2002
Location: Miami
Posts: 382
Exclamation

I went to the winamp site and found no indication of this problem anywhere.

I downloaded the 2.81 executable anyways, and comparing it to the old one I found out that the new one is 28 bytes bigger, but I'm not sure that's indication of anything. It looks like they are both the same executable.

So, there's anyone that has certified info about all this mess?

Where's the horse's mouth when you need it?



spstn is offline   Reply With Quote
Old 19-12-02, 02:45 PM   #11
daddydirt
even the losers
 
daddydirt's Avatar
 
Join Date: Jun 2000
Posts: 1,090
Default

from the Breaking News section of the WinAmp forums here

2.81 has been rebuilt with the fix. Download it from http://classic.winamp.com/download/
daddydirt is offline   Reply With Quote
Old 19-12-02, 03:49 PM   #12
thinker
Ex-Singular
 
thinker's Avatar
 
Join Date: Jul 2000
Location: Earth
Posts: 4,677
Default

Winamp...PWAHAHA!!!
thinker is offline   Reply With Quote
Old 20-12-02, 12:16 AM   #13
spstn
No Nonsense Nonsense
 
Join Date: May 2002
Location: Miami
Posts: 382
Thumbs up Thanks

Tanks to daddydirt for the links.

There are other people there as confused as I was. It looks like Nullsoft is neither happy with this flaw nor with the cold reception of Winamp 3, so is going the hush-hush route about all this.

Oh well, is always hard to compete against MS and Real.

When I reinstall 2.81 I'm gonna be checking the replacement of "in_mp3" that now should show: "Nullsoft MPEG Audio Decoder 2.81b", according to one of the posters in Nullsoft's forum.

Winamp (2.80s) is one of the last few things in the net where simplicity and beauty in execution go hand to hand, so keep your executables secure and handy, because the future looks ugly.



spstn is offline   Reply With Quote
Old 20-12-02, 12:50 AM   #14
JackSpratts
 
JackSpratts's Avatar
 
Join Date: May 2001
Location: New England
Posts: 10,017
Default Re: Thanks

Quote:
Originally posted by spstn

Winamp (2.80s) is one of the last few things in the net where simplicity and beauty in execution go hand to hand,
that's so true spstn.

- js.
JackSpratts is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump






All times are GMT -6. The time now is 03:15 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© www.p2p-zone.com - Napsterites - 2000 - 2024 (Contact grm1@iinet.net.au for all admin enquiries)