Winamp & Shoutcast Forums

Winamp & Shoutcast Forums (http://forums.winamp.com/index.php)
-   Shoutcast Discussions (http://forums.winamp.com/forumdisplay.php?f=9)
-   -   Tuning-in to "Republic of Korea Top Radio" gives you a trojan? (http://forums.winamp.com/showthread.php?t=141358)

Psythik 7th July 2003 04:03

Tuning-in to "Republic of Korea Top Radio" gives you a trojan?
 
1 Attachment(s)
Just recently, I decided to see what the buzz was all about and decided to listen to this 'Republic of Korea Top Radio' that seems to almost be dominating DI. Right when I try to tune-in, a message from my firewall pops up and alerts me not to tune-in due to a trojan that attemped to download (called 'Sienna Spy') as I was tuning-in. I decided to find-out what's going on and did a little tracing on the IP address where this trojan was coming from and got considerably less info than from most IP traces I perform. The following is all I got from it:

Quote:

Name: Unknown
IP Address: 218.145.30.106
Location: SEOUL (37.533N, 127.000E)
Network: APNIC4

Registrant contact information is not available.



OrgName: Asia Pacific Network Information Centre
OrgID: APNIC
Address: PO Box 2131
City: Milton
StateProv: QLD
PostalCode: 4064
Country: AU

NetRange: 218.0.0.0 - 218.255.255.255
CIDR: 218.0.0.0/8
NetName: APNIC4
NetHandle: NET-218-0-0-0-1
Parent:
NetType: Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS.RIPE.NET
NameServer: RS2.ARIN.NET
Comment: This IP address range is not registered in the ARIN database.
Comment: For details, refer to the APNIC Whois Database via
Comment: WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl
Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment: for the Asia Pacific region. APNIC does not operate networks
Comment: using this IP address range and is not able to investigate
Comment: spam or abuse reports relating to these addresses. For more
Comment: help, refer to http://www.apnic.net/info/faq/abuse
Comment:
RegDate: 2000-12-07
Updated: 2002-09-11

OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3100
OrgTechEmail: search-apnic-not-arin@apnic.net

ARIN WHOIS database, last updated 2003-07-05 21:05
Enter ? for additional hints on searching ARIN's WHOIS database.


Last Response Time: 239 ms

Highest Response Time: 239 ms
Lowest Response Time: 239 ms
Average Response Time: 239 ms

Total Number of Packets Sent: 1

Dropped/Lost Packets 0
Dropped/Lost Packets %: 0 %
This supposed 'trojan' that I almost got has never happened to me before when tuning-in to other stations. What is going-on here? Is MUKULCAST trying to invade mass computers by disguising a deadly trojan horse as a radio station? Or were they simply hacked and the hacker placed the trojan, knowing that it would spread massively considering that thousands of persons listen daily? And has anyone else gotten this firewall alert? I'd like to have some answers. The attachment is a snapshot of the exact firewall alert I get when tuning-in:

GarbagePoe 7th July 2003 04:07

Oh crap, I tuned into that station just now. I don't have a firewall so nothing popped-up. Could something happen to my computer now? I'm not listening to that station anymore now.

Sawg 7th July 2003 04:11

Winamp is unable to download software within a SHOUTcast stream. The cnace are you probally either alread had the tojan on your system or the firewall made a flase positive.

You should try running Ad-Aware.

You CANNOT install sofrware with a SHOUTcast Stream.


Remember, a lot of these Paranoia-ware firewall and like products are usually quite quick to call something a Trojan or attack. It helps sell more products if they make you think every connection is some kind of attack.

DJ AmPs 7th July 2003 13:32

I beg to differ Sawg, a stream can cause a DL thru the pop-up metadata. People using custom broadcasting software can cause winamp to download stuff thru the minibrowser. I don't know if there are the same warnings IE has either.

DJHotIce 7th July 2003 14:25

all adaware will do is remove spyware it's not intended to be a virus/trojan remover. I have gotten pop ups from a stream download.

Thus I know if you get a pop up, there must be a way to get a virus download. Either that or I have a spyware thing on my system, must run adaware again :D

DJ AmPs 7th July 2003 15:21

Maybe it's a listening trojan -- i.e. your computer keeps itself tuned in in the background, because I don't see how so many people could stand that station. =)

DJHotIce 7th July 2003 15:24

Quote:

Originally posted by DJ AmPs
Maybe it's a listening trojan -- i.e. your computer keeps itself tuned in in the background, because I don't see how so many people could stand that station. =)
Your speculating.

If a listener was indeed jacking up the listener count it would create a need for an imediate ban for the station :D

As you can tell snyth or w/e his sn he was listeneing to the station lol

Rafael2127 7th July 2003 16:53

OK now that you are talking about Korea
 
Now that we are talking about Korean radios
I always wanted talk about this new site http://inLIVE.co.kr I see everywhere on shoutcast I tried to be a member of there site but its all in korean I had to translate using altavista.com to understand and fill out all the info but when I got to a part where they ask me for a Id number maybe a social ## of korea something like that I never got to register all there radios can get up to 1000 to a 10000 listener and most of them they stream at 128kbps
So What is this inlive.co.Kr site that has more than 20 radios on shoutcast some of them streaming at 160kbps

hey maybe we can became a member and make a new radio for free :D

Psythik 7th July 2003 22:35

Quote:

Originally posted by DJHotIce
As you can tell snyth or w/e his sn he was listeneing to the station lol
Say what??


Anyway, I still think something is going on with this station, due to the simple fact that I run [http://housecall.trendmicro.com]TrendMicro's and McAfee's virus scanners once a week and Ad-aware every day, and haven't come up with any trojan of some sort. Therefore, I still believe listening to this station may download a trojan.

DJHotIce 7th July 2003 22:40

Quote:

Therefore, I still believe listening to this station may download a trojan.
I don't discredit your account. I'm not saying that its not possible.

wait a sec Posts: 24,571,641 lol? And your a senior member still. Wouldn't that qualify for King by now?

Well now that you mention. Have you come accross a station that has popups when you click to listen. I believe its possible. Can't you embed something like that into the playlist?

Psythik 8th July 2003 01:43

Quote:

Originally posted by DJHotIce
wait a sec Posts: 24,571,641 lol? And your a senior member still. Wouldn't that qualify for King by now?
Well...uh, it's kinda a glitch, and.....um....

never mind.

DJHotIce 8th July 2003 01:58

lol. I love the mac video. It truly speaks to me really. I'm a vid editor myself

didn't like the f words in there but hey oh well.

ddominey86 8th July 2003 12:18

ok, i'm going to striaten this all out.

a radio stream cannot contain software, and as for the Senna Spy trojan, it is a false alarm, the Republic of Korea radio uses the port 11000 for broadcasting, that is the port that the Senna Spy trojan uses, it is not really a trojan, its just a false alarm. the reson why this was trigured is because your firewall is crap.

DJ AmPs 8th July 2003 13:47

Yep you're right. I never even looked at that screen shot -- now that I have it's obvious. DOH!

DJHotIce 8th July 2003 15:30

Quote:

Originally posted by ddominey86
ok, i'm going to striaten this all out.

a radio stream cannot contain software, and as for the Senna Spy trojan, it is a false alarm, the Republic of Korea radio uses the port 11000 for broadcasting, that is the port that the Senna Spy trojan uses, it is not really a trojan, its just a false alarm. the reson why this was trigured is because your firewall is crap.


LOL LOL LOL :blah:

no use for this topic anymore eh?

Psythik 9th July 2003 19:13

I have to admit, it is a piece of shit, but hey, it's better than no firewall and it really did save my ass by protecting me from getting hacked a while back.

DJHotIce 9th July 2003 19:18

lol sounds like a dog scyth lol. like it saved my butt along that long road lol

soulful1 9th July 2003 22:42

Get yourself a copy of zoneAlarm pro. :)

soulful1

DJHotIce 9th July 2003 23:00

Wait a sec. I used to have Zone Alarm. And my system would have the biggest fight ever. I 'd hive crashing everyday on my SAM program. SO I hate zone alarm

soulful1 9th July 2003 23:42

Really?? It runs like a well oiled machine on my system. Configuration is key.


soulful1

DJHotIce 9th July 2003 23:43

I was told that SAM + Zone alarm don't mix from the program creators, and everybody says that on the mailing list too!

soulful1 9th July 2003 23:46

Seriously I have no problem with it. Guess I got lucky. Sam stats works fine. Were you using the free version or ZoneAlarm Pro?

soulful1

DJHotIce 9th July 2003 23:50

free version. I'll be using tiny personal firewall in a while

soulful1 10th July 2003 00:14

Hope you have better luck with it. :)

soulful1

DJHotIce 10th July 2003 00:21

Ah sam is running great now. But thanks for wishing the best :D

Psythik 10th July 2003 23:35

ooh, there's a free ver? I'm gettin' it.

DJHotIce 10th July 2003 23:41

lol, yea the old version of personal firewall :D its free :D Sam isn't free just to make a note

Psythik 10th July 2003 23:46

Heh. Now I got 2 firewalls running. McAfee (the crappy one) and ZoneAlarm 3. Weeelah!!!

DJHotIce 11th July 2003 03:08

AS I said in the post above, za used to be my best friend but now that sam and zone alarm don't have the same views on the world I guess I'll just need use mcAfee and tiny personal, and Norton.

Think thats enough security ;)
I hope there isn't any hardware conflicts. Nah I'll prob just use tiny personall to save on memory & CPU

Psythik 11th July 2003 04:14

I tried SAM2, but switched back to good ol' winamp after having repetative problems with SAM's encoders.

BTW, I've had these 2 firewalls running for some time now and there doesn't seem to be any conflicts yet. Plus ZA picks up what McAfee misses and vice-versa, so I'm cool with my security for now.

DJHotIce 11th July 2003 04:43

YEa thats cool. IF you try the latest ed of sam, those versions should be fixed. We've been debuggin like crazy :D


All times are GMT. The time now is 06:51.

Copyright © 1999 - 2010 Nullsoft. All Rights Reserved.