Old 6th January 2004, 12:20   #1
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
Pretty serious issues (Winamp maintainers plz read)

Dunno how to say this, but if you get my hint, /pub/music is widely open.
No authentication whatsoever needed to gain acces to the root of the FS.

(Winamp Community authoritives please PM for details)
|LDR|aDa is offline  
Old 6th January 2004, 12:24   #2
Bilbo Baggins
Wind Chime of the Apocalypse
 
Bilbo Baggins's Avatar
 
Join Date: May 2000
Location: The Forest
Posts: 17,228
Say what?
Bilbo Baggins is offline  
Old 6th January 2004, 12:26   #3
Russ
Mostly Harmless
(Alumni)
 
Join Date: Jan 2001
Location: UK
Posts: 2,319
Well, if you mean you can go here and download all the lovely DRMed licensed AOL goodness, then that is correct. And that's not a bug.

And if you mean you can go here and look at the wonderful, properly permissioned chrooted goodness of ftp27e.newaol.com, then you'd also be correct. But there's no vulnerability there (except that you can download all their music and videos, which is sort of the point...).

So in fact, there's not actually a problem at all.

For long you live and high you fly, but only if you ride the tide, and balanced on the biggest wave you race towards an early grave.
|Musicbrainz|Audioscrobbler|last.fm|
Russ is offline  
Old 6th January 2004, 12:27   #4
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
*blushes*
|LDR|aDa is offline  
Old 6th January 2004, 12:30   #5
Germ
rules all things
 
Germ's Avatar
 
Join Date: Jan 2001
Posts: 3,149
Aw Russ, you embarassed them. For shame for shame.
Germ is offline  
Old 6th January 2004, 12:31   #6
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
I really should do more research before alarming everyone like that :P
|LDR|aDa is offline  
Old 6th January 2004, 12:42   #7
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
Nevertheless, youve got like
ftp25e
ftp25d
ftp25c
ftp25b

and the list goes on, all open and public FTP servers.

You are practically begging to be hacked.

And no, ive got no idea whatsoever what sequrity measures youve taken, but in my eyes something like this isnt the smartest thing to do.
|LDR|aDa is offline  
Old 6th January 2004, 12:48   #8
Russ
Mostly Harmless
(Alumni)
 
Join Date: Jan 2001
Location: UK
Posts: 2,319
They're only "open" insofar as you can see a directory listing of the public FTP root. These aren't small-time fileservers - these things serve software of the like of Netscape, Mozilla, Compuserve, AOL, as well as Winamp and have done for several years. If they were hackable it would have been done (and it hasn't).

For long you live and high you fly, but only if you ride the tide, and balanced on the biggest wave you race towards an early grave.
|Musicbrainz|Audioscrobbler|last.fm|
Russ is offline  
Old 6th January 2004, 12:53   #9
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
ftp.newaol.com is the main one, right?
|LDR|aDa is offline  
Old 6th January 2004, 13:03   #10
THEMike
Bastificator [Alumni]
 
THEMike's Avatar
 
Join Date: May 2000
Location: #nullsoft
Posts: 1,260
ftp.newaol.com would (probably) be a load balancer that will hand off download to one of a bunch of mirror servers as one server couldn't cope with the full load.

It'll do this on a round-robin, or load based algorithm. It will know which servers are up via a heart beat system probably.

If you're going to offer downloads of software, you need some kind of annon download, FTP is preferable to HTTP as download management is easier for users.

Thousands of companies on the web have open, public, FTP/HTTP download servers, some get hacked, most don't. It's not hard to have a protected, open FTP download for stuff like winamp.

Especialy when you are AOL.

"Beer?"
THEMike is offline  
Old 6th January 2004, 16:45   #11
Agent007
Member
 
Agent007's Avatar
 
Join Date: Jan 2002
Posts: 63
So, how'd u know about the FTP servers?


Quote:
Originally posted by |LDR|aDa
Nevertheless, youve got like
ftp25e
ftp25d
ftp25c
ftp25b

and the list goes on, all open and public FTP servers.
Agent007 is offline  
Old 6th January 2004, 19:59   #12
InvisableMan
Ninja Master!
(Forum King)
 
InvisableMan's Avatar
 
Join Date: Mar 2001
Location: Hotel California
Posts: 4,333
when theres a /pub in the string then you know it's probably MEANT to be mostly wide open :P
InvisableMan is offline  
Old 6th January 2004, 20:00   #13
fwgx
Rudolf the Red.
(Forum King)
 
fwgx's Avatar
 
Join Date: Nov 2000
Posts: 9,314
I often say the same about womens legs in my local too.

"We think science is interesting and if you disagree, you can fuck off."
fwgx is offline  
Old 6th January 2004, 22:25   #14
ertmann|CPH
Forum Viking
(Forum King)
 
ertmann|CPH's Avatar
 
Join Date: Jan 2001
Location: The North
Posts: 3,541
OMG! OMG! OMG! another dane being lame

velkommen til vores lille sted på nettet iøvrigt, please enjoy your stay, watch out for Bilbo and all that jazz...

- Stefan
ertmann|CPH is offline  
Old 6th January 2004, 22:31   #15
bored154
Major Dude
 
bored154's Avatar
 
Join Date: Jul 2003
Location: near mid of CA Posts: not much........ B-Day: August 1st
Posts: 1,348
Send a message via Yahoo to bored154
um... do you know what /pub stands for? it stands for "public"(sorry if im stating the obvious)

[added] oh ya and did you know theres UK Music too? http://ftp27e.newaol.com/pub/music/uk/ and you can go here also... http://ftp27e.newaol.com/pub/ [/added]

[added again]VIDEOS [/added again]

Supporting"RE-MOD Bilbo"
.::My SETI::..::My Forums::..::My New Site::..::Winamp IRC::..::My DeviantArt Page::.
bored154 is offline  
Old 8th January 2004, 12:23   #16
|LDR|aDa
Junior Member
 
Join Date: Aug 2003
Location: Denmark, Copenhagen.
Posts: 42
Jo tak ertmann ... bor self i KBH.
/me joined Aug 2003

@agent007:
Lets say.... i was looking for more.
Ive been playing Uplink for too long now .)
|LDR|aDa is offline  
Old 8th January 2004, 13:22   #17
ertmann|CPH
Forum Viking
(Forum King)
 
ertmann|CPH's Avatar
 
Join Date: Jan 2001
Location: The North
Posts: 3,541
oh well, har bare aldrig set dig før...
ertmann|CPH is offline  
Old 8th January 2004, 23:05   #18
bored154
Major Dude
 
bored154's Avatar
 
Join Date: Jul 2003
Location: near mid of CA Posts: not much........ B-Day: August 1st
Posts: 1,348
Send a message via Yahoo to bored154
Quote:
Originally posted by |LDR|aDa
@agent007:
Lets say.... i was looking for more.
Ive been playing Uplink for too long now .)
thats a fucking hacking tool!!!

Supporting"RE-MOD Bilbo"
.::My SETI::..::My Forums::..::My New Site::..::Winamp IRC::..::My DeviantArt Page::.
bored154 is offline  
Old 8th January 2004, 23:07   #19
dlinkwit27
has no CT
(Forum King)
 
dlinkwit27's Avatar
 
Join Date: Sep 2000
Posts: 13,236
Send a message via ICQ to dlinkwit27 Send a message via AIM to dlinkwit27 Send a message via Yahoo to dlinkwit27
it's a hacking game maybe, but not a tool.
dlinkwit27 is offline  
Old 8th January 2004, 23:08   #20
bored154
Major Dude
 
bored154's Avatar
 
Join Date: Jul 2003
Location: near mid of CA Posts: not much........ B-Day: August 1st
Posts: 1,348
Send a message via Yahoo to bored154
did you look at their website? its a hacking tool.... it can hack into locked servers... find out who people are, find their records.... its a hacking tool....

[added] nm i looked in their forums... it says "Stuck in the game? come here" but it could be modified to be a hacking tool... [/added]

Supporting"RE-MOD Bilbo"
.::My SETI::..::My Forums::..::My New Site::..::Winamp IRC::..::My DeviantArt Page::.
bored154 is offline  
Old 8th January 2004, 23:11   #21
Loveless
Senior Member
 
Loveless's Avatar
 
Join Date: Aug 2001
Posts: 421
well, in all fairness, notepad.exe can be a hacking tool. If he were malicious, he wouldn't have thought the things he thought and then come posted them in here. Odds are, anyway. There's no accounting for people.

WOT NO FANNY PACKS? (. .)
----------------------w-O-w-----------
Loveless is offline  
Old 8th January 2004, 23:46   #22
Russ
Mostly Harmless
(Alumni)
 
Join Date: Jan 2001
Location: UK
Posts: 2,319
Uplink isn't a hacking tool, it's a game which has very little to do with hacking/cracking in the real world.

Locking, this thread has run its course.

(I'm quite drunk)

For long you live and high you fly, but only if you ride the tide, and balanced on the biggest wave you race towards an early grave.
|Musicbrainz|Audioscrobbler|last.fm|
Russ is offline  
Closed Thread
Go Back   Winamp & Shoutcast Forums > Community Center > General Discussions

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump