WINAMP.COM | Forums > Winamp > Winamp Discussion > Winamp skin exploit. Being used as a vector for infection |
| Pages (2): [1] 2 » |
Last Thread
Next Thread
|
| Author |
|
|
DaWolfey Junior Member
Registered: Aug 2004 |
If the above link stops working, I have downloaded the files that it sends. |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
/moved from Tech Support to Discussion Last edited by DJ Egg on 08-26-2004 at 10:22 PM |
||
|
|
|
mikm Major Dude
Registered: May 2001 |
Hmmm....it doesn't appear to be a valid appliaction or skin (i.e. cannot be uncompressed). |
||
|
|
|
DaWolfey Junior Member
Registered: Aug 2004 |
[edit steve] Removed to reduce impact of exploit. Fix is underway. [/edit] |
||
|
|
|
Russ Mostly Harmless (Alumni)
Registered: Jan 2001 |
That's just a really cunning way of circumventing IE's zone restrictions. Not really sure whose fault it is. __________________ |
||
|
|
|
shaneh Major Dude
Registered: Jan 2004 |
Yeah it is kindof an exploit in IE.. I am not sure if SP2 fixes this problem. However, I think it is a bit of an exploit on behalf of Winamp in that it allows all files contained within a .zip file to be copied to the local machine to a predictable location without prompts. This could be exploited in quite a number of ways... __________________ Last edited by shaneh on 08-22-2004 at 05:56 AM |
||
|
|
|
k_rock923 \m/ (Forum King)
Registered: Jul 2003 |
Wouldn't someone notice that there's an xml file in a .wsz?? __________________ |
||
|
|
|
Wildrose-Wally The Albertan (Reviewer)
Registered: Mar 2001 |
|
||
|
|
|
k_rock923 \m/ (Forum King)
Registered: Jul 2003 |
Good point, wally. I only open the files of skins that I want to see how something was done. I know there are xmls in modern skins. I guess that's what I kind of meant. Oh well. __________________ |
||
|
|
|
Kickboy12 Senior Member
Registered: Oct 2003 |
This isn't a IE exploit. It can affect Firefox too if your not carefull. It's entirly an Winamp exploit, cause even in firefox it will prompt you to download the file, and open it... if you open it, you're affected. :/ __________________ |
||
|
|
|
cerebri Junior Member
Registered: Aug 2004 |
This was one nasty little worm. Last edited by DJ Egg on 08-26-2004 at 10:26 PM |
||
|
|
|
Franky752 Junior Member
Registered: Aug 2004 |
advisory
Here is the exploit used : Winamp <=5.04 Skin File (.wsz) Remote Code Execution Exploit Last edited by DJ Egg on 08-26-2004 at 10:29 PM |
||
|
|
|
morgado Major Dude
Registered: Apr 2003 |
Relax ... just don't download skins for now and wait for 5.05 ... __________________ |
||
|
|
|
cerebri Junior Member
Registered: Aug 2004 |
and when will that be? :P |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
It's not a case of 'not downloading skins'. |
||
|
|
|
will Nullsoft Newbie (Moderator)
Registered: Mar 2001 |
This issue is fixed for the next version of winamp. __________________ |
||
|
|
|
cerebri Junior Member
Registered: Aug 2004 |
does anyone know what exacly the flie in this exploit (1.exe) does? besides installing that mirc-script (or is that everything?) |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
Yup. Looks like we'll be getting a 5.05 sooner than we expected... |
||
|
|
|
electricmime Major Dude
Registered: Mar 2004 |
though... isnt 5.05 a little much for one bug...? wouldnt a 5.04a(or b or whatever) be used instead? __________________ |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
maybe... |
||
|
|
|
CraigF Passionately Apathetic Administrator
Registered: May 2000 |
there was talk of some additional updates being included (like the bundling of ml_ipod), but i dont believe these will be included since this is more of a rush-to-fix than a release, yeah, i'd have probably marked it up as a 5.04x than a 5.05, but so be it. |
||
|
|
|
shaneh Major Dude
Registered: Jan 2004 |
...Executable files (exe, scr, bat, pif, com, etc) will no longer be able to run from within wal/wsz skin files... __________________ |
||
|
|
|
CraigF Passionately Apathetic Administrator
Registered: May 2000 |
while i have discussed the same with the previous developers, the general concensus is that you are simply working around the fact that IE is insecure in itself. You are also preventing much of what the <browser> tag was originally included for. |
||
|
|
|
shaneh Major Dude
Registered: Jan 2004 |
The main issue here is the fact that HTML effectively taken from the 'Internet' zone is being rendered in the 'Local Machine' zone (or whatever permissions Winamp gives the web browser object). __________________ |
||
|
|
|
Russ Mostly Harmless (Alumni)
Registered: Jan 2001 |
The best way would be for the browser object to have a way to specify the default security zone for everything it opens. But that would be easy. __________________ |
||
|
|
|
shaneh Major Dude
Registered: Jan 2004 |
Cant you just implement the "IInternetSecurityManager:" interface? It lets you map urls to zones, process url actions etc. __________________ |
||
|
|
|
Russ Mostly Harmless (Alumni)
Registered: Jan 2001 |
I dunno, I've never touched the IE browser object __________________ |
||
|
|
|
shaneh Major Dude
Registered: Jan 2004 |
Oh, I thought you were suggesting that there was no such way of doing that. I admit it isn't that simple though, but it does allow a fair bit of flexibility AFAIK. __________________ |
||
|
|
|
inthegray Major Dude
Registered: Sep 2003 |
i put up a friendly summary on all the information i've gathered regarding the exploit, on winamp unlimited. feel free to point out any inaccuracies you see. __________________ |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
Thread temporarily locked, moved backstage and edited by admin/mods. |
||
|
|
|
Kyllian Member
Registered: Sep 2003 |
S'pose you could tell us what else will be fixed/changed in 5.05? __________________ |
||
|
|
|
DJ Egg Moderator
Registered: Jun 2000 |
No, not much else really, seeing 5.04 was supposed to be the last build for a while... |
||
|
|
|
Kyllian Member
Registered: Sep 2003 |
Ok. __________________ |
||
|
|
|
dlinkwit27 has no CT (Forum King)
Registered: Sep 2000 |
__________________ |
||
|
|
|
Kyllian Member
Registered: Sep 2003 |
Hey, as long as it works __________________ |
||
|
|
|
electricmime Major Dude
Registered: Mar 2004 |
__________________ |
||
|
|
|
CraigF Passionately Apathetic Administrator
Registered: May 2000 |
5.05 should be out some time today. |
||
|
|
|
Cianca Senior Member
Registered: Mar 2002 |
new version include SINGLE UI SKIN???? (i love it) __________________ |
||
|
|
|
will Nullsoft Newbie (Moderator)
Registered: Mar 2001 |
No. This, hopefully, will be in the ipod bundle. Which should be in just over a months time. __________________ |
||
|
|
|
| Pages (2): [1] 2 » |
Last Thread Next Thread
|
WINAMP.COM | Forums > Winamp > Winamp Discussion > Winamp skin exploit. Being used as a vector for infection |
Forum Rules:
|