A Damn Good Reason Not to File Swap

Written by Eric Olsen
Published December 19, 2002

I've mentioned before that while I am philosophically in favor of file sharing (although we have to figure out a way to pay the artists and songwriters), I don't much like it for myself: I have more music than I can listen to on CD and vinyl, and the CDs keep coming in.

I also can tell the difference in sound between a CD and an MP3, which sounds tinny to me; and, I don't have the time to sit at the computer and search for songs, then wait for them to download. The quality of the file via the file-sharing networks also varies widely: you just don't know what you are getting.

None of that is insurmountable and now that I am DJing again, I can see snagging a song now and then - but this is serious:

    Two new security vulnerabilities, disclosed late Wednesday, allow an attacker to completely take over a computer system by using malicious music files.

    The first vulnerability is present in the Microsoft Windows XP operating system. This vulnerability can be exploited when a user simply lets the cursor hover over the file icon for the malicious MP3, or opens a folder where the file is stored.

    The second is found in Nullsoft's Winamp, a popular Windows media jukebox player.

    Both vulnerabilities were discovered by security firm Foundstone, and fixes were immediately available. However, some users reported they were having difficulties locating the Winamp fix.

    "The ubiquity of file-swapping services makes it the perfect attack vector for a malicious MP3 file," Foundstone CEO George Kurtz said. "That is why it is imperative to patch your systems immediately."

    The Windows XP vulnerability, which Microsoft calls "Unchecked Buffer in Windows Shell Could Enable System Compromise," can be exploited through an MP3 or WMA audio file.

    ....Microsoft advised all users of Microsoft Windows XP to apply the patch immediately. [Wired]

I would take care of it right away; but remember, where there are these, there may be more.

Career media professional Eric Olsen is honored to be the founder and publisher of Blogcritics.org, which, quite frankly, rules - as do his wife and four children.
Keep reading for information and comments on this article, and add some feedback of your own!
A Damn Good Reason Not to File Swap
Published: December 19, 2002
Type:
Section: Culture
Filed Under: Music: News
Writer: Eric Olsen
Eric Olsen's BC Writer page
Eric Olsen's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
BC articles by Eric Olsen
Music: News
All Culture Articles
Eric Olsen's personal weblog
All BC articles
All BC Comments

Comments

#1 — December 19, 2002 @ 13:23PM — cjones

since we are on the topic of damn-good reason not to file swap, I have a few other things we should not do for similar damn-good reasons...
1. Dont eat chicken - you could get salmonella
2. Dont buy a car - someone could break into it.
3. Dont cross the street - you could get hit by a car.
4. Dont have children - they might be as retarted as the person who wrote this stupid weblog

#2 — December 19, 2002 @ 13:41PM — Eric Olsen

When one is calling someone "retarded" one shouldn't misspell the word as one's credibility might be called into question.

#3 — December 19, 2002 @ 15:36PM — cjones

danx

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/2351)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments