A Damn Good Reason Not to File Swap

I've mentioned before that while I am philosophically in favor of file sharing (although we have to figure out a way to pay the artists and songwriters), I don't much like it for myself: I have more music than I can listen to on CD and vinyl, and the CDs keep coming in.

I also can tell the difference in sound between a CD and an MP3, which sounds tinny to me; and, I don't have the time to sit at the computer and search for songs, then wait for them to download. The quality of the file via the file-sharing networks also varies widely: you just don't know what you are getting.

None of that is insurmountable and now that I am DJing again, I can see snagging a song now and then - but this is serious:

    Two new security vulnerabilities, disclosed late Wednesday, allow an attacker to completely take over a computer system by using malicious music files.

    The first vulnerability is present in the Microsoft Windows XP operating system. This vulnerability can be exploited when a user simply lets the cursor hover over the file icon for the malicious MP3, or opens a folder where the file is stored.

    The second is found in Nullsoft's Winamp, a popular Windows media jukebox player.

    Both vulnerabilities were discovered by security firm Foundstone, and fixes were immediately available. However, some users reported they were having difficulties locating the Winamp fix.

    "The ubiquity of file-swapping services makes it the perfect attack vector for a malicious MP3 file," Foundstone CEO George Kurtz said. "That is why it is imperative to patch your systems immediately."

    The Windows XP vulnerability, which Microsoft calls "Unchecked Buffer in Windows Shell Could Enable System Compromise," can be exploited through an MP3 or WMA audio file.

    ....Microsoft advised all users of Microsoft Windows XP to apply the patch immediately. [Wired]

I would take care of it right away; but remember, where there are these, there may be more.

Article tags

Spread the word
Bookmark and Share
Profile image for eric-olsen

Article Author: Eric Olsen

Career media professional Eric Olsen is honored to be the founder and former publisher of Blogcritics.org, and former publisher of Technorati.com, which both rule. He is now editor, co-founder, and CEO of The Morton Report.

Visit Eric Olsen's author pageEric Olsen's Blog

Read comments on this article, and add some feedback of your own
  • No image found
  • No image found

Article comments

  • 1 - cjones

    Dec 19, 2002 at 1:23 pm

    since we are on the topic of damn-good reason not to file swap, I have a few other things we should not do for similar damn-good reasons...
    1. Dont eat chicken - you could get salmonella
    2. Dont buy a car - someone could break into it.
    3. Dont cross the street - you could get hit by a car.
    4. Dont have children - they might be as retarted as the person who wrote this stupid weblog

  • 2 - Eric Olsen

    Dec 19, 2002 at 1:41 pm

    When one is calling someone "retarded" one shouldn't misspell the word as one's credibility might be called into question.

  • 3 - cjones

    Dec 19, 2002 at 3:36 pm

    danx

Add your comment, speak your mind

Personal attacks are NOT allowed.
Please read our comment policy.
Please preview your comment.

blogcritics lists for May 26, 2012

fresh articles Most recent articles site-wide

fresh comments Most recent comments site-wide

most comments Most comments in 24hrs

top writers Most prolific Blogcritics for April

top commenters Most prolific Commenters in 24 hrs