RIAA Security Hoax

The RIAA website has been under regular attack by hackers for some time now. There may be some humor in the nature of some of the attacks, but as a method of publicizing displeasure with the organization the attacks are counterproductive, giving the RIAA PR and political ammo against computer enthusiasts in general.

The latest attack is not to the site itself, but against the organization in the form of a hoax security advisory:

    Introduction:
    Several months ago, GOBBLES Security was recruited by the RIAA (riaa.org)
    to invent, create, and finally deploy the future of antipiracy tools. We
    focused on creating virii/worm hybrids to infect and spread over p2p nets.
    Until we became RIAA contracters, the best they could do was to passively
    monitor traffic. Our contributions to the RIAA have given them the power
    to actively control the majority of hosts using these networks.

    We focused our research on vulnerabilities in audio and video players.
    The idea was to come up with holes in various programs, so that we could
    spread malicious media through the p2p networks, and gain access to the
    host when the media was viewed.

    During our research, we auditted and developed our hydra for the following
    media tools:
    mplayer (www.mplayerhq.org)
    WinAMP (www.winamp.com)
    Windows Media Player (www.microsoft.com)
    xine (xine.sourceforge.net)
    mpg123 (www.mpg123.de)
    xmms (www.xmms.org)

    After developing robust exploits for each, we presented this first part of
    our research to the RIAA. They were pleased, and approved us to continue
    to phase two of the project — development of the mechanism by which the
    infection will spread.

    It took us about a month to develop the complex hydra, and another month to
    bring it up to the standards of excellence that the RIAA demanded of us. In
    the end, we submitted them what is perhaps the most sophisticated tool for
    compromising millions of computers in moments.

    Our system works by first infecting a single host. It then fingerprints a
    connecting host on the p2p network via passive traffic analysis, and
    determines what the best possible method of infection for that host would
    be. Then, the proper search results are sent back to the "victim" (not the
    hard-working artists who p2p technology rapes, and the RIAA protects). The
    user will then (hopefully) download the infected media file off the RIAA
    server, and later play it on their own machine.

    When the player is exploited, a few things happen. First, all p2p-serving
    software on the machine is infected, which will allow it to infect other
    hosts on the p2p network. Next, all media on the machine is cataloged, and
    the full list is sent back to the RIAA headquarters (through specially
    crafted requests over the p2p networks), where it is added to their records
    and stored until a later time, when it can be used as evidence in criminal
    proceedings against those criminals who think it's OK to break the law.

    Continued on the next page Page 1 — Page 2

Article tags

Spread the word
Bookmark and Share
Profile image for eric-olsen

Article Author: Eric Olsen

Career media professional Eric Olsen is honored to be the founder and former publisher of Blogcritics.org, and former publisher of Technorati.com, which both rule. He is now editor, co-founder, and CEO of The Morton Report.

Visit Eric Olsen's author pageEric Olsen's Blog

Read comments on this article, and add some feedback of your own
  • No image found
  • No image found
  • No image found

Article comments

Add your comment, speak your mind

Personal attacks are NOT allowed.
Please read our comment policy.
Please preview your comment.

blogcritics lists for May 22, 2012

fresh articles Most recent articles site-wide

fresh comments Most recent comments site-wide

most comments Most comments in 24hrs

top writers Most prolific Blogcritics for April

top commenters Most prolific Commenters in 24 hrs