StreamingSoundtracks.com
VIP
Subscribe to become a VIP member of SST!

· Request More Often
· Unshared Requests
· Request Countdown Timer
· Request Ready Indicator
· Your Request History
· Access To The VIP Forum
· Add More Favorites

:: Click Here To Upgrade ::

:: Give VIP as a Gift ::

Listen Live!

Donation Meter


Make donations with PayPal!
Monthly Goal:
$500.00

Need:
$154.46

3 Donations:
$345.54

StreamingSoundtracks.com (May-5) Shru $50.00
StreamingSoundtracks.com (May-3) Anonymous $50.00
Death.FM (May-1) SeclusionSolution $245.54

 


Last Month's Donors
StreamingSoundtracks.com (Apr-24) klingon50 $10.00
StreamingSoundtracks.com (Apr-23) janbenes $25.00
Death.FM (Apr-9) shrike $20.00
StreamingSoundtracks.com (Apr-8) trailblder $25.00
Death.FM (Apr-2) SeclusionSolution $242.42
StreamingSoundtracks.com (Apr-2) Locutus76 $30.00




Search

 

SSTore



:: SSTore ::



WinAmp exploit in the news
Goto page 1, 2  Next
 
Post new topic   Reply to topic    StreamingSoundtracks.com Forum Index -> General
View previous topic :: View next topic 
Author Message
Yemen j2brown
Commodore
Commodore

aw

Joined: Feb 22, 2002
Member#: 9
Posts: 3188
Location: Sterling, VA

j2brown is offline View user's profile Send private message Send e-mail View j2brown's Favorites
AIM Address Yahoo Messenger MSN Messenger
PostPosted: Fri Aug 27, 2004 6:47 am   Post subject: WinAmp exploit in the news Reply with quote


I'd suspect that many folks here use WinAmp and might want to be aware that there is an exploit out there making news recently. See the following for details if you're concerned.

http://www.securityfocus.com/news/9401

or

http://www.internetnews.com/security/article.php/3400231

or

http://news.com.com/Winamp+vulnerable+to+camouflaged-skin+attacks/2100-1002_3-5323990.html

--
jeff
sdg
USA JERIC VIP (subscribed member)
Fleet Admiral (Proprietor)
Fleet Admiral (Proprietor)



Joined: Feb 12, 2002
Member#: 1
Posts: 4939
Location: Richmond, VA

JERIC is offline View user's profile Send private message Send e-mail Visit poster's website View JERIC's Favorites
AIM Address Yahoo Messenger MSN Messenger ICQ Number Skype Name
PostPosted: Fri Aug 27, 2004 7:23 am   Post subject: Reply with quote


Wow! I suggest QCD or Radio365 until a patch comes out to fix the vunerability.
_________________
"Are you not entertained? Are you not entertained? Is this not why you are here?." -Maximus

Please do not PM me. Use email, Feedback or Contact Us links.
USA Cocles
Commodore
Commodore

aw

Joined: Mar 06, 2002
Member#: 15
Posts: 2587
Location: Los Angeles, CA

Cocles is offline View user's profile Send private message Visit poster's website Cocles's Favorites are Private
AIM Address Yahoo Messenger MSN Messenger ICQ Number
PostPosted: Fri Aug 27, 2004 7:28 am   Post subject: Reply with quote


From a buddy of mine,

Winamp 2 is NOT affected. Winamp 5 Lite is also NOT affected.

If you unchecked "Modern Skin Support" in the installer you are also
NOT affected.

You can even remove Modern Skin Support just by renaming Program
Files\Winamp\Plugins\gen_ff.dll to gen_ff.dll.old. This will remove the
exploit.

If you fix this way, you will only be able to use classic skins.
Caliburn
Guest









PostPosted: Fri Aug 27, 2004 7:33 am   Post subject: Reply with quote


new skin is not even installed here :-)
USA JERIC VIP (subscribed member)
Fleet Admiral (Proprietor)
Fleet Admiral (Proprietor)



Joined: Feb 12, 2002
Member#: 1
Posts: 4939
Location: Richmond, VA

JERIC is offline View user's profile Send private message Send e-mail Visit poster's website View JERIC's Favorites
AIM Address Yahoo Messenger MSN Messenger ICQ Number Skype Name
PostPosted: Fri Aug 27, 2004 7:58 am   Post subject: Reply with quote


Good to know. I keep mine on the SST skin of course.
_________________
"Are you not entertained? Are you not entertained? Is this not why you are here?." -Maximus

Please do not PM me. Use email, Feedback or Contact Us links.
Jazzman
Lieutenant
Lieutenant



Joined: Jul 20, 2004
Member#: 7365
Posts: 100
Location: Utah, USA

Jazzman is offline View user's profile Send private message Jazzman's Favorites are Private
MSN Messenger
PostPosted: Fri Aug 27, 2004 10:48 am   Post subject: Reply with quote


Someone was saying that keeping it on some skin all the time isn't enough to protect you. Anyone know if that's true? I actually use a winamp general plugin that provides a different (non-skinnable) UI altogether. But since the main window is still running (just not visible) I suppose I'm still vulnerable. I'll rename my gen_ff.dll right now. Thanks for the tip, Cocles.
_________________
All I ask is for a chance to prove that money can't buy happiness.
USA Techo
Lieutenant
Lieutenant



Joined: Feb 12, 2004
Member#: 5054
Posts: 182


Techo is offline View user's profile Send private message View Techo's Favorites
PostPosted: Fri Aug 27, 2004 1:05 pm   Post subject: Reply with quote


Thanks for the info.

Quote:

The company said the default installation of WinAmp registers the WSZ file extension and includes an instruction to Windows and Internet Explorer to automatically open the files. It leads to the fake WinAmp skin being automatically loaded into the media player.


So if you remove the association between *.wsz files and winamp you can be safer? since Windows won't know which application is associated with the file and therefor winamp won't execute it.

For Windows Explorer goto the menu Tools->Folder Options->File Types and delete the WSZ entry in the list. I tried it and WinAMP didn't add the entry back after restarting it, and everything still seems to work just fine as it did before.

edit:

You can also prevent IE from auto opening the file if you do have it associated with a program, find the file extension in the "File Types" list, click "Advanced" and check "Confirm open after download"
Denmark Nr2000
Lieutenant Junior Grade
Lieutenant Junior Grade



Joined: Apr 06, 2003
Member#: 603
Posts: 89
Location: Denmark

Nr2000 is offline View user's profile Send private message Nr2000's Favorites are Private
PostPosted: Fri Aug 27, 2004 4:35 pm   Post subject: Reply with quote


Nullsoft has now released Winamp 5.05. The serious security flaw should be fixed in this version.

Download Winamp 5.05 - Full
Download Winamp 5.05 - Lite




Last edited by Nr2000 on Sat Dec 04, 2004 10:28 am; edited 1 time in total
Belgium Tron
Lieutenant Commander
Lieutenant Commander



Joined: Dec 13, 2003
Member#: 4034
Posts: 319
Location: Belgium

Tron is offline View user's profile Send private message Tron's Favorites are Private
PostPosted: Fri Aug 27, 2004 4:37 pm   Post subject: Reply with quote


[edit] => 2000's post. Good to have my winamp back after 2 horrible minutes Laughing
USA Techo
Lieutenant
Lieutenant



Joined: Feb 12, 2004
Member#: 5054
Posts: 182


Techo is offline View user's profile Send private message View Techo's Favorites
PostPosted: Fri Aug 27, 2004 6:06 pm   Post subject: Reply with quote


Nr.2000 wrote:
Nullsoft has now released Winamp 5.05. The serious security flaw should be fixed in this version.

Download Winamp 5.05 - Full
Download Winamp 5.05 - Lite



vroooom , That was fast Smile
USA PeteC VIP (subscribed member)
Commander
Commander



Joined: Nov 26, 2003
Member#: 3796
Posts: 587
Location: Evanston, IL

PeteC is offline View user's profile Send private message View PeteC's Favorites
PostPosted: Sat Aug 28, 2004 9:59 pm   Post subject: Reply with quote


Thanks for the info. Appreciated.
_________________
All in the world recognize the
beautiful as beautiful. Herein
lies ugliness. All recognize the
good as good. Herein lies evil.
Patje
Lieutenant
Lieutenant



Joined: Mar 31, 2003
Member#: 482
Posts: 212
Location: The Netherlands

Patje is offline View user's profile Send private message Send e-mail Patje's Favorites are Private
MSN Messenger
PostPosted: Sun Aug 29, 2004 9:22 am   Post subject: Reply with quote


JERIC wrote:
Good to know. I keep mine on the SST skin of course.



Of course Very Happy


To "Nr.2000" : Thanx.
_________________
In a world without justice, one man was chosen to protect the innocent.
Denmark Nr2000
Lieutenant Junior Grade
Lieutenant Junior Grade



Joined: Apr 06, 2003
Member#: 603
Posts: 89
Location: Denmark

Nr2000 is offline View user's profile Send private message Nr2000's Favorites are Private
PostPosted: Sat Nov 27, 2004 1:35 pm   Post subject: Reply with quote


There has been found a new serious security flaw in Winamp 5.05 and previous versions. Nullsoft has now released Winamp 5.06, the exploit may not be completely fixed in this new version! A version 5.06a or version 5.07 may soon be released.

http://secunia.com/advisories/13269/

Download Winamp 5.06 - Full
Download Winamp 5.06 - Lite




Last edited by Nr2000 on Sat Dec 04, 2004 10:27 am; edited 1 time in total
Denmark Nr2000
Lieutenant Junior Grade
Lieutenant Junior Grade



Joined: Apr 06, 2003
Member#: 603
Posts: 89
Location: Denmark

Nr2000 is offline View user's profile Send private message Nr2000's Favorites are Private
PostPosted: Sat Dec 04, 2004 10:26 am   Post subject: Reply with quote


Winamp 5.07 have now been released by Nullsoft. The security flaw should be fixed in this new version. Please upgrade now. Smile

http://secunia.com/advisories/13269/

Download Winamp 5.07 - Full
Download Winamp 5.07 - Lite




Last edited by Nr2000 on Sat Jan 15, 2005 10:16 am; edited 1 time in total
soundTrack_nut
Lieutenant Junior Grade
Lieutenant Junior Grade



Joined: Aug 08, 2003
Member#: 2714
Posts: 64
Location: Fairfax, VA

soundTrack_nut is offline View user's profile Send private message soundTrack_nut's Favorites are Private
AIM Address MSN Messenger ICQ Number
PostPosted: Sat Dec 11, 2004 10:42 am   Post subject: Reply with quote


Never heard about this until I got on the site. Just dled it. Thanks! Winamp is the best!
_________________
Stargate SG1
Stargate Atlantis
Battlestar Galactica
Returning January - SciFi Channel
Display posts from previous:
Post new topic   Reply to topic    StreamingSoundtracks.com Forum Index -> General All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Forums ©


Copyright © 2001-2020 24seven.FM, LLC All rights reserved.
Comments, images, and trademarks are property of their respective owners.
You can syndicate our news using the file backend.php or ultramode.txt. Robots may follow the Sitemap.