Vulnerability Development mailing list archives

Re: how to transfer files on napster


From: geetwentythree () YAHOO COM (Marcy Abene)
Date: Sat, 5 Feb 2000 10:39:59 -0800


I'm just speculating here, but I've heard of a similar
online file exchange area called Hotline
(http://www.bigredh.com/index2.html)
http://www.freshmeat.net/search.php3?query=hotline

Correct me if I'm wrong, but isn't this almost exactly
the same thing only with a focus on porn and warez
over mp3?  (not overtly of course)

I imagine there are security issues lurking in the
Hotline clients if they allow more file types.

On Sat, 5 Feb 2000, Blue Boar wrote:
Jordan Ritter wrote:

On Sat, 5 Feb 2000, Jason Copenhaver wrote:

# this txt explains a pretty simple way into
fooling napster into
# thinking that your transfering an mp3 file.  It
looks like it only
# checks for a valid 4 byte mp3 header and the mp3
file extenstion....

As I stated already in a list email well before
yours, this is possible.
Anyone that wants to pursue steganographic methods
for fooling file
transfer software is very likely to meet with
success.

My conclusion was, who the hell would want to?  A
hex editor?  Gee, that's
useful.

--jordan

Depends on whether you were trying to keep people
solely from giving access
to other files on accident, or if you were trying to
keep people from
trading other types of warez intentionally.

                                              BB

__________________________________________________
Do You Yahoo!?
Talk to your friends online with Yahoo! Messenger.
http://im.yahoo.com


Current thread: