Vulnerability Development mailing list archives

Re: Napster a little insecure?


From: scut () NB IN-BERLIN DE (Sebastian)
Date: Sat, 29 Jan 2000 11:09:03 +0100


Hi.

On Fri, Jan 28, 2000 at 05:20:16PM -0200, Thiago Mello wrote:

That´s not true I´ve already tested...
The Naspter is insecure because it get the user IP...
The artist (comapny) thar owns the copyright o the of the
can process if the music is pirate...

That is completely unrelated to the original post. It is true that napster.com
gets the user IP, it has to do this to actually build up a connection. It is
also true that any other napster.com user may aquire the IP address of another
napster user. It is also true that the client sends the whole path of an MP3
file to the napster server, but the server does not send the whole path of an
MP3 file to another napster's user client. I haven't checked about whether the
client allows the transfer of files that don't have an ID3 tag, but I guess
that depends on the client, one may create bogus ID3 information on the initial
file info transfer to the napster.com server and later serve another file (with
a modified client that is).

                                         Thiago Mello

ciao,
scut / team teso
[http://teso.scene.at/]

--
- scut () nb in-berlin de - http://nb.in-berlin.de/scut/ - sacbuctd@ircnet   --
-- you don't need a lot of people to be great, you need a few great to be  --
-- the best ------------------------------------------------------------------
http://3261000594/scut/pgp - 5453 AC95 1E02 FDA7 50D2 A42D 427E 6DEF 745A 8E07
--- expecting arrival 340kg tetranitrocubane as promised, hi echelon ---------



Current thread: