Sunday, December 04, 2005

LimeWire Security Hole Exposed and Remedied

Slyck News story dated March 14, 2005:

On the LimeWire.com homepage a curious message has recently appeared. On the upper left portion of the homepage, the text 'Security Update!! All LimeWire users of versions prior to 4.8 must upgrade' was posted. The lack of information, while potentially confusing to some, is method of self-protection when a serious exploit is discovered.
However, since a more mainstream audience has adopted LimeWire, the next move has been to release additional information to reach its extensive user base. LimeWire has also communicated the situation by sending upgrade messages to users of older versions. Slyck spoke with LimeWire COO Greg Bildson about the security flaw.
'LimeWire versions prior to our 4.8 release of two weeks ago contained a serious potential security flaw. Since April of 2004, it was possible to craft a HTTP request for an arbitrary file off the computer of an active user. The problem actually arose in two forms. Version 4.6 fixed half of the problem but it was only in version 4.8 that we fixed both problems. These flaws were pointed out to us by Cornell researchers reading through the open source code themselves.'
"We quickly created patches and addressed the problems immediately upon discovery. We have been shipping version 4.8 for two weeks but we strongly encourage all users to upgrade. If users have not yet upgraded to version 4.8, please do so."
"Let me outline the two specific problems. There was a bug introduced in LimeWire in April 2004 which could allow access to an arbitrary file off a user's hard disk. Based on this bug, a HTTP request could be crafted for a file on the same hard drive that LimeWire was installed on. Our 4.8 release on Feb 28 fixed this problem."
"A similar but slightly more invasive problem was introduced in July of 2004 as part of a new feature. Based on a flaw in the design of this code, a HTTP request could be crafted for a file across hard drives on a user's computer when actively running LimeWire. This problem was fixed in version 4.6 of LimeWire."
"Again, we strongly encourage all users to upgrade to LimeWire version 4.8.1 available now if they have not already done so."

Original Slyck News story

Saturday, December 03, 2005

Sony Caught Using ‘Fake’ Graffiti to Promote PSP

“Not content with simply knowingly infecting its customers’ computers with security-hole inducing spyware, Sony is now sponsoring a ‘guerrilla’ graffiti ad campaign to promote the PSP, covering inner city neighbourhoods with images of kids playing with its overpriced, crippled handheld.
  “Reports on the interwebs indicate that Sony or its ad agency has paid graffiti artists to spray paint images of little kids playing with PSPs in at least five U.S. cities: Chicago, New York, Philadelphia, Los Angeles, and San Francisco.
  “Thankfully here in San Francisco’s Mission neighbourhood, someone decided to talk back to a mega-corporation arrogant enough to piss on my neighbourhood’s walls in order to move units.
  “And whoever the commenter was, he or she was right. Not another dime.”


I couldn't agree more: this week I bought a new 74cm flat screen TV. I deliberately avoided all the Sony ones because of their rootkit arrogance. And I look carefully to see whether the movies I watch or the music I buy is published by them too.

See pictures at Secondary Screening: Sony's Fony Graffiti | digg story

Abort, Retry, Fail

I have to admit the guy has a nerve. He claims to have infected my PC with viruses, and suggested I run a McAfee scan. So here is the scan result: 12 detected files.


(Click on the images for more detail)

Why am I not worried? Well, for starters, McAfee reports the GRC.com application DCOMbobulator, along with the Remote Administrator program from Famatech, and the eMusic toolbar. If you read the detailed notes more carefully, they mention that none of these files is a virus, but a potential security risk. Funny they don't detect LimeWire as a security risk. Ed obviously knows better. Here is what he claims:

(Click on the image for more detail)

I'm not convinced. I tried really hard to find the files shown here, without success. They certainly aren't on my PC. And the claimed "infections" didn't show up, either with my anti-virus program, or with Ed's faithful McAfee. And Rootkit Revealer 1.56 doesn't report anything either.

Ed insists that mcprog.dyn.isogo.co.za isn't my PC's IP address, and refers to it by the IP number 165.165.150.158 (also known as dsl-165-150-158.telkomadsl.co.za). Actually, that number is part of a pool of addresses used by my ISP, and gets changed every 24 hours or so. The dynamic address from Isogo keeps track of which number in the pool is for my internet connection.

The screen shot he sent reveals a few unintended things too: Ed claims to use only the very latest free version of LimeWire. Why then does the screen shot display an out of date version of LimeWire PRO? It even warns him that it's out of date, right on the screen! DUH. LimeWire PRO isn't the free version, but the paid version.

Try again Ed. I'm waiting for you to hack my machine. And spoofing my IP address doesn't fool me, even if it fools your clients. I know what the "disconnected" icon means. ;-)

Friday, December 02, 2005

Go Ahead, Hack My LimeWire

I don't normally run LimeWire all the time, because I can't spare the bandwidth, and 3GB a month is not a huge amount if you're sharing a whole bunch of files, so I rarely share any. But this weekend is different: Edward L. Chiarini Jr. has promised me that he'll use the "security flaw" in LimeWire to hack my PC.

You can try it too: use a direct LimeWire connection to mcprog.dyn.isogo.co.za on the standard Gnutella port of 6346. It's wide open, even GRC.com says so. This is what you should find:
(Click on the image for more detail)

But what else will you find? My guess is nothing, because there isn't anything else to see, just the way LimeWire installs things. I don't for one moment deny that stupid people share all their files, but then stupid people do all kinds of other stupid things too. But that isn't a security flaw in LimeWire, isn't it?

Of course, if you really keep looking, you might find part of my credit card number, but only if you look really hard.

Update: in spite of the incoherent ramblings in the comments section, Ed didn't hack my PC. He was unable to say what files were shared on my PC, and the image he provided didn't show them either. Here is his image:



Here is what I was sharing, as seen from another PC:

So if he had connected to my PC, these files would also show up in his picture. Not even the word document showed up, and he knew in advance about that.

See follow-up blog: Abort, Retry, Fail | digg story
| Original News Story | WFAA News Story: Flaws Exposed
| File Not Found; Flaw not Found

LimeWire: FAQ on Security

"Q: Are there security risks associated with using LimeWire?

A: As long as you don't share your entire hard drive, you shouldn't encounter any significant security risks using Gnutella. However, make sure you are sharing only files you want to share, and to be completely safe, don't run executable programs that you obtain from the Gnutella network."

"Q: How do I share my files?

A: LimeWire will automatically share the files you've downloaded. You can also share files in several other ways. First, move files from other folders on your system to your LimeWire shared directory (c:\Program Files\LimeWire\Shared is the default location for the folder on Windows systems). In Windows, you can go to your Library Tab and click the 'Explore' button to open your library in Windows Explorer. Alternately, you can add a directory that you would like to share either by going to 'File>Add Folder to Share' to share while on the 'Library' tab or by adding a shared directory from the 'Tools>Options>Sharing' window. Click on 'Add' to Browse your files. "

Thursday, December 01, 2005

Privacy Policy

Privacy

Black and White Inc respects your privacy.

Any personal information you provide to us including and similar to your name, address, telephone number and e-mail address will not be released, sold, or rented to any entities or individuals outside of Black and White Inc.

Credit card details

Black and White Inc will never ask for Credit Card details and request that you do not enter it on any of the forms on Black and White Inc.

External Sites.

Black and White Inc is not responsible for the content of external internet sites. You are advised to read the privacy policy of external sites before disclosing any personal information.

Cookies

A "cookie" is a small data text file that is placed in your browser and allows Black and White Inc to recognize you each time you visit this site(customisation etc). Cookies themselves do not contain any personal information, and Black and White Inc does not use cookies to collect personal information. Cookies may also be used by 3rd party content providers such as newsfeeds.

Remember The Risks Whenever You Use The Internet

While we do our best to protect your personal information, we cannot guarantee the security of any information that you transmit to Black and White Inc and you are solely responsible for maintaining the secrecy of any passwords or other account information. In addition other Internet sites or services that may be accessible through Black and White Inc have separate data and privacy practices independent of us, and therefore we disclaim any responsibility or liability for their policies or actions.

Please contact those vendors and others directly if you have any questions about their privacy policies.

Harry Potter and the Digital Divide

There is one great mystery about books in general (and audio books in particular) that I truly don't understand.

If I want to read any Harry Potter novel, I need walk only a mile to the nearest bookstore and buy a book. But I get the British copy. If I want to buy the Audio CD, I have to buy the one narrated by Stephen Fry, and it costs a fortune. If I ask for the version by Jim Dale, the answer is a simple but frustrating "NO".

If I want the audio download, I can't buy it without flying to the USA or the UK and purchasing a special iPod with it already loaded. Neither the iPod nor the audio download are available in South Africa, where I live. So I have a simple choice: buy the Jim Dale one on Audio CD from Amazon.com in the hope that they will ship it to me, or download it from a file sharing network for free, albeit illegally.

Then there is the mystery about why some books have different titles in the USA: Why is it "Harry Potter and the Sorcerer's Stone" in the US, but "Harry Potter and the Philosopher's Stone" in the UK? Who are they trying to confuse?

It seems to me that the great Atlantic divide created by book publishers was driven by the steam age, and may have made sense when it was simply uneconomic to ship tons of books across the Atlantic. But what really mystifies me is why this divide persists in electronic publishing. The internet knows very few geographic borders, and certainly it costs no more to send a digital download to any specific geographic location around the globe, yet audio books are bound by the same marketing nonsense that was invented a century or more ago.

Why can authors sell their works to only certain parts of the world? Does the current distribution channel for books and CDs think that its bureaucratic bloat is ever going to compete on a cost-effective basis with independent publishers who can be more profitable by reaching a global audience?

Sony BMG faces the music

Satisfaction shortfall:
"EFF has expressed satisfaction that Sony BMG has taken steps in acknowledging the security risks caused by the CDs with XCP software, including a recall of the infected discs. However, the group maintains the measures still fall short of what Sony needs to do to fix the problems caused to customers. 'Sony BMG has failed entirely to respond to concerns about MediaMax, which affects over 20 million CDs--10 times the number of CDs as the XCP software,' EFF declared."

Wouln't it be great if the EFF managed to force Sony to stop copy protection of CDs altogether?