August 25, 2004 4:36 PM PDT

Digital attacks on Winamp use 'skins' for camouflage

Beware of wolves in llama's clothing.

That's the lesson for Winamp users, after a group of security researchers discovered that spyware makers are using a flaw in the way the multimedia software loads graphical themes, or skins, to infect PCs with their wares. The digital music player--made by America Online subsidiary Nullsoft, whose informal mascot is the llama--improperly allows the skin files to run programs.

The flaw is being used by some spyware makers to infect people's computers with their illicit programs, according to another group of researchers, at French company K-Otik Security. The attack had been used to spread spyware among Internet relay chat users, infecting a computer after the victim clicked on a Web address that appeared in the chat window.

"We received several reports from users who were hacked after clicking on a link distributed on several IRC (Internet relay chat) channels," said Chaouki Bekrar, a consultant and co-founder of K-Otik. Clicking on the link infected the users' computers and sent out additional instant messages, Bekrar said.

The vulnerability is the latest flaw to arrive without warning. Knowledge of such flaws--known in technical circles as zero-day, or 0-day, vulnerabilities--can spread widely before the software developer can even fix the problem. A similar issue in Microsoft's Internet Explorer browser enabled spyware intruders to load software onto the PCs of visitors to an intruder's Web site. The seriousness of the flaw convinced Microsoft to release an early fix for the problem.

A representative of America Online said the company had been made aware of the problem but that a fix had not yet been created. "We're looking into the reports and will provide more information, as necessary, at the appropriate time," the representative said.

Security information provider Secunia rated the vulnerability "extremely critical," its highest rating for software threats, and said the threat extends beyond instant messaging to any skin downloaded through a browser link or e-mail link.

"A malicious Web site using a specially crafted Winamp skin to place and execute arbitrary programs" could take control of a victim's computer, the company said in a Wednesday advisory. "With Internet Explorer, this can be done without user interaction."

But the security site suggests a simple solution to the problem in its advisory: "Use another product."

America Online could be forgiven for not appreciating the advice.

3 comments

Join the conversation!
Add your comment (Log in or register)
It's fine....
Winamp is currently aware of the problem and is working on the next release.

<a class="jive-link-external" href="http://forums.winamp.com/showthread.php?s=&#38;threadid=190902" target="_newWindow">http://forums.winamp.com/showthread.php?s=&#38;threadid=190902</a>

There's no need to "use another product" - but rather then realize that if you click on a link to a .wal file, but the link "points" to a .jpg file... then something's probably wrong.
Posted by (1 comment )
Reply Link Flag
Much needed update for Winamp...
Is support for running as a limited user, not a Power Luser or Admin. There are workarounds, but the product needs full support because it is generally used by kids who are really adept at stumbling into computer hostile environments.
Posted by boomslang (61 comments )
Reply Link Flag
Winamp 5.05 released
This entire issue is now resolved with the newly patched release of Winamp 5.05

<a class="jive-link-external" href="http://www.winamp.com/player" target="_newWindow">http://www.winamp.com/player</a>

Further info:
<a class="jive-link-external" href="http://www.winamp.com/about/article.php?aid=10605" target="_newWindow">http://www.winamp.com/about/article.php?aid=10605</a>
<a class="jive-link-external" href="http://forums.winamp.com/showthread.php?threadid=191604" target="_newWindow">http://forums.winamp.com/showthread.php?threadid=191604</a>
<a class="jive-link-external" href="http://forums.winamp.com/showthread.php?threadid=190902" target="_newWindow">http://forums.winamp.com/showthread.php?threadid=190902</a>
Posted by Dalai Llama (1 comment )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Microsoft (-1.91%) -0.58 30.00
Time Warner (-0.11%) -0.04 37.84
Dow Jones Industrials (-0.24%) -31.07 12,842.97
S&P 500 (-0.37%) -5.06 1,346.71
NASDAQ (-0.45%) -13.25 2,918.14
CNET TECH (-0.55%) -11.20 2,037.94
  Symbol Lookup