Forum |  HardWare.fr | News | Articles | PC | S'identifier | S'inscrire | Shop Recherche
3280 connectés 

  FORUM HardWare.fr
  Windows & Software
  Logiciels

  Gros bug avec winamp

 


 Mot :   Pseudo :  
 
Bas de page
Auteur Sujet :

Gros bug avec winamp

n°1694951
cyberP@cal
Posté le 28-08-2004 à 15:49:19  profilanswer
 

Voila que les radio fonctionnais bien et la il y en as plein qui ne marche plus.J'ai install la 5.05 tt remarché,mais suite a un plantage j'ai redemarrer mon pc et voila que sa recommance plus moyen d'ecouter la radio  :fou:  J'ai beau desinstall reinstall parfois sa marche et aprés sa marche plus . Qui sais de quoi ca peut venir ?

mood
Publicité
Posté le 28-08-2004 à 15:49:19  profilanswer
 

n°1695597
fatkiller
Posté le 28-08-2004 à 23:27:51  profilanswer
 

Bonsoir,
 
Ma réponse n'a rien a voir avec ton probleme, mais il y a problème de sécurité avec winamp.
 
Voici la news en Anglais:
-------------------------
Winamp Flaw Allows Hackers  
to Skin Your Computer
Severity: High
26 August, 2004
 
Summary:
Before any security mailing lists got wind of it, personnel from the greyhat Web site K-Otik.com discovered and posted underground exploit code for a new Winamp vulnerability. The vulnerability involves a specially-crafted Winamp skin file that can automatically download and execute code on a victim's computer. By enticing one of your users to a malicious Web page or sending an HTML e-mail, an attacker could deliver his malicious Winamp skin to your user's computer and gain total control of the machine. If you suspect your users have installed Winamp version 5.04 or earlier (whether or not you officially permit it), you should insist that they remove Winamp. For other countermeasures, see the Solution section below.
 
Exposure:
Winamp, a very popular media player that supports and plays more than 30 media file types, is used most commonly to play MP3 files. Although Winamp is not a business application, we've found that many employees install popular client applications like Winamp without authorization. Even if Winamp isn't part of your official corporate desktop image, some of your users probably have it on their systems.
 
Yesterday, a greyhat Web site known as K-Otik.com posted underground exploit code for a new vulnerability that affects Winamp 5.04 and below. Usually we report on vulnerabilities discovered by whitehat security researchers who disclose flaws in order to inform and protect the public. However, in this case a blackhat hacker calling himself |silent released his new Winamp exploit to other malicious hackers on the Internet, specifying that he would not inform Winamp or the security community. Therefore, Winamp users should consider this a high risk vulnerability, since malicious attackers have possessed exploit code before the security community knew of it.  
 
Winamp's popular skinning ability enables customizing the look and feel of the application to fit your tastes. The malicious exploit takes advantage of a design flaw in Winamp's Skin Zip (.wsz) files. These .wsz files usually consist of a zipped archive containing files that fall into two main categories: 1) Media files for customizing Winamp, and 2) XML files that tell Winamp how to apply the media files. However, |silent discovered that he could also embed a malicious program within a Winamp skin file and then craft the XML portion so that Winamp executes it automatically.  
 
Internet Explorer becomes Winamp's unwilling accomplice in this attack. |silent discovered he could create a Web page so that it would automatically download an infected Winamp skin as soon as an Internet Explorer (IE) user visited it. Windows associates .wsz files with Winamp by default. That means a smart attacker could maliciously craft his Web site so that if a victim visits the page, the malicious skin file downloads via IE automatically and executes in Winamp automatically. In sum, one wrong click could give up your machine.  
 
Solution Path:
Since |silent never disclosed this vulnerability directly to Winamp's creators, Nullsoft, there is no patch correcting this flaw (although you can bet Nullsoft knows of this issue by now). We plan on updating this alert if Nullsoft releases a patch.
 
Today, the only way to totally protect yourself from this flaw is to remove Winamp. If you do not allow Winamp in your network, consider taking this opportunity to e-mail your users, citing the Winamp flaw as another example of why they should not install unauthorized programs on company-owned computers.  
 
If you choose to continue using Winamp now, these workarounds can mitigate your exposure to |silent's vulnerability:
 
Dis-associate the .wsz file type in Windows. Doing this prevents you from installing any new Winamp skins automatically. To dis-associate .wsz files from Winamp, open Windows Explorer and click Tools => Folder Options => File Types tab. Scroll down to locate and highlight the WSZ extension type (which appears only if you have Winamp installed). Highlight it, and either click the Delete button to completely remove the WSZ extension type or click the Change button and select some other application, such as Notepad, to opens .wsz files harmlessly.  
Use another browser besides IE to prevent the automatic download of the malicious Winamp skin. This is not a feasible option for everyone. However, other browsers, such as Mozilla Firefox, prompt the users for some interaction before automatically downloading |silent's malicious Winamp skin.
Firebox II, III, X and Vclass users should check below to learn how to block .wsz files by using their WatchGuard proxy services.  
Though WatchGuard does not recommend installing Windows XP Service Pack 2, we did test |silent's exploit under SP2. SP2 includes new secure-browsing features that prevent IE from automatically downloading certain files. With SP2 installed, the malicious Web code |silent uses to download a Winamp skin onto your computer does not work without significant user interaction.

n°1696016
cyberP@cal
Posté le 29-08-2004 à 13:42:15  profilanswer
 

merci mais je connais deja et effectivement sa n'as rien a voir avec mon pb,si qq1 a une idée je suis preneur...

n°1696019
Profil sup​primé
Posté le 29-08-2004 à 13:47:04  answer
 

firewall qui bloque peut etre ...

n°1696236
cyberP@cal
Posté le 29-08-2004 à 17:08:42  profilanswer
 

franck75 a écrit :

firewall qui bloque peut etre ...


 
c'est pas ça non plus... :(

n°1696310
bigdidi300​0
Il n'est pas grand pour rien!
Posté le 29-08-2004 à 18:16:07  profilanswer
 

fatkiller a écrit :

Bonsoir,
 
Ma réponse n'a rien a voir avec ton probleme, mais il y a problème de sécurité avec winamp.
 
Voici la news en Anglais:
-------------------------
Winamp Flaw Allows Hackers  
to Skin Your Computer
Severity: High
26 August, 2004
 
Summary:
Before any security mailing lists got wind of it, personnel from the greyhat Web site K-Otik.com discovered and posted underground exploit code for a new Winamp vulnerability. The vulnerability involves a specially-crafted Winamp skin file that can automatically download and execute code on a victim's computer. By enticing one of your users to a malicious Web page or sending an HTML e-mail, an attacker could deliver his malicious Winamp skin to your user's computer and gain total control of the machine. If you suspect your users have installed Winamp version 5.04 or earlier (whether or not you officially permit it), you should insist that they remove Winamp. For other countermeasures, see the Solution section below.
 
Exposure:
Winamp, a very popular media player that supports and plays more than 30 media file types, is used most commonly to play MP3 files. Although Winamp is not a business application, we've found that many employees install popular client applications like Winamp without authorization. Even if Winamp isn't part of your official corporate desktop image, some of your users probably have it on their systems.
 
Yesterday, a greyhat Web site known as K-Otik.com posted underground exploit code for a new vulnerability that affects Winamp 5.04 and below. Usually we report on vulnerabilities discovered by whitehat security researchers who disclose flaws in order to inform and protect the public. However, in this case a blackhat hacker calling himself |silent released his new Winamp exploit to other malicious hackers on the Internet, specifying that he would not inform Winamp or the security community. Therefore, Winamp users should consider this a high risk vulnerability, since malicious attackers have possessed exploit code before the security community knew of it.  
 
Winamp's popular skinning ability enables customizing the look and feel of the application to fit your tastes. The malicious exploit takes advantage of a design flaw in Winamp's Skin Zip (.wsz) files. These .wsz files usually consist of a zipped archive containing files that fall into two main categories: 1) Media files for customizing Winamp, and 2) XML files that tell Winamp how to apply the media files. However, |silent discovered that he could also embed a malicious program within a Winamp skin file and then craft the XML portion so that Winamp executes it automatically.  
 
Internet Explorer becomes Winamp's unwilling accomplice in this attack. |silent discovered he could create a Web page so that it would automatically download an infected Winamp skin as soon as an Internet Explorer (IE) user visited it. Windows associates .wsz files with Winamp by default. That means a smart attacker could maliciously craft his Web site so that if a victim visits the page, the malicious skin file downloads via IE automatically and executes in Winamp automatically. In sum, one wrong click could give up your machine.  
 
Solution Path:
Since |silent never disclosed this vulnerability directly to Winamp's creators, Nullsoft, there is no patch correcting this flaw (although you can bet Nullsoft knows of this issue by now). We plan on updating this alert if Nullsoft releases a patch.
 
Today, the only way to totally protect yourself from this flaw is to remove Winamp. If you do not allow Winamp in your network, consider taking this opportunity to e-mail your users, citing the Winamp flaw as another example of why they should not install unauthorized programs on company-owned computers.  
 
If you choose to continue using Winamp now, these workarounds can mitigate your exposure to |silent's vulnerability:
 
Dis-associate the .wsz file type in Windows. Doing this prevents you from installing any new Winamp skins automatically. To dis-associate .wsz files from Winamp, open Windows Explorer and click Tools => Folder Options => File Types tab. Scroll down to locate and highlight the WSZ extension type (which appears only if you have Winamp installed). Highlight it, and either click the Delete button to completely remove the WSZ extension type or click the Change button and select some other application, such as Notepad, to opens .wsz files harmlessly.  
Use another browser besides IE to prevent the automatic download of the malicious Winamp skin. This is not a feasible option for everyone. However, other browsers, such as Mozilla Firefox, prompt the users for some interaction before automatically downloading |silent's malicious Winamp skin.
Firebox II, III, X and Vclass users should check below to learn how to block .wsz files by using their WatchGuard proxy services.  
Though WatchGuard does not recommend installing Windows XP Service Pack 2, we did test |silent's exploit under SP2. SP2 includes new secure-browsing features that prevent IE from automatically downloading certain files. With SP2 installed, the malicious Web code |silent uses to download a Winamp skin onto your computer does not work without significant user interaction.


 
ce problème a été réglé dans la versions 5.05....


Aller à :
Ajouter une réponse
  FORUM HardWare.fr
  Windows & Software
  Logiciels

  Gros bug avec winamp

 

Sujets relatifs
gros gros probleme pour xpaspirer un gros topic?
Gros problème avec le bureau[winamp] raccourci chanson suivante/précédente
de gros soucis avec ie et ma connexion[débutant gros besoin d'aide] 2 PBs - Configuration Outpost Firewall
Gros Problème de config avec routeur/point d'accès Linksysgros probleme avec winamp, le son est tout lent , c trop bizare !!
gros pb avec winampGros problème avec winamp
Plus de sujets relatifs à : Gros bug avec winamp


Copyright © 1997-2025 Groupe LDLC (Signaler un contenu illicite / Données personnelles)