Spyware tunnels in on Winamp flaw

By Joris Evers, CNET News.com
Monday, February 06, 2006 11:28 AM

A security bug in Winamp is being exploited by miscreants to install spyware on machines running the media player software, experts have warned.

Earlier this week, security companies warned that attack code for exploiting the flaw was circulating on the Internet. Last week, Sunbelt Software said it had found a Web site hosting a malicious Winamp playlist file. Opening the file loads spyware onto an unwitting user's PC, it said.

"After surfing to a malicious Web site on our test machines, the file 'x.pls' begins to download," Sunbelt's Adam Thomas wrote in a posting on the anti-spyware software maker's corporate blog. "Almost immediately, Winamp starts to execute the play list and remote code execution begins."

The flaw was disclosed on Monday, when Winamp maker Nullsoft, a division of America Online, released an update to fix it. The company posted version 5.13 of Winamp, while Secunia and other security companies issued alerts about the problem. Secunia rated the issue "extremely critical," its highest rating.

"Not following the recommendation from Nullsoft to upgrade to version 5.13 could result in the extremely nasty CWS Looking-For.Home Search Assistant infection as well as an installation of our good friend SpySheriff," Thomas wrote. Antivirus software is not yet detecting this exploit, he wrote.

Home Search Assistant might monitor a user's activity and send out confidential information to its creator, according to Sunbelt's threat database. SpySheriff will display a false warning that the computer is infected with spyware. It then tries to persuade the user to buy a SpySheriff product, according to Sunbelt.

Distributors of adware and spyware often exploit security vulnerabilities in programs to get their applications onto PCs. Makers of such software often pay distributors per installation of the adware or spyware.

The Winamp problem affects version 5.12 of the media player. Earlier versions may also be affected. Late last week, the malicious Web site referred to by Sunbelt, 008k.com, appeared to be offline. The site displayed a message: "Site is closed for abuses."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

A look at the Terminal Services Manager in Windows Server 2008

Windows Server

Terminal Services Manager has been around for a while, but Microsoft made some changes to the utility in Windows Server 2008. Here's what you'll find.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web