Slashdot Mirror


Crackers Tune In to Windows Media Player

jamshedji writes "Crackers are using the newest DRM technology in Microsoft's Windows Media Player to install spyware, adware, dialers and computer viruses on unsuspecting PC users."

28 of 367 comments (clear)

  1. It's like sun on your wedding day? by garcia · · Score: 5, Insightful

    "It's pretty ingenious," said Patrick Hinojasa, chief technical officer at Panda Software. "To take an anti-piracy feature and use it to feed spyware is extremely ironic."

    Not quite ingenious but certainly not ironic. Perhaps if they were loading copyrighted materials such as movies and music onto your machine while you were attempting to download the license for DRM *then* it would be ironic.

    The sad thing is that 99% of Windows users are likely telling WMP to install these licenses automatically when they try to play a media file. It's the "popup addiction" at work. People can't stand popups and anything to get them out of the way for good is they way they want to go.

    This is going to become yet another excuse for trusted computing and single codec repositories. "Look! You are being infected by those bad sites on the Internet! Want protection? Use trusted computing and you'll never have a problem again! Just sign here, here and here. Pay here and connect here. Ahh, isn't that better?"

    1. Re:It's like sun on your wedding day? by UWC · · Score: 4, Interesting
      All WMP versions that I've encountered through the current one have given a choice on whether to enable DRM at install. I've never tried installing with DRM enabled, so I don't know if it would request DRM on all files, or just makes sure to verify DRM on protected files, but with DRM turned off, I've not had a problem with playback of other files or portability of WMP-created media (e.g. CDs I've ripped to WMA. Yeah, I know, I should have used MP3 or Ogg, but CDex wasn't working for me at the time, and I was lazy; I've since rectified the transgressions).

      I wonder how long until you're no longer given the choice to opt out of DRM at install, though.

    2. Re:It's like sun on your wedding day? by SpecBear · · Score: 4, Insightful

      It's not that it's being exploited by genius so much as it was implemented by arrogance. The very nature of DRM software is to conspire with a content provider to use Joe User's computer against him in a way that he cannot circumvent.

      Any DRM implementation is more likely to be exploitable in ways such as this. DRM is more likely to be insecure from the user's standpoint because it's designed from the ground up with somebody else's security as the highest priority. And once the software has been exploited, it has the potential to be highly troublesome because the malicious code now has access to a system that was designed to prevent the owner of the computer from tampering with it. The more effective the DRM is, the more dangerous it is to the user.

      Perhaps I'm being overly paranoid, but I find this to be quite alarming.

  2. It's a bit like IE and activeX except.. by Ckwop · · Score: 5, Insightful

    this time.. we probably wont have the ability to turn it off.

    This will become the new ActiveX.. I can see it already..

    Simon.

    1. Re:It's a bit like IE and activeX except.. by RpiMatty · · Score: 4, Informative

      No, in this case WMP asked to go download and install the codec needed to play the video file.
      When the user clicks yes, then their system becomes infected.
      So if you don't trust the video source, or set WMP to not download codec you will be safe

    2. Re:It's a bit like IE and activeX except.. by dewke · · Score: 4, Informative

      You can turn the "feature" off. The spyware is installed when the player claims it needs a license. The settings for this are on the privacy tab.

      --
      Oderint dum metuant
    3. Re:It's a bit like IE and activeX except.. by notasheep · · Score: 4, Informative

      Actually, it has nothing to do with codecs. It has to do with acquiring a license to play a video file. And you can turn this off if you'd like in WMP. The problem is that most folks have it set to automatically acquire licenses by default.

      --
      Your mind looks a little cramped. Why don't you stretch it a little?
  3. No logic by MarkRose · · Score: 5, Insightful

    One has to wonder why an application whose primary purpose it is to just display data is such a huge vector for infection. What was Microsoft thinking when they made it possible for movies to automatically open URL's and install stuff? Perhaps someone can explain the logic to me.

    --
    Be relentless!
    1. Re:No logic by DavidD_CA · · Score: 5, Informative

      If you RTFA, you'd understand that Windows Media Player attemps to connect to the Internet when a file is played that it doesn't have a valid license for.

      In theory, if you download an MP3 with DRM enabled, Windows Media Player will search your computer for the license. If it doesn't find it, it will go to the URL specified in the MP3. This is part of the DRM spec.

      "Hackers" are just taking advantage of this, creating fake MP3s/MOVs and making those URLs go to junk-infested sites.

      In WMP's defense, it *does* ask you first if you want to go out and hit the site for the DRM license. And once you get there, if you're running SP2 then security is no different than any other mailious website you may visit.

      SP2 should block the popups, and give you a much more informative warning if the site tries to push software onto your computer.

      --
      -David
  4. Crackers like... by NetNifty · · Score: 5, Interesting

    Crackers like the RIAA/MPAA contractor Overpeer?

  5. What's with /. running months old news? by funkdid · · Score: 4, Funny

    Ok I'll admit it. I did a search on Limewire for some "adult" type content. Every single movie I grabbed up tried to get me to install some piece of software in order to watch the movie. 1800fastsearch, etc. I was annoyed that the spyware companies had gotten their tentacles this deep in porn. Those bastards, is nothing sacred?

    --

    I boycott signatures

    1. Re:What's with /. running months old news? by drafalski · · Score: 4, Funny

      tentacles this deep in porn

      Seems like a "5, Funny" joke is lurking in there somewhere...

  6. Re:Unsuspecting??? by garcia · · Score: 5, Insightful

    For those who still don't suspect, you might try Firefox.

    What does Firefox have to do with ending Spyware via WMP? Absolutely nothing. Last time I checked Firefox opened WMP on Windows machines when you attempted to play a media file.

    Hmm.

    Now maybe if you had suggested some little known media player that didn't automatically install codecs after you clicked "don't ask me again, just install" then maybe your post would have been worth something.

    At least RTFA.

  7. Surprise surprise... by tommertron · · Score: 5, Insightful
    Remember when media files used to be safe? When we only needed to worry about files with .exe and .zip and a few others containing viruses or malware? Even before the DRM stuff in Media Player, MS added the ability for video clips to launch web pages. Gee, great idea. Did they never think that people could have exploited that?

    Is it really worth sacrificing the safety of media files so that video players could launch web pages and other code? Another example of Microsoft trying to add usability, whlile sacrificing security. There's no way they couldn't have known about this security flaw.

    --
    Random rants about technology: http://technorants.blogspot.com
  8. Re:Hackers, not Crackers. by DrinkingIllini · · Score: 5, Insightful

    Because as /.ers we know the difference, and these are most certainly crackers, not hackers.

  9. Someone's got to say it by Bronz · · Score: 5, Insightful


    They aren't using Windows Media Player to install spyware. They are using WMP to get users to click on a link that takes them to a webpage where, presumably, the user's browser is compromised.

    Give the proliferation of spyware *without* this new fishing technique, I don't understand the significance of this. People find spyware all by themselves, they don't need any help.

  10. Not only hackers! by EvilCowzGoMoo · · Score: 5, Interesting
    Its not only hackers taking advantage of DRM vulnerabilities. This article at virus.org reports that the RIAA is also exploiting DRM!

    "The contractor Overpeer who works solely for the MPAA and RIAA to polute Peer-to-Peer networks with corrupt and useless files has moved to a new low by using a loop hole within Windows Media DRM to launch popup adds and infect users PCs with Spyware, Viruses and Adware.

    In what could be considered a quite blatent breach of computer crime laws the world over, Overpeer a company owned by Loudeye is making a lot of money seeding Peer-to-Peer networks with thousands of fake files. It's one of the entertainment industry's favourite, and most obnoxious, anti-p2p contractors.

    The loophole in the Windows Media DRM process allows companies to create media files and link them to adware. When you normally download a protected Windows Media file, you also receive a license that lets you play it. If however Windows Media Player cannot find a valid license on your PC, it checks in with a remote system running Microsoft's Windows Media DRM Server.

    You should rarely see that happen. Some files, however are set up to ask you for information before playing. They do this by displaying a URL in a dialog box labeled License Acquisition. Normally that dialog box is used to check for a user name or offer a chance to purchase the file that's being played. In a legitimate DRM-encrypted file the author may let you play it a few times, then bring up a window asking if you want to buy it.

    Since the license dialog box is in essense an Internet Explorer window, it will display whatever is on the page it points to, in the cases that have been seen of this these trojaned Windows Media files, they all point to servers that load up unwanted ads, including windows that attempt install adware onto your PC surreptitiously, including adding items to your browser's Favorites list, attempting to change your home page and installing viral adware such as the 180search Assistant. "

    Acording to the above article's date (December 31, 2004) Is it possible the RIAA inspired the hacker comunity?
  11. Crackers? by deft · · Score: 4, Funny

    Has anyone told Chris Rock that crackers are doing this?
    He'll be pissed.

    --

    There's nothing Intelligent about Intelligent Design.
  12. ...so, when did Firefox become... by lxt · · Score: 5, Insightful

    ...a media player? It's a flaw in Windows Media Player, not (unusual as it is) Internet Explorer.

    So, in other words - use VideoLAN :)

  13. Winamp TV had this problem too by British · · Score: 4, Interesting

    On the Beta Winamp TV stations, adult site operators quickly figured how to launch URLs on video streams. Needless to say, the support forums showed you how to turn off this feature about a day after the discovery.

    Please, not every app in the known world needs to launch a freakin' web page, etc.

  14. Re:No no no, all wrong by RPoet · · Score: 4, Insightful

    I like the variant term Richard Stallman likes to promote: Digital Restrictions Management.

    --
    "Oppression and harassment is a small price to pay to live in the land of the free." -- Montgomery Burns.
  15. True, but sad. by Penguinoflight · · Score: 4, Insightful

    I agree with your trusted computing satement, if Microsoft does acknowlege this incident there will only be more problems. Microsoft has been doing this kind of thing for years, so I dont expect their announcements to suddenly be more honest. I'd be even more surprised if the mass media found the real story instead of propogating microsoft garbage speak. Microsoft has been loosing credibility for several years now, in the future I look for "non-trusted computing" to be EASIER, and more trusted. When consumers see a open market that meets these requirements (and it's already impressive), they'll seriously consider a new platform.

    --
    "And we have seen and do testify that the Father sent the Son to be the Savior of the World"
    1 John 4:14
  16. Re:You know my solution. by jfengel · · Score: 4, Insightful

    Thing is, this is one of those cases that hits Windows more because of the monoculture than directly due to the inherent security flaws or the DRM problem.

    In general "advanced" formats will require downloading software. The fact that the "advance" here is DRM is almost immaterial, except perhaps for the fact that some people believe they're downloading a license rather than software. But Windows asks explicitly if you want to download and install the software. You get a warning, you have to say, "Yeah, I want that piece of malware." The message may not be clear enough, and since there are cases where you do want it you're asking a naive user to make a fairly sophisticated security judgment, but it is there, and the malware can't bypass it. It doesn't need to.

    To my knowledge Linux doesn't have a good solution to that problem, either. If you need software to play that movie/music, it's up to you to verify that the software isn't malware. Linux users escape this problem largely because there aren't enough of them to make it worth the malware writer's effort (as well as the fact that Linux users tend to be better educated and would answer "Hell no!" to the question if asked).

    What's needed here is a security sandbox. Download the codec but don't give it permission to do anything except take stuff from one place in memory and dump it to another, or access a limited direct-to-video API. No network access, no disk access. I'm not aware of any particular Linux security sandbox.

    Microsoft does have its own, in its C#/CLR, though clearly that hasn't made it to the point of writing codecs yet. And it may not, since these are performance-intensive apps and virtual machines impose overhead. I've seen codecs written in Java, and they're tolerable but not what you'd choose.

  17. Better replacement for WMP by m50d · · Score: 5, Informative
    http://sourceforge.net/projects/guliverkli/

    Windows media player like it should be. Low resource usage, plays dvds and any file you have the codecs for installed, without any network access at all. (Unless you're playing a stream or course)

    --
    I am trolling
  18. Simple rule of thumb by karnat10 · · Score: 4, Funny

    This has kept my computer safe and my mind happy for the last twenty years. I don't plan to change it:

    Don't buy products from Microsoft!

    There is one exception: The Microsoft Optical Wheel Mouse is a great product. You can't fuck up a mouse, though.

    Wait, Apple's round one-button mouse.

    Now, that's a deal: Apple could learn from M$ how to design mice, while Steve explains to Bill what an Operating System is.

  19. Trusted Computing Will Make It Worse by ftzdomino · · Score: 5, Insightful

    Trusted computing will make current spyware and worm problems a lot worse.

    As soon as a bug is found in a trusted computing architecture, which WILL happen, things will get a whole lot worse for the average user. Spyware will be created which your hardware refuses to allow you to remove, even with a boot disk or safe mode. Your computer will refuse allow you to install anti-virus and spyware cleaning tools. The spyware will install a certificate with high trust levels for spyware vendors.

    Even if no bug is found, companies like AOL have proven they're willing to sell out their customers by bundling adware with AIM without disclosure. This will likely create an initial hole which can be opened up much wider.

    Issues like this are killing Windows. I learned my lesson a few years ago that almost no shareware or freeware can be trusted. This makes Windows a lot less useful and is one of the many reasons why I usually run linux on my desktop.

    IMHO, trusted computing will only hurt Windows' usability by the average user.

  20. I guess that explains that by AssFace · · Score: 4, Interesting

    I was in NYC on business at the end of last week. The owner of our company had me swing by his apartment while I was in town and he wanted me to setup a wireless network there - which I did.
    As part of the process I was tasked with fixing the 3 XP laptops that were "not working" or "too slow".

    Sure enough, I found that they all had spyware - but one had 52 viruses on it.

    The best part was that his wife (it was her laptop) said to me "oh that is odd because my IT person from work JUST scanned that two days ago - so I hardly think that I got 52 viruses in two days."

    I tried to be polite but essentially told her that she might want to look into getting a better IT person.

    One of the viruses that she had kept spawning instances of the media player and I couldn't figure out why... now I see why I guess.

    (technically some of the viruses were trojans/worms/spyware, so I guess I should just say "malware")

    --

    There are some odd things afoot now, in the Villa Straylight.
  21. This automatic downloading has got to stop by Animats · · Score: 4, Insightful
    It's all Microsoft's fault. They put backdoor IE invocations in everything. And now we're paying the price.

    If you have to run Microsoft, one solution is to back off to Windows 2000. You run Windows 2000. Windows XP runs you. Many corporate installations refuse to go with XP for that reason.

    It's not just Microsoft, either. Remember that DRM-protected CD that changed the firmware on Apple CD drives so the machine would never work again? (And remember Apple refusing to fix it under warranty?)