PDA

View Full Version : Win Amp 2 And Viruses?



seaweed
02-16-2005, 01:54 AM
I have winamp 2.95, ive tried all the other win amps and used v5.3 for a few weeks before changing it,now im back with win amp v2.95 This version just works really well has all the controls and info just as it ought to be. It also works faultlessly with "billy" a small player i use to check my play files for wearable MP3 player.
Neither dose it conflict with Quintisentual player i use when looking at video clips or go on to play files win amp cant.
Every time i use my winamp v2.95 i get a nag screen which tells me v3.00 to v5.00 have faults and are at risk of a virus attack and that i should upgrade to the latest version?? Is v2 at risk?? or only v3 on??

Ive only heard that win amp staff have been downsized, that the creator of winamp has left, and no new update are expected?? so whats the point of useing the newest version?? will it be safe anyway?? Then we might as well go to Quintisental player??

So is my really great win amp v2 at risk of killing my PC?????????????????

locustfurnace
02-16-2005, 06:44 AM
What makes you worry about winamp and viruses? If you run a virus scanner, and don't download programs you are not sure where they came from. Why worry about a virus then?

Tomb
02-16-2005, 12:50 PM
There was a security risk relating to Winamp last year. It was advised that all users moved to Winamp 5.05 at the time.

Just don't use skins!

Flaw With Winamp Could Compromise Enterprise Security. A recently discovered flaw in the popular Winamp multimedia player by AOL subsidiary, Nullsoft is sure to hit a sour note with unfortunate victims. Spyware authors are exploiting the way Winamp loads its graphical themes (skins) for the distribution and infection of PCs.

"We received several reports from users who were hacked after clicking on a link distributed on several IRC (Internet relay chat) channels," said Chaouki Bekrar, a consultant and co-founder of K-Otik.

A representative of America Online said the company had been made aware of the problem but that a fix had not yet been created. "We're looking into the reports and will provide more information, as necessary, at the appropriate time," the representative said.

seaweed
02-19-2005, 11:04 AM
:unsure: i read this from secutity updeate
Winamp 5.x
http://secunia.com/product/3021/

DESCRIPTION:
A vulnerability with an unknown impact has been reported in Winamp.

The vulnerability is reportedly caused due to an error in in_cdda.dll
and can be exploited to cause a buffer overflow.

No more information is currently available.

SOLUTION:
Update to version 5.08c.

PROVIDED AND/OR DISCOVERED BY:
Reported by vendor.

ORIGINAL ADVISORY:
http://forums.winamp.com/showthread.php?s=...threadid=202799 (http://forums.winamp.com/showthread.php?s=&threadid=202799)



------------ <_< what is buffer overflow and why is it a risk?

The Dude
02-19-2005, 12:01 PM
Hey Seaweed,nice seeing you here :)

Your firewall should have defs to block any buffer overflow attempt....I know mine does (Especially for AIM,where those attempts often occur)

Good Luck honey,thank you 4 coming Ashore :)

locustfurnace
02-19-2005, 07:36 PM
A buffer overflow is when a buffer is sent more data than it was designed to handle.
A firewall will not stop a buffer overflow that occurs in userland apps. It could be possible for someone to design a skin or a plugin, which causes buffer overflows by using a exploit in the jpeglib or via the plugin.

With the down-sizing of Winamp&#39;s development staff. it might just be in your best interest to switch to a different program.

seaweed
02-22-2005, 06:05 AM
Hello DUDE&#33;&#33;
I hope so, im useing winamp 2.95 ii like it best of all, i even diabled it and used Quintisentual player which is better than v5.0+ win amp, but win amp 2.95 has all the features and works wonderfully without changing the skin.
Does buffer overload just happen? is there somewhere a program just looking for win amp??And then take over my PC??

locustfurnace
02-22-2005, 06:46 AM
Buffer overloads can happen during normal operations of a program, but it does not happen to often. Someone can design a script, code, plugin, skin to create a security hole in the program. Which is possible could be forced to do a number of things which was not the intent of the app.
You can google the term, which will describe it in more detail.

You could try the Foobar2000 (http://www.foobar2000.org/) audio player, not fancy, but does play most if not all audio formats.