Results 1 to 12 of 12

Thread: That whacky RIAA is at it again...

  1. #1
    Banned

    Join Date
    Jan 2002
    Location
    Atlanta, Georgia, USA
    Posts
    8,700

    That whacky RIAA is at it again...

    http://www.theregister.co.uk/content/6/28842.html

    Is the RIAA "hacking you back"?
    By Andrew Orlowski in San Francisco
    Posted: 14/01/2003 at 00:29 GMT


    The RIAA is preparing to infect MP3 files in order to audit and eventually disable file swapping, according to a startling claim by hacker group Gobbles. In a posting to the Bugtraq mailing list, Gobbles himself claims to have offered his code to the RIAA, creating a monitoring "hydra".

    "Several months ago, GOBBLES Security was recruited by the RIAA (riaa.org) to invent, create, and finally deploy the future of antipiracy tools. We focused on creating virii/worm hybrids to infect and spread over p2p nets," writes Gobbles.

    "Until we became RIAA contracters [sic], the best they could do was to passively monitor traffic. Our contributions to the RIAA have given them the power to actively control the majority of hosts using these networks."

    Gobbles claims that when a peer to peer host is infected, it catalogs media and sends the information "back to the RIAA headquarters (through specifically crafter requests over the p2p networks) where it is added to their records", and also propagates the exploit to other nodes.

    "Our software worked better than even we hoped, and current reports indicate
    that nearly 95% of all p2p-participating hosts are now infected with the
    software that we developed for the RIAA."

    The "hydra" is uncorroborated.

    Gobbles attached two pieces of code, one of which jinglebellz.c details a frame header exploit for the Linux player mpg123. The code chastises OpenBSD lead Theo de Raadt for failing to checksum the public MP3s (written to celebrate each OpenBSD release). The group has singled out OpenBSD in its previous exploits

    In their presentation to last year's DefCon, the group described itself as "the largest active nonprofit security group in existence (that favors full disclosure)," consisting of 17+ members.

    "They're real, and they're damn good. They have made what appeared to be extremely exaggerated claims in the past, and when mocked, they have demonstrated that they are serious," one security expert familiar with their work, who declined to be named, told The Register.

    "He's a funny guy," De Raadt told us. "This is a buffer overflow exploit," he confirmed. De Raadt said he was more concerned by social engineering than by external exploits. "We had Fluffy Bunny, now we have Gobbles. They come in waves. "

    An exploit of this nature is of dubious legality, right now, but language in Howard Berman's "P2P Piracy Prevention" bill last year legitimizing such exploits was backed by RIAA chief Hilary Rosen:-

    The Berman bill, ensured a copyright owner would not be liable for "disabling, interfering with, blocking, diverting, or otherwise impairing the unauthorized distribution, display, performance, or reproduction of his or her copyrighted work on a publicly accessible peer-to-peer file trading network, if such impairment does not, without authorization, alter, delete, or otherwise impair the integrity of any computer file or data residing on the computer of a file trader." Berman is expected to re-introduce the bill in this Congressional session. ®
    ______________________________________________

    Sounds like war has been declared...

  2. #2
    Admiral Ladogaboy's Avatar
    Join Date
    Jan 2000
    Location
    Hiding amongst the minnows
    Posts
    6,843
    Well, what they are more than likely going to do is catch a bunch of homemakers and teenagers in the act. I would think that the smart people would go back to using ftp or privately controlled hubs.

    *note: Not to imply that all homemakers and teenagers aren't smart.
    It is not enough to merely touch the face of god; you also must open your eyes so that you may see your palm.

  3. #3
    shibuya girl
    Join Date
    Apr 2000
    Location
    Oregon
    Posts
    6,855
    gee, i wonder how long those buffer overflows will remain now that thy know about it.

  4. #4
    the lemonizer sho.gun's Avatar
    Join Date
    Apr 2001
    Location
    Calabasas, CA
    Posts
    5,374
    Here's the original letter from Gobbles:

    http://online.securityfocus.com/arch...1/2003-01-17/2

  5. #5
    dunno if any of you caught it, but the RIAA's site was hacked a bit ago, in response... my BF saved the page before they took it down.
    www.detoulous.net/riaa
    Have a groovy day!

  6. #6
    Vice Admiral blueindian's Avatar
    Join Date
    Sep 2002
    Location
    down in the ghetto
    Posts
    4,142
    that's good stuff!
    yeah, pretty much we missed the boat on that one. but it's still here. get you some.

  7. #7
    Admiral molecularfire's Avatar
    Join Date
    Jun 2001
    Location
    Walking through a lemon grove looking for one good orange
    Posts
    6,134
    Actually, this actually increases my opinion of the RIAA. This is a computer problem and should be dealt with over the computers. I've always thought of going to court as a way of whining... if someone pisses you off, kick their rears... It's more honorable that way.
    Disclaimer - The above opinion should not be taken as medical advise. My only advise is to talk to your doctor. If you are stupid enough to take anything I say seriously, you have nobody to blame for your cranio-anal inversion but your stupid self.

    I may not be smart enough to do everything but I am dumb enough to try anything. - Beastboy.

  8. #8
    Commander JackHammer's Avatar
    Join Date
    Jun 2000
    Location
    The Toilet Capital of America
    Posts
    1,328
    Who here is afraid?
    "I'm very sorry for your loss. Your mother was a terribly attractive woman."
    -Royal Tenebaum


    "Oh yeah. Oh yeah. I would do everything to her, I don't care what she looks like. I would wreck that chick."
    -Brian from the Family Guy after Peter asked him whether he would have sex with Lois.

  9. #9
    shibuya girl
    Join Date
    Apr 2000
    Location
    Oregon
    Posts
    6,855
    Ok, I re-read this. This is a load of crap. Not true.

  10. #10
    Commander JackHammer's Avatar
    Join Date
    Jun 2000
    Location
    The Toilet Capital of America
    Posts
    1,328
    But how do you know Revil?
    "I'm very sorry for your loss. Your mother was a terribly attractive woman."
    -Royal Tenebaum


    "Oh yeah. Oh yeah. I would do everything to her, I don't care what she looks like. I would wreck that chick."
    -Brian from the Family Guy after Peter asked him whether he would have sex with Lois.

  11. #11
    shibuya girl
    Join Date
    Apr 2000
    Location
    Oregon
    Posts
    6,855
    Originally posted by JackHammer
    But how do you know Revil?
    I'd like to see you write a worm that works in multiplatform environments being that complex.
    edit: Which also is fit in to a media file that won't break it's standards.
    Last edited by revil; 01-15-2003 at 06:16 PM.

  12. #12
    Commander JackHammer's Avatar
    Join Date
    Jun 2000
    Location
    The Toilet Capital of America
    Posts
    1,328
    I personally can't write any worm. I once did dig some up and fished with them but that's about it.
    "I'm very sorry for your loss. Your mother was a terribly attractive woman."
    -Royal Tenebaum


    "Oh yeah. Oh yeah. I would do everything to her, I don't care what she looks like. I would wreck that chick."
    -Brian from the Family Guy after Peter asked him whether he would have sex with Lois.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •