Worms sing an ode to security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
In a newly discovered computer security scenario, you could get an Internet worm for a song. More precisely, you could get a worm along with a song played on a number of popular Internet media players, including Microsoft's Windows Media Player or RealNetworks' RealPlayer. That's because the players provide the ability to embed Web addresses and scripts -- key ingredients in self-propagating, hostile code. "What we're looking at here is the fact that you can have mobile code now inside of a music file," said Richard Smith, a security consultant. "So you start getting into security problems like macro (viruses) in (Microsoft) Word documents, or ActiveX or JavaScript problems in HTML files. Once you get code inside of a data file, you start having problems." An exploit using music files would rely on a Web browser with a known vulnerability. But reports of the potential problem have raised old concerns about the ability of malicious file-swappers to "poison the pool" of files traded on networks such as Gnutella, MusicCity/Morpheus, Kazaa and other services that have sprung up in Napster's wake. The potential problem gained attention this week after a discussion on the Bugtraq security mailing list. The thread described a music file that, once opened, began spawning pop-up windows advertising a pornographic Web site. In addition to their prurient content, the pop-up windows displayed a potent and potentially hazardous capability of media files to embed scripts, security experts said. One antivirus company, Trend Micro, said it had already fingered the problem, though it remained back-burnered as a theoretical threat. "We are already looking at it," said David Parry, Trend Micro's chief information officer. "It's in the hopper for research." Microsoft and RealNetworks said they were also looking into the problem. "What you're seeing is...an example of the misuse of a legitimate feature," said Michael Aldridge, lead product manager for the Windows Digital Media Division. "We're investigating this issue with our development teams to see what issues we can address. One thing that users can do to protect themselves is avoid downloading files from unknown sources." RealNetworks said it, too, was investigating the issue, but that the problem appears to be a general one for all music files and stems from vulnerabilities in Web browsers, not music players. "The ability to embed JavaScript exists with any URL and is something you can embed in an MP3 file," said Bob Kimball, vice president of legal and business affairs. "Our player doesn't have any independent ability to render JavaScript; we hand that to the browser, which handles JavaScript according to whatever security precautions the user has set up." Security versus functionality
The vulnerability as described by security experts illustrates the classic trade-off between security and functionality. In giving its media player the ability to read scripts and to open Web pages, Microsoft outlines a wide array of potential uses. "Inserting URLs into your digital media files and embedding the Windows Media Player ActiveX control in a Web page results in a powerful, synchronised presentation that is organised and convenient for your audience," reads a Microsoft Web page on the topic. "By using the ActiveX control in a script, you can create a set of framed Web pages. One frame can contain the embedded ActiveX control for playing the audio or video lecture, while another frame displays the synchronised URLs encountered in the digital media stream. The URLs can be links to additional study tools, diagrams, lecture notes, or a quiz available on the Web." Microsoft, long criticised in security circles for prizing new features over security and privacy protections, last month promised to clean up its act and its image with a "Trustworthy Computing" initiative. In addressing the potential media-file vulnerability, Microsoft's Aldridge said the initiative would influence the company's handling of the issue. "We have a renewed commitment at Microsoft to develop trustworthy products," Aldridge said. "This scenario is being included in this process of viewing all functionality through the lens of providing more security and privacy to our users." Online music-sharing network Gnutella was hit by its own worm one year ago, despite assurances from security experts that the music-trading sites were less vulnerable to attack than traditional systems such as email networks. Security experts said the Gnutella outbreak differed fundamentally from the newly described potential problem with regard to script-wielding media files. "This would be an email mass-mailing bomb, something that spreads by mass communications media, as opposed to a file-infecting virus that passes from computer to computer," said Trend Micro's Parry. Don't panic
Other recent media-file security incidents include an anti-file-swapping hack being considered by the Recording Industry Association of America and a hoax that spread false information about an MP3 viral threat. Parry said his company was not scanning media files and would not do so until or unless the problem graduated from a potential threat to a real one. "I refuse to panic when somebody speculates about something like this," Parry said. "There are thousands of known, unexploited potential threats out there. For the time being, this is a theoretical issue, and if it becomes real, go to your antivirus company and there will be something to do after this particular vulnerability shows up." Like Microsoft, RealNetworks advised people concerned about the security threat posed by music files to be wary of their digital music's source. "A lot of people are getting MP3 files from untrusted sources," said Alex Alben, vice president for government affairs at RealNetworks. "They're trading MP3s, getting them from those sites that are operating on P2P (peer-to-peer) file sharing. And I guess there's an element on the Web that's taking advantage of those sources." Microsoft and RealNetworks are collaborating with other companies on separate initiatives to offer digital music on a subscription basis.
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Go to the Security forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

25 seconds ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

4 minutes ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

22 minutes ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

3 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

5 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

5 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

6 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

7 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

8 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

16 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

23 hours ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

23 hours ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

23 hours ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

1 day ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

1 day ago by awbMaven on US indicts Romanian over NASA climate change hack
subhorup

It simultaneously worries me and uplifts me that a self-proclaimed group of internet activists name themselves after Indian mythical figures....

2 days ago by subhorup on Anonymous activists release PCAnywhere source code
naviathan

It's actually far easier to work anonymously on the internet than you think. With tools like Tor bouncing your traffic around the world before...

2 days ago by naviathan on Anonymous activists release PCAnywhere source code
Agnostic_OS

1000272134 and bluedalmatian with you both there but then I'm still in 10.04 land (and happy with it)

2 days ago by Agnostic_OS on Ten factors that make Ubuntu 11.10 a hit
apexwm

Interesting article and definitely see your points on the products mentioned. One of the top products for our Help Desk (approximately 20% of all...

2 days ago by apexwm on Ten flawed products that derail productivity