Slashdot Log In
Worm Transcodes MP3s To Infect PCs
Posted by
kdawson
on Fri Jul 18, 2008 09:34 AM
from the just-don't-click dept.
from the just-don't-click dept.
snydeq writes "Kaspersky Labs has discovered malware that inserts links to malicious Web pages within ASF media files, posing a danger to Windows users who download music files from P2P networks. Infected files launch IE and load a page that asks the user to download a codec. The download, a Trojan horse, installs a proxy program to route other traffic through the PC. The malware also has worm-like qualities, according to Secure Computing. It searches for MP3s, transcodes them to WMA format, wraps them in an ASF container, and adds links to further copies of the malware, all without modifying the .MP3 extension."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
wow, that's evil (Score:5, Funny)
Wow, that's evil, even for malware authors.
Re:wow, that's evil (Score:5, Insightful)
Parent
Re:wow, that's evil (Score:4, Funny)
I want the RIAA to be DEEPLY investigated,prosecuted with a fair trial and a decent hangin'.
The music industry is terminal.It's lashing out in its dying breath.
Just run your antivirus over your downloads before playing.
Let's just go ahead and keep killing the industry so musicians can have a level playing field and we can do away with the corruption and misdirection to mediocre talent it provides.
Parent
Re: (Score:3, Insightful)
Do you really believe this would be effective?
Wouldn't it be more important to run your antivirus on your codecs before installing?
Re: (Score:3, Insightful)
How do you buy music from artists that are represented by the RIAA? Seems to me that most of the money you spend when buying most of the music the RIAA cares about isn't going to the artist in the first place.
Re: (Score:3, Interesting)
Re: (Score:3, Interesting)
Or we could you know,take music back from the evil empire.Music is sound ,sound is free.Performance is work,work is rewarded monetarily.There is no use for a music "industry" except to rip off everyone from the artist all the way to you.
Stealing implies ownership.Music exists as energy independent of ownership.Music uses humans as a gateway to this dimension.Humans may be rewarded for acting as gatways not as owners of intangibles.Copyright is such a joke due to it's distortion
Re:wow, that's evil (Score:5, Funny)
Wow, that's evil, even for malware authors.
That's nothing. I heard the next version will automatically go out the Web, sign up for an e-Trade account, and then proceed to buy stocks like GOOG, AAPL, RHAT, etc., and automatically sell them short.
Parent
Re:wow, that's evil (Score:5, Funny)
It searches for MP3s, transcodes them to WMA format, wraps them in an ASF container
Wow, that's evil, even for malware authors.
That's nothing. You should see the fix. Your anti-virus program will update its definitions, and if it identifies any of these files prior to download, it makes them appear in a Real Audio format so your never tempted to download them to begin with.
Parent
Re:wow, that's evil (Score:5, Funny)
Parent
No the ultimate evil is if... (Score:5, Funny)
Parent
Re:No the ultimate evil is if... (Score:4, Funny)
Parent
Re:wow, that's evil (Score:5, Funny)
Because "WOOSH" sounds better in that format?
Parent
Re:wow, that's evil (Score:4, Informative)
WMA, WMV and ASF are the very same container format. The only difference is the filename extension.
Parent
Re:wow, that's evil (Score:5, Informative)
ASF is the container, WMA is the codec.
WMA can be used to refer to the container [wikipedia.org], but it's actually an ASF container with a WMA track inside.
That's confusing, and basically the file extension refers to the codec, not the container. The WMA or WMV files you download are actually ASF files. It's about as logical as having the DIVX extension for AVIs with DIVX encoding, but hey... who's going to try to change it?
Parent
Re: (Score:3, Informative)
Richard Stallman Says... (Score:4, Funny)
If you'd just used OGG, this never would have happened! ;-)
Re:Richard Stallman Says... (Score:5, Interesting)
We are moving into darker and darker times when it comes to malware. It seems to me that they are trying every evil alternative to make us and our computers to zombies.
How to remember the good old days when we could get the "Your computer is now stoned" or an east german ambulance with sound passing over the screen. Pretty annoying but relatively harmless.
Parent
Gentlemen, (Score:5, Funny)
I must applaud the RIAA on this occasion. I may have mocked their efforts in the past, but this is truly an impressive piece of work, worthy to be called a hack.
Re:Gentlemen, (Score:5, Insightful)
Parent
Nice (Score:5, Insightful)
Way to go Microsoft!
Is there anything these morons can't fuck up?
Re:Nice (Score:5, Informative)
For those of you who think this is just a troll, or are just unfamiliar with ASF:
It's like the ActiveX of multimedia wrapper files. A security nightmare? You bet. Does it still depend on user stupidity? Well, yes.
Parent
Re:Nice (Score:4, Interesting)
Parent
Re:Nice (Score:4, Interesting)
Parent
hidden extensions (Score:5, Insightful)
I hate how Windows has hidden file extensions in every version since XP. It's supposed to make the machine more Mac-like and friendlier, but it is a serious security concern.
I try to turn it off on every machine that I'm asked to setup or fix, but occasionally I get someone who deletes the "unfamiliar" file extensions from their files and ends up not being able to open them.
Parent
Re:hidden extensions (Score:4, Interesting)
Parent
Re:hidden extensions (Score:5, Informative)
Parent
Nothing New... (Score:4, Informative)
Re:Nothing New... (Score:5, Insightful)
You should turn in your geek card for falling for that one! Any site you don't 100% trust that asks you to install a codec for a file format you can play already screams 'malware' in a loud shrill voice.
Parent
Re: (Score:3, Informative)
It means you have A codec that works, and all the player cares is that you have A codec that claims to work. If you can play the file format, you have both a working codec and a codec that the player knows about, so the player isn't going to tell you that you need to download another one.
Any WEBSITE that tells you that you need to download a codec when you already have one for that format is screamin
Re:Nothing New... (Score:5, Informative)
That's actually not true. It's less of an issue with audio file formats, but video file formats can contain video compressed with any number of codecs, and you need the correct codec to play them. For instance, if I can play raw
Any WEBSITE that tells you that you need to download a codec when you already have one for that format is screaming MALWARE,
You are correct that many malware websites use fake codecs to install their malware, but it's just not true that any codec will work for any given file format. Just because you can open the file doesn't mean you have the right codec to view the content. It has nothing to do with the "fastest" or "best" codec. If you don't have the right codec, the video won't play back at all.
Parent
Microsoft only threat? (Score:3, Interesting)
Re:Microsoft only threat? (Score:5, Informative)
Parent
Re: (Score:3, Informative)
yes you did... here right in the first line of your OP
Data vs Program (Score:5, Insightful)
Microsoft has a SERIOUS design pathology. They too often confused "data" with "program." Every G.D. thing in Windows can, in some way, initiate an action. This is a problem.
A "music" file should be data. E-mail should be DATA! This is absolutely crazy. Making everything capable of being interpreted as programmatic content is at best a security flaw.
Re: (Score:3, Insightful)
Computer users (yourself included, me too!) have demanded more automation,
Speak for yourself. I don't want "automation" and most of my family and friends get confused by it, "Hey, why is it doing that?" is the typical response.
they want less user interaction, thus MS and everybody else will develop for these wants.
You are confusing "wanting it to work" and "automation." Clicking, or double clicking, on an icon in a window and having the correct player pop up and play the file correctly is what people want.
What player? (Score:5, Interesting)
I have a feeling this exploit doesn't work in VLC.
A few days ago I played a movie in VLC on a Windows machine and half way through the VLC error log opened and had some interesting things in it. It was trying to place some files into some directories, and then lastly was trying to open a website.
So it wasn't able to do those things, but I can't help shake the feeling that if I had played it in Windows Media Player it would have done some damage. Though it could have also been an exploit for a specific player like Realtime, Xvid, etc..
Disclaimer: I'm not associated with VLC, although I do really like it.
Re: (Score:3, Insightful)
My question is how the hell that works? Why is it even possible to do that!?
Data comes in, gets split into an audio stream and a video stream. You look at the magical tags and figure out which decoder to fire up. Feed compressed data into the decoder, get decompressed data out. Pass the video data to the display pipeline, and the audio data to the audio pipeline.
There should be no way to execute anything from those pipelines.
Re: (Score:3, Informative)
a) ASF is patented, b) by Microsoft. (Score:5, Funny)
So ... I think we can deduce which players are vulnerable to this.
Parent
von Neuman rolls in his grave (Score:5, Insightful)
This is why you separate the executable code from the data.
hmm... (Score:4, Funny)
Good thing I only download FLAC and transcode it myself to mp3... I mean, I buy cds straight from the RIAA for $50 a pop so I can bypass those greedy artists... yeah, that's the ticket...
They're ASF, Not MP3, Files (Score:5, Informative)
The buggy format is not MP3. The MP3 files are perfectly safe.
This worm transcodes them into ASF files. The ASF files are the threat. The ASF files pretend to be safe MP3s, but they include links that Windows automatically opens. MP3 files don't do that.
Of course, it's really Windows that's buggy (duh). Windows allows the worm to enter and run. Windows lets the unsafe ASF files appear to the operator to be safe MP3. Windows opens the ASF links to the bad sites. Windows then runs whatever the bad sites deliver to the browser (which the user could have just clicked to from another page, without the MP3/ASF worm at all, and just blown their system by Web surfing).
But of course, we can't say that Windows and ASF and IE are the security monsters. We have to blame MP3. Even though this exploit requires converting the file into something that's not MP3 before it can get started attacking you.
Re:They're ASF, Not MP3, Files (Score:5, Interesting)
I had to reread because after a once through it seemed there was no risk to me, as I don't download wma/asf. Then I realized it said the extension remains the same. Which makes sense -- I know Windows Media Player will open any supported media type by reading the headers, and double clicking on a file with a media extension will open WMP. So there's your problem -- WMP, not Windows.
Then I also remembered that I'm not using Windows anymore, so I'm safe after all.
Parent
Re: (Score:3, Informative)
This report says that safeguard fails.
The title of this story is "Worm Tran
A bit of clarification? (Score:3, Interesting)
It searches for MP3s, transcodes them to WMA format, wraps them in an ASF container, and adds links to further copies of the malware, all without modifying the .MP3 extension. [emphasis mine]
So if this is correct, I figure one of two things is happening:
1) It renames the file blah.mp3.asf, but if you have extensions hidden, it will hide the 'asf' and show the 'mp3'
or
2) it is an asf named blah.mp3 but when WMP opens the file, WMP says "Who cares what it's named, I can see that this is an ASF so I will go ahead and play it."
Anyone know which it is?
Details on actual Windows Media behavior (Score:5, Interesting)
The original article is rather overblown by the real-world behavior here. I just whipped out a WMA file with a URL marker, renamed it to .mp3, and tried it to see what would happen.
With Windows Media Player 11 installed (out as an optional update for two years for XP, and default in Vista):
Trying to open up an ASF file with a .mp3 extension prompts a dialog reading:
"The file you are attempting to play has an extension (.mp3) that does not match the file format. Playing the file may result in unexpected behavior."
So, if a user opened one of these files, they'd have an immediate warning something was up.
However, if they play the file, nothing will happen if the player is in the stock state. Script commands don't run unless the user has gone into Tools > Options > Security and checked the "Run script commands if present" (which is off by default).
And if a user somehow got one of these modified files AND has ignored the first dialog AND changed the default security option, all they're going to get is a new web page opening up in the default browser, which would then be subject to other security on the machine.
So, current Windows installs appaer to be secure by default against this exploit.
Re: (Score:3, Informative)
Being able to make an asf look like an MP3 is...weird. If true then that is going to spread very quickly.
Re: (Score:3, Informative)
Not really , name the file: mymusicfile.mp3.asf , Windows does the rest for you.
Re:Dont use untrusted codecs! (Score:5, Insightful)
The irony is that in all these years, I don't think I've ever seen WMP successfully find and install a codec it was missing. I just end up with a message saying it couldn't find the codec that doesn't even tell me which codec it was looking for. Then it turns out this all just another malware attack vector.
In 2000, this problem would have "more of the same" but the fact that this still exists in 2008 is insane. I mean Microsoft publicly admitted their security is awful in 2000, took four years to make a decent attempt to correct things, and yet here we are four years after that...
Thanks, Microsoft. Thanks a lot. You give new meaning to word FAIL on a daily basis.
Parent