


WinAmp Security Hole Discovered, Patched 393
Sbarbero writes "According to Techworld.com, a significant security hole has been discovered in NullSoft's WinAmp, meaning everyone should upgrade to the 5.03 version the makers have just put out right now. Security company NGS has found that the exploit 'can be activated remotely simply by rendering a specially crafted html document' and will run arbitrary code - they have a full advisory on their site." Oddly enough, the vulnerability is in the playback for the classic .XM 'tracker' music format.
Er... (Score:2, Interesting)
Re:Er... (Score:4, Insightful)
Re:Er... (Score:2, Informative)
Re:Er... (Score:5, Informative)
Re:Er... (Score:3, Funny)
Where's my patched 2.9x? (Score:2, Insightful)
Some of us just want an MP3 player - we don't need cpu-hogging visualisations, 100s of "cool" skins, or any of the rest of it.
Time to give some of the other players a try, methinks...
</rant>
Re:Where's my patched 2.9x? (Score:5, Informative)
Winamp 3, on the other hand, is a whole different ball game.
Re:Where's my patched 2.9x? (Score:3, Interesting)
I'm prepared to accept that Winamp 3 was even worse though
Re:Where's my patched 2.9x? (Score:2, Informative)
Re:Where's my patched 2.9x? (Score:3, Interesting)
Re:Where's my patched 2.9x? (Score:2)
I've preferred 2.0x to the 2.9x versions. I are teh uber luddite :)
IIRC, somewhere between 2.09 and 2.91, WinAmp stopped including track lengths when you used "Generate HTML playlist", presumably because track length estimation was nontrivial on certain MP3s with borked VBR headers, etc.
Fun project for tonight - try this exploit on the really old stuff. .MOD is certainly old enough that in_mod.dll might still be in the plugin directory of the old versions.
Shame
Re:Where's my patched 2.9x? (Score:5, Informative)
Delete in_mod.dll from the "Plugins" directory.
Hole: Patched.
Who uses MOD/XM files anymore anyways?
Re:Where's my patched 2.9x? (Score:2)
Re:Where's my patched 2.9x? (Score:5, Informative)
Re:Where's my patched 2.9x? (Score:3, Informative)
Knulla Kuk by Moby (the original Moby!)
Space Debris by Captain
Variations by Jogeir Liljedahl
Capslock by Mick Rippon
Jaunt by Wolfsong
These are just a few of many high-quality tracks that are out there. It's worth giving some a listen sometime!
Re:Where's my patched 2.9x? (Score:3, Informative)
For starters, most GameBoy Advance music is composed in those formats.
Re:Where's my patched 2.9x? (Score:2)
Actually, I do (Score:2)
I haven't *downloaded* any of those files in ages though. Anyone know where one can find good ones?
Re:Where's my patched 2.9x? (Score:3, Informative)
Re:Where's my patched 2.9x? (Score:3, Redundant)
Re:Where's my patched 2.9x? (Score:5, Funny)
You know your media player is too big when all the eye candy slows your older computers to the point they can't play mp3's without choking.
wrong. (Score:5, Informative)
Really? (Score:2)
Really?
Going from the link to Wasabi that you provided, I stumbled upon their license page [wasabidev.org], which specifically says that Winamp 5 uses Wasabi:
"Wasabi is not totally open-source: the core skinning and Maki scripting framework (wasabi.dll) is still closed-source, as it is used in Nullsoft's flagship product Winamp 5."
Obviously, I could just be missing something. But it sure seems like Wasabi is indeed used in Winamp 5.
Re:wrong. (Score:4, Interesting)
Re:wrong. (Score:3, Informative)
And it's not bloated?
Re:wrong. (Score:2, Funny)
Re:wrong. (Score:2)
Re:wrong. (Score:2, Informative)
Re:wrong. (Score:3, Informative)
They ended up making a replacement codec in-house. A lot of people initially complained about the sound quality, but they improved it with every release, and supposedly since 2.666 the rendering bugs have been removed. It sounds great, and performs well.
Re:Where's my patched 2.9x? (Score:2)
Re:Where's my patched 2.9x? (Score:2)
Thank goodness (Score:5, Funny)
Hi from Napster! We've been tracking your listening habits and suggest the following music...Barry Manilow, Air Supply, Leo Sayer. If you act now and buy, we won't tell your friends or neighbors.
What I think everyone wants to know is... (Score:5, Interesting)
Re:What I think everyone wants to know is... (Score:5, Informative)
Systems Affected: Nullsoft Winamp versions 2.91 to 5.02 (possibly older versions, although this is not confirmed)
Re:What I think everyone wants to know is... (Score:2, Insightful)
If for some reason it is impossible to download the updated version of Winamp, the vendor has informed NGSS that it is possible to disable the handling of Fasttracker 2 module files by taking the following steps:
1. Right click the Winamp player, go to 'Options' and then to 'Preferences...'.
2. In the new window which loads, go to 'Plug-ins' and 'Input'.
3. Look for the input plug-in items 'Nullsoft Module Decoder' an
Damnit! (Score:5, Funny)
I am so tired of waiting.
Re:Damnit! (Score:5, Funny)
Doesn't matter. No one will be able to afford it.
Upgrade to foobar instead. (Score:5, Informative)
You can always upgrade to http://www.foobar2000.org/ [foobar2000.org] instead. No more nonstandard interface, a decent mass-tagger, excellent replay-gain support, etc. What's not to like?
Re:Upgrade to foobar instead. (Score:2)
Re:Upgrade to foobar instead. (Score:3, Informative)
Sure there is - From the Foobar2000-> Preferences menu, select Database, and ensure that your mp3 dir is listed in the "Restrict Directories to" box. If you only want specific file types rather than anything foobar can play, restrict file types to *.mp3;*.ogg for example.
Now hit the Scan button and wait a few.
Next up is Components->Album List. Boom boom there ya go. As you add new mp3s to your playlist, if they are in your previously mentioned directories, they will be auto-a
Re:Upgrade to foobar instead. (Score:3, Informative)
WinAmp has plenty not to like about it.. it's just those things tend to be more oriented around it's awful skins and lack of support for all sorts of things I use daily, like playing cuesheets without broken and hac
xm? (Score:2)
Re:xm? (Score:5, Informative)
WinAmp Use (Score:5, Interesting)
Basically, I guess the question is how to make a strong case for WinAmp use. I already sing the praises of Firefox and recommend OpenOffice to folks who don't want/can't shell out $$ for MS Office. I recommend AVG as a free virus-scanner. Same with ZoneAlarm, Spybot S&D, and Ad-Aware. What winning argument do I use to say "use WinAmp instead of..." to Windows users who ask?
Re:WinAmp Use (Score:3, Interesting)
What I will suggest for media playback in general is "Media Player Classic" available at sourceforge. I don't know what the general consensus is here, but for me, it has done what I've asked it to do, and that's good enough for me.
Re:WinAmp Use (Score:2)
Re:WinAmp Use (Score:2)
This is the ugliest web site that I've ever seen! If I didn't know that this was some kind of audio file player software, I never would have known.
I love the part where they say to download the freeware program and then list all of the features of the U-Pay version. From the description, I couldn't determine one difference between the U-Pay and the 'fr
Re:WinAmp Use (Score:2)
The only time I use another media player for anything is mplayer2 for porn, and thats only so I can watch lots at once.
Re:WinAmp Use (Score:2)
WiMP is my player of choice usually since it has easily an easily accessible controls for adjusting brightness, contrast etc. of a video. My monitor is pretty dark for some reason and I always have to boost the brightness in order to see anything. WA5 doesn't have any controls for this as far as
Re:WinAmp Use (Score:2)
I use winamp 5.x primarly for video playback, I find it to work quite well. I can see where you are comming from though... I have another PC and dispite the fact it has a faster CPU... I find that winamp's video play back on it is a touch slugish... I think it's running an ATI rage 128 or some such, where the PC it runs well on is a G-force lame edition.
I also used winamp
Re:WinAmp Use (Score:3, Informative)
I recommend it as an audio player, but I like Media Player Classic for video.
history of Winamp:
http://www.time.com/time/digital/reports / mp3/frank el1.html
Actually I think the fellows who made XMMS wanted a Linux version of Winamp... in fact XMMS skins are the same format as the old winamp skins.
Anyway... I like it well enough... I think it's suffered from bloat since Frankel sold NullSoft to AOL, but it's all good.
Get Winamp 2.X if you want just a good au
Re:WinAmp Use (Score:3, Insightful)
Yes. Winamp was out before XMMS. Actually, XMMS used to be called X11Amp, which was when I first tried it.
Let me tell you, when X11Amp first came out, it wasn't even close to the quality and features that Winamp had. It was the best thing around for Unix MP3 playback though, and it's improved and matured greatly since then.
Re:WinAmp Use (Score:2, Interesting)
some ones i use every day are CTRL + ALT + PG DOWN to forward the track, CTRL + ALT + Down Arrow , to lower volume for when phone rings and CTRL + ALT + Insert to restart a track. there are many others to do basically any function. you can change them to whatever you want as well. Prima
Re:WinAmp Use (Score:2)
It has been ages since I've follwed up [since I'am a] Linuxer (...)
Basically, I guess the question is how to make a strong case for WinAmp use. I already sing the praises of Firefox and recommend OpenOffice to folks who don't want/can't shell out $$ for MS Office. I recommend AVG as a free virus-scanner. Same with ZoneAlarm, Spybot S&D, and Ad-Aware. What winning argument do I use to say "use WinAmp instead of..." to Windows users who ask?
Why would you care ? It's not that there are no Windows users
Re:WinAmp Use (Score:4, Insightful)
It really whips the llama's ass!
Wow (Score:5, Interesting)
I think the only way you can get less bloated is if you used something like mpg123. XMMS is a winamp-clone on linux anyway.
Re:Wow (Score:2)
Re:Wow (Score:2)
You could enqueue with Winamp 2.x.
This is major (Score:2, Funny)
And since winamp uses IE for web page rendering people are used to so high standards for security.
bummer.
I was wondering when it would happen. (Score:2, Informative)
FYI:
Data files as instruments do not really s
Mikamp module (Score:5, Interesting)
Will this bug be updated in mikmod as well ?
I hope that one day, Winamp will drop Mikamp and use Modplug instead, which sources has been released and it the best player on Win32 (mikmod sounds horrible on Windows, and is buggy).
Also modplug plays more formats and is better, although is win32 only;
ModPlug is indeed better. (Score:2)
Re: (Score:2, Informative)
Re:Mikamp module (Score:2)
Great site. They offer "Undies filled with hot fresh cum." I hate sites with undies filled with the cold, stale stuff.
Somebody actually gets paid to write that stuff...
Why are you using Winamp to play XM's anyway? (Score:5, Informative)
Why get this player? So that you can drink deeply from the cup of BBS\Internet history! Check out some [hornet.org] MOD [scene.org] sites [wustl.edu] and dig some chippy goodness!
SHAMELESS PLUG -- Be sure to scope out my MODs [onlinehome.us] as well!
Re:Why are you using Winamp to play XM's anyway? (Score:2)
Don't load in startup (Score:5, Insightful)
Don't have it automatically load at boot. Simple! Next, change your association's to only load the files you want (for example, I don't know _anyone_ that uses Winamp for more then video playing and mp3's, what's with the
Another way to change file associations is to go into Explorer, "Tools" pull down menu, select "Folder Options", click the tab "File Types" and you can delete them from here.
Now this solves the loading problem, if it loads only when you click on your MP3 you don't have to worry about it leaving open ports (this goes for any third party software you don't need running all the time..). Not only will this prevent this sort of attack, but you'll get some freed resources, and a faster boot time, 'to boot'!..
Re:Don't load in startup (Score:2)
Modules are quite popular in the electronic scene, and if you got the right player, usually sound much better than the equivalent MP3.
Plus, if you are into MAKING electronic music, with a module you have the actual SOURCE for it
Re:Don't load in startup (Score:2)
Winamp is a bit tricky with file associations. There's a blanket file type called "Winamp Media File" (or something like that...I'm on my Mac right now so I can't check) which includes all of the file extensions that Winamp handles. If you go into The "Folder Options" it's not as simple as sending mp3 to Winamp, but ogg vorbis to
Re:Don't load in startup (Score:2)
No upgrade required (Score:5, Informative)
Winamp, the vendor has informed NGSS that it is possible to disable the
handling of Fasttracker 2 module files by taking the following steps:
1. Right click the Winamp player, go to 'Options' and then to
'Preferences...'.
2. In the new window which loads, go to 'Plug-ins' and 'Input'.
3. Look for the input plug-in items 'Nullsoft Module Decoder' and double
click it to bring up the 'Nullsoft Module Decoder Preferences' window.
4. Select the 'Fasttracker 2' loader and deselect the 'Enabled' checkbox to
the right of the loaders list.
5. Close all of the option windows and return to the main player.
Third Party Software Sucks (Score:5, Funny)
Crap like this is why you should never use third party software like Winamp. Stick with Microsofts line of quality products and you'll be safe.
Seriously, just look at the time it took to fix this bug. I could almost read the entire headline before the fix. The bug took as long to fix as to read the comma between "Discovered" and "Patched". I expect better from Third Party software.
Until Third Party software is able to show they care about their products I can only recommend that you stick with 100% Microsoft Approved Solutions.
More than a security fix (Score:5, Informative)
Fix for winamp 2.91 (Score:4, Informative)
While you're at it; all the new and updated input plugins (in_mp3, in_midi, etc) seem to work just fine in 2.91.
Just use Foobar2000... (Score:2, Insightful)
you can choose to download and install the open source components (official or third parties) that you want....
this is customization as it should be.
Or just go grab iTunes instead (Score:2)
Fresh from the llama's ass (Score:3, Informative)
Hot off #nullsoft
i don't even think the exploit is in our code
ron, is the exploit in the decoder?
isn't it in mikmod
When is the Mac version of this exploit coming out?
I am so tired of waiting.
hehe
i don't think we even wrote that xm decoder
*** Quit: statsbot (Ping timeout: 180 seconds)
*** Join: DrunkenMaster (DM@adsl-66-159-200-78.dslextreme.com)
`steev: the exploit was in the mikmod library that's used by in_mod for xm decoding
so its not even our code heh
yeah
there you go
it's not even our fault the exploit exists
So this isn't even a winamp bug, it's a mikmod bug.
Fasttracker 2 (Score:2)
I'm no music composer, so expensive packages are but. I just want something to have some fun in the spare time, kinda like FT2, just a bit easier on newer hardware and (Gor forgive-me) that runs under Windows.
Thanks!
Download FreeAmp instead (Score:2)
Yeah, Right (Score:2)
I'm so scared...
Some of this "vulnerability" stuff is getting out of hand.
Reminds me of the Marty Feldman bit where he goes into an insurance broker's office and asks him if he is protected "from falling into a pit of hedge-hogs whilst playing croquet" and "from being struck by a meteorite whilst sun-bathing on the beach?"
Re:Yeah, Right (Score:2)
Regardless, if you use winamp, you should keep it up-to-date. It's not difficult, and it's a good practice for all your software (or at least the ones with free updates).
XM? Classic? Bah! (Score:2)
Bah!
If it's ain't an original
Warning!! Win32 Version is not Stable! (Score:3, Informative)
Vulnerablity or not, I'm going back to the old version.
Dolemite
__________________________
Re:Aha! (Score:3, Informative)
Re:Aha! (Score:5, Informative)
Systems Affected: Nullsoft Winamp versions 2.91 to 5.02 (possibly older versions, although this is not confirmed)
Re:Aha! (Score:2)
Can anyone tell me why I would want to upgrade? It seems to me that every newer version of winamp just gets bigger and slower. All I want it to do is play mp3's, and this version seems to do that just fine...
Re:Aha! (Score:5, Informative)
in requirements:
500MHz Pentium III or comparable
One of the systems that I use winamp on is a Pentium-133 laptop that sits on my entertainment center and plays mp3's thru my stereo.
Why does it take a PIII-500 to play mp3's? It seems to be working fine on the p133 right now. Seems to me like too much extra bloat...
You want 2.81? (Score:3, Informative)
At least they still host it. (you can also s/full/lite in the URL)
Re:You want 2.81? (Score:2)
Re:You want 2.81? (Score:3, Informative)
Link [oldversion.com].
Re:Aha! (Score:4, Interesting)
foobar2000 [foobar2000.org] will serve your needs well. It does everything you could possibly want to do within the realm of playing music, and virtually nothing else. Low memory footprint/CPU requirements, simple and functional GUI (without fancy skins), and very powerful. Check it out.
Re:Aha! (Score:2)
hmmm... looks like Winamp2 isn't available on their site anymore (or at least I didn't dig far enough). Guess I'll have to make sure I keep my installer around
Re:Uhhhh (Score:2)
Re: (Score:2, Troll)
Windows itself costs (Score:2, Informative)
last time I checked WMP didn't cost anything either.
Any program distributed only with Microsoft Windows costs 150 USD or so for a Windows XP Pro OEM license. So does any Win32 program designed to bail if it detects Wine.
Re:Windows itself costs (Score:2)
That's like saying that you have to have a computer to run it as well, so better factor that cost into all the software you get too. Oh, and you have to pay for electricity to run
Re:Upgrade to version 1.45 (Score:2)
Old version of Winamp (Score:2)
http://www.oldversion.com/program.php?n=winamp
Re:Upgrade to version 1.45 (Score:5, Insightful)
Winamp certianly does not have spyware included in it! Real, MusicMatch and others may, but winamp has a very clean reputation. Since they're owned by AOL, an AOL icon is placed on your desktop (although the last time I used it, the installer actually PROMPTED you if you wanted it there!).
Winamp had bloat problems with version 3. It sucked. Everyone who's involved with winamp, even the developers, acknowledge this. Winamp 5 is MUCH better. With 'new' skins enabled, it takes up slightly more than winamp 2 (which didn't support 'new skins). Disabling the skins results in winamp 5 occupying LESS ram than winamp 2. This is quite an accomplishment, as winamp 2 has been around for many years. Any modern windows PC should be able to run it without a problem. Very few programs can make this claim any more.
If your computer can't spare the 5mb or so that winamp5 takes up, you need to consider an upgrade!
Re:Suprise (Gator) (Score:2)
Methinks you better learn how to keep that spyware junk off your system first, before you go blaming programs and people that had absolutely nothing to do with it.