
Feb 4th, 2006, 04:39 AM
|
 |
WireNine CEO
|
|
Join Date: Jun 2005
Location: ON, Canada
Posts: 952
Rep Power: 10
|
|
Spyware tunnels in on Winamp flaw
Quote:
A security bug in Winamp is being exploited by miscreants to install spyware on machines running the media player software, experts have warned.
Earlier this week, security companies warned that attack code for exploiting the flaw was circulating on the Internet. On Thursday, Sunbelt Software said it had found a Web site hosting a malicious Winamp playlist file. Opening the file loads spyware onto an unwitting user's PC, it said.
"After surfing to a malicious Web site on our test machines, the file 'x.pls' begins to download," Sunbelt's Adam Thomas wrote in a posting on the anti-spyware software maker's corporate blog. "Almost immediately, Winamp starts to execute the play list and remote code execution begins."
The flaw was disclosed on Monday, when Winamp maker Nullsoft, a division of America Online, released an update to fix it. The company posted version 5.13 of Winamp, while Secunia and other security companies issued alerts about the problem. Secunia rated the issue "extremely critical," its highest rating.
"Not following the recommendation from Nullsoft to upgrade to version 5.13 could result in the extremely nasty CWS Looking-For.Home Search Assistant infection as well as an installation of our good friend SpySheriff," Thomas wrote. Antivirus software is not yet detecting this exploit, he wrote.
|
Read full article here http://news.com.com/Spyware+tunnels+...tml?tag=cd.top
|