RIAA must Die. NOW!

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

RIAA must Die. NOW!

Post by Einhander Sn0m4n »

Found these links at www.ZeroPaid.com
http://online.securityfocus.com/archive/1/306476
http://www.neowin.net/forum/index.php?a ... 7&t=59561&
A little letter received by http://Online.Securityfocus.com :
GOBBLES Security Fuckheads wrote:

Code: Select all

-----BEGIN PGP SIGNED MESSAGE-----

___ ___ ___ ___ _ ___ ___ ___ ___ ___ _ _ ___ ___ _______
/ __|/ _ \| _ ) _ ) | | __/ __| / __| __/ __| | | | _ \_ _|_ _\ \ / /
| (_ | (_) | _ \ _ \ |__| _|\__ \ \__ \ _| (__| |_| | /| | | | \ V /
\___|\___/|___/___/____|___|___/ |___/___\___|\___/|_|_\___| |_| |_|
"Putting the honey in honeynet since '98."

Introduction:
Several months ago, GOBBLES Security was recruited by the RIAA (riaa.org)
to invent, create, and finally deploy the future of antipiracy tools. We
focused on creating virii/worm hybrids to infect and spread over p2p nets.
Until we became RIAA contracters, the best they could do was to passively
monitor traffic. Our contributions to the RIAA have given them the power
to actively control the majority of hosts using these networks.

We focused our research on vulnerabilities in audio and video players.
The idea was to come up with holes in various programs, so that we could
spread malicious media through the p2p networks, and gain access to the
host when the media was viewed.

During our research, we auditted and developed our hydra for the following
media tools:
mplayer (www.mplayerhq.org)
WinAMP (www.winamp.com)
Windows Media Player (www.microsoft.com)
xine (xine.sourceforge.net)
mpg123 (www.mpg123.de)
xmms (www.xmms.org)

After developing robust exploits for each, we presented this first part of
our research to the RIAA. They were pleased, and approved us to continue
to phase two of the project -- development of the mechanism by which the
infection will spread.

It took us about a month to develop the complex hydra, and another month to
bring it up to the standards of excellence that the RIAA demanded of us. In
the end, we submitted them what is perhaps the most sophisticated tool for
compromising millions of computers in moments.

Our system works by first infecting a single host. It then fingerprints a
connecting host on the p2p network via passive traffic analysis, and
determines what the best possible method of infection for that host would
be. Then, the proper search results are sent back to the "victim" (not the
hard-working artists who p2p technology rapes, and the RIAA protects). The
user will then (hopefully) download the infected media file off the RIAA
server, and later play it on their own machine.

When the player is exploited, a few things happen. First, all p2p-serving
software on the machine is infected, which will allow it to infect other
hosts on the p2p network. Next, all media on the machine is cataloged, and
the full list is sent back to the RIAA headquarters (through specially
crafted requests over the p2p networks), where it is added to their records
and stored until a later time, when it can be used as evidence in criminal
proceedings against those criminals who think it's OK to break the law.

Our software worked better than even we hoped, and current reports indicate
that nearly 95% of all p2p-participating hosts are now infected with the
software that we developed for the RIAA.

Things to keep in mind:
1) If you participate in illegal file-sharing networks, your
computer now belongs to the RIAA.
2) Your BlackIce Defender(tm) firewall will not help you.
3) Snort, RealSecure, Dragon, NFR, and all that other crap
cannot detect this attack, or this type of attack.
4) Don't fuck with the RIAA again, scriptkids.
5) We have our own private version of this hydra actively
infecting p2p users, and building one giant ddosnet.

Due to our NDA with the RIAA, we are unable to give out any other details
concerning the technology that we developed for them, or the details on any
of the bugs that are exploited in our hydra.

However, as a demonstration of how this system works, we're providing the
academic security community with a single example exploit, for a mpg123 bug
that was found independantly of our work for the RIAA, and is not covered
under our agreement with the establishment.


Affected Software:
mpg123 (pre0.59s)
http://www.mpg123.de


Problem Type:
Local && Remote


Vendor Notification Status:
The professional staff of GOBBLES Security believe that by releasing our
advisories without vendor notification of any sort is cute and humorous, so
this is also the first time the vendor has been made aware of this problem.
We hope that you're as amused with our maturity as we are. ;PpPppPpPpPPPpP


Exploit Available:
Yes, attached below.


Technical Description of Problem:
Read the source.


Credits:
Special thanks to stran9er@openwall.com for the ethnic-cleansing shellcode.
-----BEGIN PGP SIGNATURE-----
Version: Hush 2.2 (Java)
Note: This signature can be verified at https://www.hushtools.com/verify

wlwEARECABwFAj4jBA0VHGdvYmJsZXNAaHVzaG1haWwuY29tAAoJEBzRp5chmbAP4gwA
oKmMyRIxA74KZfAVv3MsEBKCZxRMAJsFFhywKWzMoiT/Qiy4FV+r1inukA==
=OjMp
-----END PGP SIGNATURE-----



[ attachment: (application/octet-stream) ]

-----BEGIN PGP SIGNATURE-----
Version: Hush 2.2 (Java)
Note: This signature can be verified at https://www.hushtools.com/verify

wj8DBQA+IwO0HNGnlyGZsA8RAuusAJ49gGSCJzKlRpn+7b9vd+GYydWzUQCgjq3Ofe2n
WBnlQNf4GeyaFTit5N0=
=RBjc
-----END PGP SIGNATURE-----
As always, Comments, Suggestions, and Flames Are Welcome!
Image Image
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Post by Darth Wong »

Sounds like a joke to me.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

As much as I'd like to go berzerk on another anti-riaa rant....that sounds a little peculiar to me.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Darth Wong wrote:Sounds like a joke to me.
It probably is, but I'm warning my www.SpywareInfo.com friends just the same. Here's a Google Search: GOBBLES Security link for you to peruse. These asshats seem to be a bunch of severely malicious Black Hats posing as Security White Hats.
Image Image
User avatar
Sokar
Jedi Master
Posts: 1369
Joined: 2002-07-04 02:24am

Post by Sokar »

Its got to be a joke, RIAA may be the biggest collection of asshats to ever draw breath, but they have been careful to stay within the letter of the law. If they were to do this, it opens up a can of legal worms so vast as to make copyright infringment seem like childs play.......
BotM
User avatar
Sokar
Jedi Master
Posts: 1369
Joined: 2002-07-04 02:24am

Post by Sokar »

Its got to be a joke, RIAA may be the biggest collection of asshats to ever draw breath, but they have been careful to stay within the letter of the law. If they were to do this, it opens up a can of legal worms so vast as to make copyright infringment seem like childs play.......
BotM
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

OK, I'm going to go out on a limb and mention that only a complete idiot could get infected with this "hydra." The reason?
We focused our research on vulnerabilities in audio and video players.
The idea was to come up with holes in various programs, so that we could
spread malicious media through the p2p networks, and gain access to the
host when the media was viewed.
If you don't do web browsing with Winamp and have blocked it from accessing the Internet with a REAL personal firewall, like Tiny Personal Firewall or... whatever the other one is, this "exploit" cannot access a port on your computer. It's compounded if you have a separate firewall running, like, say, a dedicated Linux firewall/gateway.

Now, on top of that, they can't spread MP3s infected with the virus, for the simple reason that the MPEG Layer 3 standard does not allow for executable code inside the MP3 file. Even if they inserted executable code into the file, it wouldn't run.

Further complicating matters, they claim that this "hydra" works across a broad spectrum of media players. This is bullshit. XMMS works only on *nix systems, specifically those with X. Windows Media Player works only on Windows. Both OSs have completely different structures and vulnerabilities. You cannot develop one single worm that will attack all systems; just try to make a binary that will run on x86, PPC, and RISC platforms. Or a binary that will run under Windows and doesn't require WINE to run under *nix.

Secondly, most p2p clients are also wildly different in structure. KaZaA, while being the most popular, is designed differently from Gnucleus. The two use different networks.

I think I'm going to stop. Needless to say, these guys are just jackasses looking for attention; they even say that attention is ALL they're looking for...
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
AdmiralKanos
Lex Animata
Lex Animata
Posts: 2648
Joined: 2002-07-02 11:36pm
Location: Toronto, Ontario

Post by AdmiralKanos »

I'll bet that the mpg123 exploit they distributed with their message is actually a trojan.
For a time, I considered sparing your wretched little planet Cybertron.
But now, you shall witnesss ... its dismemberment!

Image
"This is what happens when you use trivia napkins for research material"- Sea Skimmer on "Pearl Harbour".
"Do you work out? Your hands are so strong! Especially the right one!"- spoken to Bud Bundy
User avatar
RedImperator
Roosevelt Republican
Posts: 16465
Joined: 2002-07-11 07:59pm
Location: Delaware
Contact:

Post by RedImperator »

Sounds like a "Protocols of the Elders of Zion" type hoax. Make people believe the record company is planting viruses on their computer. Besides, how could they tell whichfiles are legal and which aren't? I've got all six Offspring albums on this computer in MP3 format, and I ripped all of them off CDs that I legally own.
Image
Any city gets what it admires, will pay for, and, ultimately, deserves…We want and deserve tin-can architecture in a tinhorn culture. And we will probably be judged not by the monuments we build but by those we have destroyed.--Ada Louise Huxtable, "Farewell to Penn Station", New York Times editorial, 30 October 1963
X-Ray Blues
User avatar
Frank Hipper
Overfiend of the Superego
Posts: 12882
Joined: 2002-10-17 08:48am
Location: Hamilton, Ohio?

Post by Frank Hipper »

RedImperator wrote:Sounds like a "Protocols of the Elders of Zion" type hoax. Make people believe the record company is planting viruses on their computer. Besides, how could they tell whichfiles are legal and which aren't? I've got all six Offspring albums on this computer in MP3 format, and I ripped all of them off CDs that I legally own.
You deserve infection for owning all six Offspring albums in the first place. :D
Image
Life is all the eternity you get, use it wisely.
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Update: The Register is reporting this story.
Image Image
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Einhander Sn0m4n wrote:Update: The Register is reporting this story.
"He's a funny guy," De Raadt told us. "This is a buffer overflow exploit," he confirmed. De Raadt said he was more concerned by social engineering than by external exploits. "We had Fluffy Bunny, now we have Gobbles. They come in waves. "
That about sums it up. Social engineering.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »


ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

And that means no one will believe this Gobbles asshole again. VICTORY!
Image Image
User avatar
Joe
Space Cowboy
Posts: 17314
Joined: 2002-08-22 09:58pm
Location: Wishing I was in Athens, GA

Post by Joe »

I'm sure this is true, because clearly the RIAA is unfamiliar with what is and is not intentionally tortious activity. :roll:
Image

BoTM / JL / MM / HAB / VRWC / Horseman

I'm studying for the CPA exam. Have a nice summer, and if you're down just sit back and realize that Joe is off somewhere, doing much worse than you are.
HemlockGrey
Fucking Awesome
Posts: 13834
Joined: 2002-07-04 03:21pm

Post by HemlockGrey »

And that means no one will believe this Gobbles asshole again.
Um, you did.
The End of Suburbia
"If more cars are inevitable, must there not be roads for them to run on?"
-Robert Moses

"The Wire" is the best show in the history of television. Watch it today.
User avatar
EmperorMing
Sith Devotee
Posts: 3432
Joined: 2002-09-09 05:08am
Location: The Lizard Lounge

Post by EmperorMing »

I noticed Microshaft's media player in there. I wonder how they are taking this...
Image

DILLIGAF: Does It Look Like I Give A Fuck

Kill your God!
User avatar
beyond hope
Jedi Council Member
Posts: 1608
Joined: 2002-08-19 07:08pm

Post by beyond hope »

Incidental note: there was a price-fixing investigation in progress involving several music distributors and retailers. The fallout from that could hurt the RIAA badly. Even if not, they're slitting their own throats by jacking up the prices of CDs even further (I can't believe when I went to Best Buy the last time: their prices are now up in the $16-17 range where the mall chains USED to be.) They'll price themselves out of existance before long, and wonder what happened.

Idiots. :roll:
User avatar
EmperorMing
Sith Devotee
Posts: 3432
Joined: 2002-09-09 05:08am
Location: The Lizard Lounge

Post by EmperorMing »

beyond hope wrote:Incidental note: there was a price-fixing investigation in progress involving several music distributors and retailers. The fallout from that could hurt the RIAA badly. Even if not, they're slitting their own throats by jacking up the prices of CDs even further (I can't believe when I went to Best Buy the last time: their prices are now up in the $16-17 range where the mall chains USED to be.) They'll price themselves out of existance before long, and wonder what happened.

Idiots. :roll:
I heard about that BS too. Also, did anyone hear of the civil suite that was sent against them concerning the price of a CD and what content is on it?
Image

DILLIGAF: Does It Look Like I Give A Fuck

Kill your God!
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Look at the "Get your free 20$ thread"

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Lord Pounder
Pretty Hate Machine
Posts: 9695
Joined: 2002-11-19 04:40pm
Location: Belfast, unfortunately
Contact:

Post by Lord Pounder »

Frank Hipper wrote:
RedImperator wrote:Sounds like a "Protocols of the Elders of Zion" type hoax. Make people believe the record company is planting viruses on their computer. Besides, how could they tell whichfiles are legal and which aren't? I've got all six Offspring albums on this computer in MP3 format, and I ripped all of them off CDs that I legally own.
You deserve infection for owning all six Offspring albums in the first place. :D
Hey i like The Offspring. They are a misunderstood band.
RIP Yosemite Bear
Gone, Never Forgotten
Post Reply