Vulnerability Development mailing list archives

Re: Napster a little insecure?


From: mark () ENTROPYNET COM (Mark Shirley)
Date: Sun, 30 Jan 2000 12:49:27 -0500


it is more likley they it checks for the mp3 header instead of an id3 tag.  all mp3's must have a header.

On Sat, Jan 29, 2000 at 03:52:20PM +0100, Thomas Maschutznig wrote:
There _IS_ some kind of check, which files are being sent..
I've heard of three actually
(dont take this as 100% sure.. PLEASE)

.) As Said below, it checks for ID3-Tags..
I doubt this, as not all MP3s have an ID3Tag and dont HAVE to have one

.) It will only send files with ".mp3" as extension
Sounds ok, and with napster, I never found a file, that didnt have mp3 as
extension

.) Napster only checks in the directory, you specify it to look for MP3s,
you wanna share
Well, would be reasonable to do so ;)

Eagerly waiting for 25 "I-am-currently-on-vacation"-autoreplys,

         T

That may be true but i've once heard that napster doesn't allow the
transfer of the files which don't have ID3 Tag (I haven't tried that)
-- snip --

On Thu, 27 Jan 2000, Dennis Miller wrote:

I'm running Napster v2.0 Build 1318 which is a freeware utility to share
MP3's across
the internet located at http://www.napster.com <http://www.napster.com> .
Notice Napster sends the complete location of the file(s) being sent.  Does
this mean that there is a way to coax the client to offer up ANY file?



Current thread: