[22086] in bugtraq

home help back first fref pref prev next nref lref last post

Re: KaZaA + Morpheus sharing files

daemon@ATHENA.MIT.EDU (Markus Kern)
Thu Aug 2 12:35:14 2001

Message-ID: <3B6939F2.C173A803@gmx.net>
Date: Thu, 02 Aug 2001 13:30:58 +0200
From: Markus Kern <markus-kern@gmx.net>
MIME-Version: 1.0
To: "Hackemate.com.ar" <hackemate@softhome.net>
Cc: vuln-dev@securityfocus.com, bugtraq@securityfocus.com
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit



"Hackemate.com.ar" <hackemate@softhome.net> wrote:

<snip>

> But they are not linked like that, they are:
> 
> http://24.232.8.x:1214/16206/Sting+-+All+ThisTime+%28unplugged%29.mp3
> instead of:
> http://24.232.8.x:1214/Sting+-+All+ThisTime+%28unplugged%29.mp3
> 
The number (16206 here) is probably an index into an internal table
which contains all the shared files. This is actually a Good Thing
because it means that you can only download files that are in the table
in the first place. If implemented correctly it makes directory
traversal
attacks impossible.

Another thing that bothers me about KaZaA is that it downloads its
updates
not from a central server but from other peers on the network. If the
client
doesn't perform any integrity checks on the file it would be trivial to 
serve a trojan as update which would be automatically executed after the
users permission to update KaZaA.

-- Markus Kern

home help back first fref pref prev next nref lref last post