[32900] in bugtraq
Re: Edonkey/Overnet Plugins capable of Virus/Worm behavior
daemon@ATHENA.MIT.EDU (Julian Ashton)
Thu Dec 18 15:12:18 2003
Date: 18 Dec 2003 10:32:01 -0000
Message-ID: <20031218103201.18322.qmail@sf-www1-symnsj.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Julian Ashton <ashton@joltmedia.com>
To: bugtraq@securityfocus.com
In-Reply-To: <20031217225422.GA13131@cs.uoregon.edu>
I am concearned that this is a P2P app with over 1.2 million simulatneous users and that anyone can write a plugin and put it on the network, the plugin CAN self propgate and CAN force overnet/edonkey to perform DDOS attacks. But where is the security that I am looking for? The owners "MetaMachine", I think that all plugins should required to be signed by MetaMachine and checked when loaded. Am I asking too much? I do not want to see this network become a mode of virus propogation.