On CBS MoneyWatch: The Real 'Best Colleges' in the U.S.
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dan Ilett
Posted on ZDNet News: Jan 14, 2005 9:57:00 PM

A set of video files available on peer-to-peer networks is piggybacking on Microsoft's antipiracy tools to trick viewers into downloading adware and spyware, security experts have warned.

Spanish security company Panda Software warned earlier this week that several companies are apparently using Microsoft Media Player's digital rights management (DRM) tool to fool people into downloading spyware and viruses. The existence of the files was confirmed by Harvard researcher Ben Edelman.

Microsoft responded Friday, saying that the security risk does not arise from a flaw in its rights management tool, although the issue is triggered by an apparently content-protected file. Content distributors can use Windows Media Player to pop up a Web page with information about a video or song, and in this case, that page was apparently loaded with automatic spyware download mechanisms.

The automatic downloads would be blocked on any computer running the Service Pack 2 release of Windows, Microsoft representatives said. People can also protect PCs running older versions of the operating system by turning up the security settings in Internet Explorer to "high," they added.

"There is no way to automatically force the user to run the malicious software," Microsoft said in an e-mailed statement. "This function is not a security vulnerability in Windows Media Player or DRM."

The appearance of the files on peer-to-peer networks marks a new twist in the old problem of "drive-by downloads," in which companies have used vulnerabilities in the Internet Explorer browser, or simply taken advantage of Web surfers' unfamiliarity with technology, to trick them into downloading abusive software.

The Federal Trade Commission has sued at least one company, run by former spammer Sanford Wallace, for distributing adware and spyware through this kind of Web page mechanism. This is the first time the Microsoft rights management tools have been publicly used to trigger the effect, however.

Panda Software said in an advisory that two versions of the dangerous files are being distributed. However, both are easy to spot once they have run. After connecting to the Internet, they display the message: "Thanks for downloading this file. Click Play to listen."

If someone clicks through the site, spyware is automatically downloaded to the victim's PC, Panda said.

Panda and Harvard researcher Edelman each have identified a small company called Protected Media and file-swap fighter Overpeer as responsible for the Trojan-like Windows Media Player files.

Protected Media did not immediately return calls seeking comment. Overpeer's chief executive officer, Marc Morgenstern, said his company was not responsible for sending any software to people's computers.

Overpeer is hired by record labels and music studios to distribute "decoy" files on file-swapping networks, hoping that potential downloaders will find a false version of the latest Britney Spears single, rather than the real one, for example. In some of those decoys, Overpeer does include code that pops up a Web page window, but Morgenstern said his company's pages simply direct users to an authorized digital song store.

"We're not delivering or serving spyware or viruses," Morgenstern said. "We don't know who did this thing that was mentioned, but it wasn't us."

A Microsoft representative said the software company was continuing to pursue the problem.

"We are concerned, because it is behavior inconsistent with what we would do with our DRM," said Mike Coleman, lead product manager for Microsoft's Windows client consumer division.

Microsoft is planning to release an update to the Windows Media Player that will shut down a file's ability to automatically pop up a Web page, unless the user turns that function on, a representative said.

Dan Ilett of ZDNet UK reported from London.

A set of video files available on peer-to-peer networks is piggybacking on Microsoft's antipiracy tools to trick viewers into downloading adware and spyware, security experts have warned.

Spanish security company Panda Software warned earlier this week that several companies are apparently using Microsoft Media Player's digital rights management (DRM) tool to fool people into downloading spyware and viruses. The existence of the files was confirmed by Harvard researcher Ben Edelman.

Microsoft responded Friday, saying that the security risk does not arise from a flaw in its rights management tool, although the issue is triggered by an apparently content-protected file. Content distributors can use Windows Media Player to pop up a Web page with information about a video or song, and in this case, that page was apparently loaded with automatic spyware download mechanisms.

The automatic downloads would be blocked on any computer running the Service Pack 2 release of Windows, Microsoft representatives said. People can also protect PCs running older versions of the operating system by turning up the security settings in Internet Explorer to "high," they added.

"There is no way to automatically force the user to run the malicious software," Microsoft said in an e-mailed statement. "This function is not a security vulnerability in Windows Media Player or DRM."

The appearance of the files on peer-to-peer networks marks a new twist in the old problem of "drive-by downloads," in which companies have used vulnerabilities in the Internet Explorer browser, or simply taken advantage of Web surfers' unfamiliarity with technology, to trick them into downloading abusive software.

The Federal Trade Commission has sued at least one company, run by former spammer Sanford Wallace, for distributing adware and spyware through this kind of Web page mechanism. This is the first time the Microsoft rights management tools have been publicly used to trigger the effect, however.

Panda Software said in an advisory that two versions of the dangerous files are being distributed. However, both are easy to spot once they have run. After connecting to the Internet, they display the message: "Thanks for downloading this file. Click Play to listen."

If someone clicks through the site, spyware is automatically downloaded to the victim's PC, Panda said.

Panda and Harvard researcher Edelman each have identified a small company called Protected Media and file-swap fighter Overpeer as responsible for the Trojan-like Windows Media Player files.

Protected Media did not immediately return calls seeking comment. Overpeer's chief executive officer, Marc Morgenstern, said his company was not responsible for sending any software to people's computers.

Overpeer is hired by record labels and music studios to distribute "decoy" files on file-swapping networks, hoping that potential downloaders will find a false version of the latest Britney Spears single, rather than the real one, for example. In some of those decoys, Overpeer does include code that pops up a Web page window, but Morgenstern said his company's pages simply direct users to an authorized digital song store.

"We're not delivering or serving spyware or viruses," Morgenstern said. "We don't know who did this thing that was mentioned, but it wasn't us."

A Microsoft representative said the software company was continuing to pursue the problem.

"We are concerned, because it is behavior inconsistent with what we would do with our DRM," said Mike Coleman, lead product manager for Microsoft's Windows client consumer division.

Microsoft is planning to release an update to the Windows Media Player that will shut down a file's ability to automatically pop up a Web page, unless the user turns that function on, a representative said.

Dan Ilett of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 41 Talkback(s)
at least people on crack can run (nt)
nt (Read the rest)
Posted by: linuxoverwindows Posted on: 01/27/05 You are currently: a Guest | | Terms of Use
No flaw in media player..  d_jedi | 01/14/05
Flaw in IE? That depends on.....  JoeMama_z | 01/14/05
heres what i have seen...  linuxoverwindows | 01/15/05
I use a firewall too  JasonL31 | 01/16/05
ie phone home  linuxoverwindows | 01/27/05
what update?  linuxoverwindows | 01/15/05
No Flaw, but they fixed it with SP2?? Yea, right.  DonnieBoy | 01/14/05
What they're saying is...  Michael Kelly | 01/14/05
Well, basically, they are saying they could fix it, but won't  DonnieBoy | 01/14/05
What part do you have trouble understanding  IT Scion | 01/14/05
holding your breath?  linuxoverwindows | 01/15/05
Re: No flaw  X Marks The Spot | 01/14/05
i have SP4  linuxoverwindows | 01/15/05
I tried XP too - then upgraded back to Win2k  JasonL31 | 01/16/05
windows emulators etc  linuxoverwindows | 01/27/05
No Flaw  JakAttak | 01/14/05
Re: No flaw  X Marks The Spot | 01/14/05
Sounds more like phishing (NT)  rapson | 01/14/05
Yeah, and I have...  ReFoRMaT | 01/14/05
Re: No flaws  X Marks The Spot | 01/14/05
okay...reread it  IT Scion | 01/14/05
The hole is in WMP  voska | 01/17/05
It bad enough  chiwawa | 01/15/05
agnitum jammer  linuxoverwindows | 01/15/05
It's about time...  jnaffke@... | 01/15/05
Exactly...  TheCrow_z | 01/15/05
keyword: protection  linuxoverwindows | 01/15/05
No flaws, just M$ "incidental" feature enhancements  drichards1953 | 01/16/05
does it matter if it's a flaw or piggyback  hipparchus2000 | 01/16/05
Yes --  X Marks The Spot | 01/16/05
anyone still use media player  JasonL31 | 01/16/05
I Do  voska | 01/17/05
Here's one you can try.  Yen_z | 01/17/05
Here's an idea  Spoon Jabber | 01/17/05
but... but...  linuxoverwindows | 01/27/05
Of course it's not a flaw....  BitTwiddler | 01/17/05
Microsoft Like An Alcoholic Crack Addict  itanalyst | 01/17/05
at least people on crack can run (nt)  linuxoverwindows | 01/27/05
Neck hurts  Roger Ramjet | 01/18/05
Don't Worry  dstinson_z | 01/18/05
Yes...  MacCanuck | 01/18/05

What do you think?

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
Save time with automated shipping solutions
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Visit the UPS Business Essentials Guide
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline