On BNET: Look like you're working
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dan Ilett
Posted on ZDNet News: Jan 14, 2005 9:57:00 PM

A set of video files available on peer-to-peer networks is piggybacking on Microsoft's antipiracy tools to trick viewers into downloading adware and spyware, security experts have warned.

Spanish security company Panda Software warned earlier this week that several companies are apparently using Microsoft Media Player's digital rights management (DRM) tool to fool people into downloading spyware and viruses. The existence of the files was confirmed by Harvard researcher Ben Edelman.

Microsoft responded Friday, saying that the security risk does not arise from a flaw in its rights management tool, although the issue is triggered by an apparently content-protected file. Content distributors can use Windows Media Player to pop up a Web page with information about a video or song, and in this case, that page was apparently loaded with automatic spyware download mechanisms.

The automatic downloads would be blocked on any computer running the Service Pack 2 release of Windows, Microsoft representatives said. People can also protect PCs running older versions of the operating system by turning up the security settings in Internet Explorer to "high," they added.

"There is no way to automatically force the user to run the malicious software," Microsoft said in an e-mailed statement. "This function is not a security vulnerability in Windows Media Player or DRM."

The appearance of the files on peer-to-peer networks marks a new twist in the old problem of "drive-by downloads," in which companies have used vulnerabilities in the Internet Explorer browser, or simply taken advantage of Web surfers' unfamiliarity with technology, to trick them into downloading abusive software.

The Federal Trade Commission has sued at least one company, run by former spammer Sanford Wallace, for distributing adware and spyware through this kind of Web page mechanism. This is the first time the Microsoft rights management tools have been publicly used to trigger the effect, however.

Panda Software said in an advisory that two versions of the dangerous files are being distributed. However, both are easy to spot once they have run. After connecting to the Internet, they display the message: "Thanks for downloading this file. Click Play to listen."

If someone clicks through the site, spyware is automatically downloaded to the victim's PC, Panda said.

Panda and Harvard researcher Edelman each have identified a small company called Protected Media and file-swap fighter Overpeer as responsible for the Trojan-like Windows Media Player files.

Protected Media did not immediately return calls seeking comment. Overpeer's chief executive officer, Marc Morgenstern, said his company was not responsible for sending any software to people's computers.

Overpeer is hired by record labels and music studios to distribute "decoy" files on file-swapping networks, hoping that potential downloaders will find a false version of the latest Britney Spears single, rather than the real one, for example. In some of those decoys, Overpeer does include code that pops up a Web page window, but Morgenstern said his company's pages simply direct users to an authorized digital song store.

"We're not delivering or serving spyware or viruses," Morgenstern said. "We don't know who did this thing that was mentioned, but it wasn't us."

A Microsoft representative said the software company was continuing to pursue the problem.

"We are concerned, because it is behavior inconsistent with what we would do with our DRM," said Mike Coleman, lead product manager for Microsoft's Windows client consumer division.

Microsoft is planning to release an update to the Windows Media Player that will shut down a file's ability to automatically pop up a Web page, unless the user turns that function on, a representative said.

Dan Ilett of ZDNet UK reported from London.

A set of video files available on peer-to-peer networks is piggybacking on Microsoft's antipiracy tools to trick viewers into downloading adware and spyware, security experts have warned.

Spanish security company Panda Software warned earlier this week that several companies are apparently using Microsoft Media Player's digital rights management (DRM) tool to fool people into downloading spyware and viruses. The existence of the files was confirmed by Harvard researcher Ben Edelman.

Microsoft responded Friday, saying that the security risk does not arise from a flaw in its rights management tool, although the issue is triggered by an apparently content-protected file. Content distributors can use Windows Media Player to pop up a Web page with information about a video or song, and in this case, that page was apparently loaded with automatic spyware download mechanisms.

The automatic downloads would be blocked on any computer running the Service Pack 2 release of Windows, Microsoft representatives said. People can also protect PCs running older versions of the operating system by turning up the security settings in Internet Explorer to "high," they added.

"There is no way to automatically force the user to run the malicious software," Microsoft said in an e-mailed statement. "This function is not a security vulnerability in Windows Media Player or DRM."

The appearance of the files on peer-to-peer networks marks a new twist in the old problem of "drive-by downloads," in which companies have used vulnerabilities in the Internet Explorer browser, or simply taken advantage of Web surfers' unfamiliarity with technology, to trick them into downloading abusive software.

The Federal Trade Commission has sued at least one company, run by former spammer Sanford Wallace, for distributing adware and spyware through this kind of Web page mechanism. This is the first time the Microsoft rights management tools have been publicly used to trigger the effect, however.

Panda Software said in an advisory that two versions of the dangerous files are being distributed. However, both are easy to spot once they have run. After connecting to the Internet, they display the message: "Thanks for downloading this file. Click Play to listen."

If someone clicks through the site, spyware is automatically downloaded to the victim's PC, Panda said.

Panda and Harvard researcher Edelman each have identified a small company called Protected Media and file-swap fighter Overpeer as responsible for the Trojan-like Windows Media Player files.

Protected Media did not immediately return calls seeking comment. Overpeer's chief executive officer, Marc Morgenstern, said his company was not responsible for sending any software to people's computers.

Overpeer is hired by record labels and music studios to distribute "decoy" files on file-swapping networks, hoping that potential downloaders will find a false version of the latest Britney Spears single, rather than the real one, for example. In some of those decoys, Overpeer does include code that pops up a Web page window, but Morgenstern said his company's pages simply direct users to an authorized digital song store.

"We're not delivering or serving spyware or viruses," Morgenstern said. "We don't know who did this thing that was mentioned, but it wasn't us."

A Microsoft representative said the software company was continuing to pursue the problem.

"We are concerned, because it is behavior inconsistent with what we would do with our DRM," said Mike Coleman, lead product manager for Microsoft's Windows client consumer division.

Microsoft is planning to release an update to the Windows Media Player that will shut down a file's ability to automatically pop up a Web page, unless the user turns that function on, a representative said.

Dan Ilett of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 41 Talkback(s)
at least people on crack can run (nt)
nt (Read the rest)
Posted by: linuxoverwindows Posted on: 01/27/05 You are currently: a Guest | | Terms of Use
No flaw in media player..  d_jedi | 01/14/05
Flaw in IE? That depends on.....  JoeMama_z | 01/14/05
heres what i have seen...  linuxoverwindows | 01/15/05
I use a firewall too  JasonL31 | 01/16/05
ie phone home  linuxoverwindows | 01/27/05
what update?  linuxoverwindows | 01/15/05
No Flaw, but they fixed it with SP2?? Yea, right.  DonnieBoy | 01/14/05
What they're saying is...  Michael Kelly | 01/14/05
Well, basically, they are saying they could fix it, but won't  DonnieBoy | 01/14/05
What part do you have trouble understanding  IT Scion | 01/14/05
holding your breath?  linuxoverwindows | 01/15/05
Re: No flaw  X Marks The Spot | 01/14/05
i have SP4  linuxoverwindows | 01/15/05
I tried XP too - then upgraded back to Win2k  JasonL31 | 01/16/05
windows emulators etc  linuxoverwindows | 01/27/05
No Flaw  JakAttak | 01/14/05
Re: No flaw  X Marks The Spot | 01/14/05
Sounds more like phishing (NT)  rapson | 01/14/05
Yeah, and I have...  ReFoRMaT | 01/14/05
Re: No flaws  X Marks The Spot | 01/14/05
okay...reread it  IT Scion | 01/14/05
The hole is in WMP  voska | 01/17/05
It bad enough  chiwawa | 01/15/05
agnitum jammer  linuxoverwindows | 01/15/05
It's about time...  jnaffke@... | 01/15/05
Exactly...  TheCrow_z | 01/15/05
keyword: protection  linuxoverwindows | 01/15/05
No flaws, just M$ "incidental" feature enhancements  drichards1953 | 01/16/05
does it matter if it's a flaw or piggyback  hipparchus2000 | 01/16/05
Yes --  X Marks The Spot | 01/16/05
anyone still use media player  JasonL31 | 01/16/05
I Do  voska | 01/17/05
Here's one you can try.  Yen_z | 01/17/05
Here's an idea  Spoon Jabber | 01/17/05
but... but...  linuxoverwindows | 01/27/05
Of course it's not a flaw....  BitTwiddler | 01/17/05
Microsoft Like An Alcoholic Crack Addict  itanalyst | 01/17/05
at least people on crack can run (nt)  linuxoverwindows | 01/27/05
Neck hurts  Roger Ramjet | 01/18/05
Don't Worry  dstinson_z | 01/18/05
Yes...  MacCanuck | 01/18/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More