Did the record industry release peer-to-peer worm?

Would they really stoop so low?

By Robert Lemos, 15 January 2003 11:45

NEWS Claims that the music industry hired a group of hackers to create a worm to infect peer-to-peer networks are being dismissed by security experts. In an advisory posted to security mailing lists, a group called Gobbles Security delivered its latest vulnerability - a real one found in a relatively unknown MP3 player - wrapped in an apparent joke aimed at the Recording Industry Association of America. The main part of the advisory consisted of Gobbles' claims that its programmers had created a 'hydra' - a worm capable of spreading in a variety of ways - that infects all major music software. The RIAA, the organisation that represents major music publishers, wasn't amused. "It's a complete hoax," said an RIAA spokesman, who asked that his name not be used. "It's not true." Security experts agreed. Steve Manzuik, moderator of vulnerability information site VulnWatch, received the advisory on Sunday. But because of the apparent joke, he held the document until the vulnerability was verified a day later. "This is typical Gobbles," Manzuik said. "Cause a stir, but also release useful information." The true vulnerability is not found in the major music players - Windows Media Player, WinAMP and Xmms are among the players Gobbles names - but in the MPG123 music player, a relatively unknown piece of open-source software. Mailing list BugTraq also decided to post the advisory. Oliver Friedrichs, senior manager at computer security firm Symantec, which owns the mailing list, said: "In this case, it contained valid vulnerability details, so we decided to publish it." This is not the first time the RIAA has been a potential target of hacker humour. Over the weekend, unknown hackers hit the organisation's site and replaced some content with false releases. In July, the music industry's website was hit by vandals in an attack that caused the pages to be available only sporadically for four days. The music industry isn't hacking back, but someday it might. A bill sponsored by US Representatives, Howard Berman and Howard Coble would allow copyright owners and such groups as the RIAA and the Motion Picture Association of America to disable, block or otherwise impair a "publicly accessible peer-to-peer file-trading network." What do you think? Should record companies be allowed to 'hack in the name of the law' (see http://www.silicon.com/a55733 for more)? Register a reader comment and have your say. Robert Lemos writes for News.com

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ