Feeds

Morpheus fesses up to user lockout security breach

Exchanges insults with former ally KaZaA.com

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

Morpheus has re-instated its file swapping service after ditching support for the P2P stack supplied by developer FastTrack and embracing the Gnutella protocol.

Last week, users unexpectedly found themselves locked out of the MusicCity Morpheus network. The organisation blamed incompatibilities between Morpheus and a fresh release of software provided by FastTrack software, the KaZaA Media Desktop v1.5.

This was not the entire story:

In launching the Gnutella-friendly Morpheus Preview Edition, StreamCast Networks/Morpheus chief executive Steve Griffin admits its servers were hit by a massive Denial of Service attack last week.

"It appears that the attacks included an encrypted message being repeatedly sent directly to your computers that changed registry settings in your computer," a statement by Griffin to users on the accelerated availability of Morpheus Preview Edition states.

"Later, it appears our ad servers were attacked resulting in messages being sent to other sites without our knowledge, which threatened our most basic revenue model."

Postings to the BugTraq security mailing list two weeks ago documented a denial of service exploit on PCs running older versions of the FastTrack P2P stack (prior to KaZaA 1.5), which was used by KaZaA.com and Grokster as well as MusicCity's Morpheus system. Confusingly, this had nothing to do with encrypted messages and referred instead to exhausting the memory available on a client by creating multiple pop-up windows.

Neither MusicCity Morpheus nor Sharman Networks Services, the firm behind KaZaA.com, offered any comment on this pop-up Window DoS problem when we quizzed them about it last week, preferring instead to issue statements on their rift.

This tiff has escalated in recent days with MusicCity describing FastTrack-Kazaa software as a security risk (or a vector for spyware). KaZaa has hit back with a Morpheus migration tool.

Entertainment industry execs - who've been trying to shut both services through the courts - should be pleased with the latest developments. ®

Related stories

Morpheus goes to sleep - users locked out
Morpheus application is 'safe'
KaZaA.com 'evaluates' Dutch court ban
Ala-KaZaA-m!
KaZaA ordered to cease infringing copyright
Napster to ask court to reaffirm Appeal Court ruling
Get your filthy hands off my CDs
RIAA targets post-Napster MP3 sharers
Popular file-share utilities contain Trojans

Security for virtualized datacentres

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
OECD lashes out at tax avoiding globocorps' location-flipping antics
You hear that, Amazon, Google, Microsoft et al?
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.