Feeds

Old Morpheus still works for unhacked users

P2P networks hack given a fresh twist

  • alert
  • submit to reddit

3 Big data security analytics techniques

Updated Older versions of the Morpheus file sharing utility still work, Register readers have discovered to their surprise.

Earlier this month Music City Morpheus ditched support for the P2P stack supplied by developer FastTrack and embraced the open source Gnutella protocol, with the launch of Morpheus Preview Edition.

The move was accompanied by accusations from Morpheus that its servers had been subject to a denial of service attack, and that messages which changed its users' registry setting had made the service unavailable.

Music City pointed the finger of blame towards KaZaA.com (recently acquired by Sharman Network Services), which like MusicCity's Morpheus and Grokster has licensed the FastTrack P2P stack. MusicCity described FastTrack-KaZaA software as a security risk (or a vector for spyware).

Not so, says FastTrack-KaZaA.

KaZaA founder Niklas Zennstrom told CNet that StreamCast Networks, the firm behind Music City Morpheus, had failed to pay its bills, so the license for its P2P stack was terminated.

Sharman Network Services and KaZaA deny any involvement in the hacking attacks, and Sharman has issued a statement saying KaZaA.com was also subjected to malicious DoS attacks.

On February 28, the KaZaA.com Web site was "bombarded by hundreds of thousands of http requests", which prevented users from accessing the site or downloading KaZaA Media Desktop 1.5 for five hours, it said.

Whoever did it is hard to say, but we've recently received evidence that someone with in-depth knowledge of KaZaA has been playing silly buggers.

Shenanigans

Register reader Haavard Pettersen's recent experiences suggest someone had indeed tampered with people's computers to prevent them from using Morpheus.

When Pettersen tried to use an older version of Morpheus (on a Windows 98 partition), that hasn't been used since before Morpheus went down, he discovered to his surprise that it still worked.

In XP, he couldn't get either old Morpheus or Preview Edition to work, incidentally.

Russ Spooner, a security consultants at Interrorem and former Morpheus user, confirms Pettersen's experience.

"Clearly the FastTrack client part of the software (used in KaZaA, Grokster and Morpheus) has a backdoor in it that allows the knowledgeable few to fire special packets at clients logged into the FastTrack network which will enable them to modify registry settings," Spooner told us.

"It would appear that for a period of time they had effectively a login script sitting on the authentication servers that basically said 'if (client==morpheus ){ modify registry}'," he added.

The offending login script has now been removed, he notes, so now the original clients work fine, "just so long as they were not exposed to the evil pathogen".

Sharman Network Services (which contrary to what we earlier reported only licenses the FastTrack stack) referred our queries on this to KaZaA founder Niklas Zennstrom. We'll fill you on what he says when he gets back to us.

Both Morpheus and KaZaA are embroiled in copyright violation lawsuits brought against them by the music industry. Yesterday StreamCast Networks announced plans to use digital rights management technology called CintoA to protect the copyright of independent artists, while allowing its users to continue sharing free files.

Whether this will appease its critics, such as the Recording Industry Ass. of America and the Motion Picture Ass. of America, seems doubtful. ®

Related stories

Morpheus fesses up to user lockout security breach
Morpheus goes to sleep - users locked out
Morpheus application is 'safe'
KaZaA.com 'evaluates' Dutch court ban
Ala-KaZaA-m!
KaZaA ordered to cease infringing copyright
Napster to ask court to reaffirm Appeal Court ruling
Get your filthy hands off my CDs
RIAA targets post-Napster MP3 sharers
Popular file-share utilities contain Trojans

SANS - Survey on application security programs

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
Red Hat to ship RHEL 7 release candidate with a taste of container tech
Grab 'near-final' version of next Enterprise Linux next week
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.