Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

iTunes Shared Music hole

p2p news / p2pnet: Fake iTunes Shared Music entries can be created by spoofing fake domain/list names and IP addresses inside an MDNS packet used to broadcast existing lists, says Airscanner Mobile Security Advisory #05101001.

“This spoofing attack can be scripted to post numerous entries to specific or all iTunes users on a network (flooding),” says Seth Fogie, going on:

“By repeated excessive posting of Shared Music Entries, we were able to create a major system load on systems using iTunes.”

Fogie says the DoS risk is low (“Shared Music anonymous forced disconnect”) and list abuse attacks are merely annoying to iTunes users.

But, “ Shared Music lists from various users can be renamed and swapped, thus creating an environment in which you can’t be sure to whom you are connecting.”

Something you think we should know? tips[at]p2pnet.net

See:-
AirscanneriTunes 6.0 Shared Music Denial of Service/Spoofing/Flooding/Abuse, October 10, 2005

HOME

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy