PDA

View Full Version : Morpheus Security Hole



JAWS
02-06-2002, 05:51 PM
Interesting!

Read on...

Yes. We have confirmed the reports that Morpheus does indeed contain the security hole. Our programmers are working diligently on a fix and we hope to have it ready within the week. We have found that the exploit does in fact allow a malicious user to gain access to the root level of the Morpheus user's C: drive and therefore gain write access to private files on the user's entire system, not just the shared folder.

We have determined that the reason why only some systems are affected, is that the flaw does not seem to work on Windows XP systems. We believe this is due to the fact that XP uses the NTFS file system and has security settings in effect. Windows98, 95, and WinME systems are vulnerable.

(Note: Although it will sometimes run, Morpheus is not recommended for Windows XP due to additional problems with compatibility. WIndows XP compatibility is expected in our future 2.0 release this spring.)

The Kazaa program, and Grokster which share the same code, are also affected. We apologize for any inconvenience this has caused you and we assure you we are working as fast as we can to arrive at a solution. We will post the security fix on the Grokster site where we have posted another security tool, at the following url:
http://www.grokster.com/virusinformation.html

We hope to provide you with the best filesharing program out there and we assure you that we will have the issue taken care of shortly.

Thank you,
-Paul Sarsfield,
Tech Support
MusicCity Morpheus

JBELL
02-06-2002, 09:32 PM
thats why I only use it when i am in front of the comp and never allow the defualt paths ... I always modify them.



then I never leave anything in that directory once it finishes downloading so people NEVER see me and download from me...

JAWS
02-06-2002, 09:36 PM
Originally posted by JBell
thats why I only use it when i am in front of the comp and never allow the defualt paths ... I always modify them.



then I never leave anything in that directory once it finishes downloading so people NEVER see me and download from me...

You got that right! As soon as I saw this, I deleted all the folder's contains! LOL!

(Note: Although it will sometimes run, Morpheus is not recommended for Windows XP due to additional problems with compatibility. Windows XP compatibility is expected in our future 2.0 release this spring.)

I don't understand this; I've never had a problem.

JBELL
02-06-2002, 09:53 PM
Originally posted by JAWS


You got that right! As soon as I saw this, I deleted all the folder's contains! LOL!

(Note: Although it will sometimes run, Morpheus is not recommended for Windows XP due to additional problems with compatibility. Windows XP compatibility is expected in our future 2.0 release this spring.)

I don't understand this; I've never had a problem.

ignore it ... I run software specific to my field of work... that claims to ONLY work on NT4 and have it stable (and faster) on WinME

Smizack
02-07-2002, 06:55 AM
Originally posted by JAWS
Interesting!

We have determined that the reason why only some systems are affected, is that the flaw does not seem to work on Windows XP systems. We believe this is due to the fact that XP uses the NTFS file system and has security settings in effect. Windows98, 95, and WinME systems are vulnerable.



Bah! My XP is fat32 not ntfs. But why are they just now figuring this out? That has been known since Morpheus came out...:confused:

Smizack
02-07-2002, 07:02 AM
Originally posted by JAWS


You got that right! As soon as I saw this, I deleted all the folder's contains! LOL!

(Note: Although it will sometimes run, Morpheus is not recommended for Windows XP due to additional problems with compatibility. Windows XP compatibility is expected in our future 2.0 release this spring.)

I don't understand this; I've never had a problem.

Me either. It's crap, I've been doing it since like July I think, and I've never had a problem with it.

JAWS
02-26-2002, 10:19 PM
I just got a warning; saying my version is too old? I also noticed there were only 66 users online. Weird

JBELL
02-26-2002, 10:31 PM
Originally posted by JAWS
I just got a warning; saying my version is too old? I also noticed there were only 66 users online. Weird

the security hole was a hoax..... and updating it forces you into a new setting that monitors more closly - I am looking for a new prog so I can dump morpheus completely...


watch your firewall when you use morpheus - it is fun! I got pinged and flooded constantly. I dont know how yet though.

Smizack
02-26-2002, 10:51 PM
Originally posted by JBell


the security hole was a hoax..... and updating it forces you into a new setting that monitors more closly - I am looking for a new prog so I can dump morpheus completely...


watch your firewall when you use morpheus - it is fun! I got pinged and flooded constantly. I dont know how yet though.

Don't use Direct Connect. Is sucks the 350lb ass! Everyone talked it up so I used it for a while. It's ok on small files, but good luck getting anything over 10Mgs. And it's s l o w.

JAWS
03-03-2002, 07:18 PM
Has anyone messed around with the new Morpheus Preview Edition?

JBELL
03-03-2002, 07:39 PM
Originally posted by JAWS
Has anyone messed around with the new Morpheus Preview Edition?

hellz no!!!

KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA

Smizack
03-03-2002, 09:12 PM
My Kazaa won't connect either...

JAWS
03-04-2002, 10:47 AM
Originally posted by JBell


hellz no!!!

KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA KAZAA


You're so right! The new Morpheus sucks ass! I switched to KAZAA. :)

JBELL
03-04-2002, 10:51 AM
Originally posted by Smizack
My Kazaa won't connect either...

same here now... DAMN!

*switchign to the 'big red H'*

Smizack
03-04-2002, 10:54 AM
Originally posted by JBell


same here now... DAMN!

*switchign to the 'big red H'*

?? Whatchu talkin 'bout Willis???

JBELL
03-04-2002, 10:55 AM
woohoo I connected look at HALF my mp3 collection that it is sharing...

Smizack
03-04-2002, 10:58 AM
Originally posted by JBell
woohoo I connected look at HALF my mp3 collection that it is sharing...

Ok. Gotcha.

JBELL
03-04-2002, 11:00 AM
Originally posted by Smizack


?? Whatchu talkin 'bout Willis???

big red H - HOTLINE ... the GREATEST file sharring prog ever!!!!

Smizack
03-04-2002, 11:09 AM
Originally posted by JBell


big red H - HOTLINE ... the GREATEST file sharring prog ever!!!!

I gotta try it then. I've been resorting to DC and it sucks!

JBELL
03-04-2002, 11:11 AM
Originally posted by Smizack


I gotta try it then. I've been resorting to DC and it sucks!

what makes it great is - very hard to learn how to use - and it is true peer to peer - NO SERVERS!!! only trackers to locate the peer servers...


PM me later and I will explain what you need to do and I will eventually get a server running on my rig and it has a chat room built in - for instant messaging

Smizack
03-04-2002, 11:16 AM
Originally posted by JBell


what makes it great is - very hard to learn how to use - and it is true peer to peer - NO SERVERS!!! only trackers to locate the peer servers...


PM me later and I will explain what you need to do and I will eventually get a server running on my rig and it has a chat room built in - for instant messaging

Sweet, sounds cool!

JAWS
03-05-2002, 07:02 PM
Originally posted by JBell
woohoo I connected look at HALF my mp3 collection that it is sharing...

I want to know? Does sharing that many files slow your computer?

Smizack
03-05-2002, 07:46 PM
Originally posted by JAWS


I want to know? Does sharing that many files slow your computer?

To an extent. It's not that bad though.. just let it go overnight. To many uploading kills your bandwidth though. That kinda sux.

JAWS
03-06-2002, 06:13 PM
Guys, did you ever download KAZAA Expansion Pack V. 1.5.1? I just wanted to know because I'm getting a pop up saying I should!

JBELL
03-06-2002, 06:32 PM
Originally posted by JAWS
Guys, did you ever download KAZAA Expansion Pack V. 1.5.1? I just wanted to know because I'm getting a pop up saying I should!

*whispers*

spyware!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!

JAWS
03-06-2002, 07:00 PM
Originally posted by JBell


*whispers*

spyware!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!

Thanks man! That's what I thought! :)

Smizack
03-06-2002, 09:10 PM
Originally posted by JBell


*whispers*

spyware!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!

hehe Yup, staying away from that. JBell.. The red h. I can't connec to the dns #'s. says it's been refused..:confused:

JBELL
03-06-2002, 09:25 PM
Originally posted by Smizack


hehe Yup, staying away from that. JBell.. The red h. I can't connec to the dns #'s. says it's been refused..:confused:
gimme a phone number and a time to call on friday - I will talk you through it

Smizack
03-06-2002, 09:33 PM
Originally posted by JBell

gimme a phone number and a time to call on friday - I will talk you through it

Aight... I'm not sure how long I'll be home friday. But I'll let ya know. 1-800 36-24-36

Now I'm gonna have fly chicks callin' me at all times of the night!:rolleyes:

Heh

JAWS
03-06-2002, 09:35 PM
Originally posted by Smizack


Aight... I'm not sure how long I'll be home friday. But I'll let ya know. 580-262-9600

Now I'm gonna have fly chicks callin' me at all times of the night!:rolleyes:

Heh

No, but you might get a prank call or two! :D

Smizack
03-06-2002, 09:40 PM
Originally posted by JAWS


No, but you might get a prank call or two! :D

[jercky boys] Hello? hello? is dis Herman?? HELLO!?[/jerky boys]:p

JAWS
03-06-2002, 09:44 PM
Originally posted by Smizack


[jercky boys] Hello? hello? is dis Herman?? HELLO!?[/jerky boys]:p

LMAO! I remember them! I had a couple of their tapes!

Smizack
03-06-2002, 09:55 PM
Originally posted by JAWS


LMAO! I remember them! I had a couple of their tapes!

I just got back 3 of the cd's I haven't heard them in a while though..

JBELL
03-06-2002, 10:36 PM
Originally posted by Smizack


Aight... I'm not sure how long I'll be home friday. But I'll let ya know. xxx-xxx-xxxx

Now I'm gonna have fly chicks callin' me at all times of the night!:rolleyes:

Heh

ok smizack - any secret code name I should ask for? LOL

and that should have been a PM bro....

Smizack
03-07-2002, 06:50 AM
Originally posted by JBell


ok smizack - any secret code name I should ask for? LOL

and that should have been a PM bro....

Yeah.. I'll have to edit that in a bit.

Code name: Red delta. Then they'll patch you through to our Scandinavian base. I'll be waiting...:D :p :D

JAWS
04-12-2002, 09:34 AM
Has anyone downloaded KaZaA new version 1.6. Or is it spyware?

JBELL
04-12-2002, 09:45 AM
Originally posted by JAWS
Has anyone downloaded KaZaA new version 1.6. Or is it spyware?

I ran a test and had 16 spyware progz from the kazaa install.

JAWS
04-12-2002, 10:01 AM
Originally posted by JBell


I ran a test and had 16 spyware progz from the kazaa install.

Damn, that's what I thought. I almost installed it, but back out. Thanks

JBELL
04-12-2002, 10:03 AM
Originally posted by JAWS


Damn, that's what I thought. I almost installed it, but back out. Thanks

I uninstalled and now kazaa wont run becuase i uninstalled an ''important'' file needed for it to run.

JAWS
04-12-2002, 10:34 AM
Originally posted by JBell


I uninstalled and now kazaa wont run becuase i uninstalled an ''important'' file needed for it to run.

That’s happen to me twice in the last week. I narrowed it down to something I'm deleting in Ad-Ware. I just download it again.

Smizack
04-12-2002, 10:36 AM
I have a hack for that, to remove the spyware and the ad. It makes it the like version. I'll post it when I get home.