You are here: silicon.com > Software > Security Strategy

Security Strategy

Security flaws make innocent users into file-swappers

Gnutella spreads the word

Tags: gnutella, flaw, file-swapping, security

By CNET Asia Staff

Published: 3 October 2003 09:29 GMT

Security flaws in internet file-sharing networks could incriminate innocent users, according to a research paper.

The anonymous paper - Entrapment: Incriminating Peer to Peer Network Users - detailed several methods that could be used to trick unknowing users into downloading copyrighted files and host them, reported New Scientist.

The Gnutella network would show that the innocent user is sharing copyrighted files, if network messages that usually rely on users to pass on requests for data stored on users' computers are manipulated, said the report.

The Gnutella network is a file sharing network that forms the backbone of a number of popular file-sharing clients including Morpheus and Bearshare.

UK-based P2P programmer Adam Langley said in the report that the Gnutella specific attacks seem reasonable at first glance and the techniques described are not surprising, as Gnutella is not designed to resist such attacks.

Also, it is possible to incriminate an innocent user sending the person a Trojan, as most Windows users would run any old attachment they receive, Langley continued.

Recently, The Recording Industry Association of America (RIAA) withdrew a file-swapping lawsuit after a possible case of mistaken identity.

The RIAA represents the largest US music companies, and has already sued 261 file-sharers who were accused of illegal file swapping through P2P networks, which appear to have reduced activity on the more popular P2P networks, according to a new US research by Nielsen NetRatings, which tracks internet usage.

Leading music file swapping network Kazaa saw a 41 per cent drop in users over the last three months. In the week ending 21 September, traffic fell to about 3.9 million visitors, from 6.5 million in the week that ended on 29 June. Traffic to Morpheus, another network has also dived from 272,000 to 261,000 in the same period, reported news agency Reuters.

On 29 September, several P2P networks unveiled a code of conduct to encourage responsible behaviour among users and asked Congress to find a way record to pay labels and other copyright holders for the data shared online.

Asia-Pacific residents have also been nervously eyeing the recording industry's blitz on file-sharing in the US and asking if this region's users will be the next targets.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Localization Engineer - any European languages

The Software Localisation engineer must have attention to detail and the ability to create and adapt.The Localisation Engineer performs general ...

Localisation Engineer

Identifies and prepares files for localisation. Manages files using version control systems. Generates word counts for files to be translated. ...

Server Management with linux

These services include providing support of the Operating System configuration and associated file systems, log files, processes, problem ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: