<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Comments on 14448</title>
	<link>http://www.metafilter.com/14448//</link>
	<description>Comments on MetaFilter post Comments on 14448</description>
	<pubDate>Mon, 04 Feb 2002 10:45:04 -0800</pubDate>
	<lastBuildDate>Mon, 04 Feb 2002 10:45:04 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Post number 14448</title>
		<link>http://www.metafilter.com/14448/</link>	
		<description>&lt;a href="http://news.bbc.co.uk/hi/english/sci/tech/newsid_1798000/1798095.stm"&gt;Privacy of MP3 fans at risk&lt;/a&gt; A new security hole has been discovered in one of the world&apos;s most popular file-swapping programs &lt;i&gt;&lt;b&gt;Morpheus&lt;/b&gt;&lt;/i&gt; which could allow anyone to gain private information about its millions of users. </description>
		<guid isPermaLink="false">post:www.metafilter.com,2002:site.14448</guid>
		<pubDate>Mon, 04 Feb 2002 10:34:26 -0800</pubDate>
		<dc:creator>arnab</dc:creator>		<category>morpheus</category>		<category>mp3</category>		<category>filesharing</category>		<category>security</category>
	</item>	<item>
		<title>By: zeoslap</title>
		<link>http://www.metafilter.com/14448/#218434</link>	
		<description>Talk about light on facts, what exactly is this hole supposed to be ?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218434</guid>
		<pubDate>Mon, 04 Feb 2002 10:45:04 -0800</pubDate>
		<dc:creator>zeoslap</dc:creator>
	</item>	<item>
		<title>By: walrus</title>
		<link>http://www.metafilter.com/14448/#218444</link>	
		<description>Tell me, does my &lt;a href=&quot;http://www.zonealarm.com&quot;&gt;firewall&lt;/a&gt; stop this, or not?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218444</guid>
		<pubDate>Mon, 04 Feb 2002 10:49:16 -0800</pubDate>
		<dc:creator>walrus</dc:creator>
	</item>	<item>
		<title>By: aaaaa</title>
		<link>http://www.metafilter.com/14448/#218445</link>	
		<description>apparently old hole, new news.  (and same problem exists with KaZaa and other similarly coded programs)

Basically, instead of accessing the shared Morpheus folders via the Morpheus server, you can just go in via HTTP and port 80 and browse/grab whatever files you want.    It seems that Morpheus brings its own InetServer process and runs that along with its own stuff.  

And Norton/ZoneAlarm don&apos;t necessarily monitor port 80, so you also bypass any firewall protection that the Morpheus server is running on.

There&apos;s more to it, but that&apos;s the gist.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218445</guid>
		<pubDate>Mon, 04 Feb 2002 10:49:55 -0800</pubDate>
		<dc:creator>aaaaa</dc:creator>
	</item>	<item>
		<title>By: ttrendel</title>
		<link>http://www.metafilter.com/14448/#218470</link>	
		<description>Thank God Windows crashes so much. If it didn&apos;t, I might actually think of keeping something valuable on my computer. If anyone wants a buttload of poorly-written college papers, have at it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218470</guid>
		<pubDate>Mon, 04 Feb 2002 11:04:01 -0800</pubDate>
		<dc:creator>ttrendel</dc:creator>
	</item>	<item>
		<title>By: mokey</title>
		<link>http://www.metafilter.com/14448/#218486</link>	
		<description>i think it&apos;s also the fact that some users mistakenly allow the sharing of their entire hard drives. afaik it&apos;s not a bug or exploit (article is v. vague) but users not configuring properly (?). check the thread at slashdot for more conjecture.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218486</guid>
		<pubDate>Mon, 04 Feb 2002 11:28:36 -0800</pubDate>
		<dc:creator>mokey</dc:creator>
	</item>	<item>
		<title>By: walrus</title>
		<link>http://www.metafilter.com/14448/#218499</link>	
		<description>You mean &lt;a href=&quot;http://slashdot.org/article.pl?sid=02/02/03/025221&amp;mode=thread&quot;&gt;this thread&lt;/a&gt;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218499</guid>
		<pubDate>Mon, 04 Feb 2002 11:37:31 -0800</pubDate>
		<dc:creator>walrus</dc:creator>
	</item>	<item>
		<title>By: mokey</title>
		<link>http://www.metafilter.com/14448/#218520</link>	
		<description>aye</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218520</guid>
		<pubDate>Mon, 04 Feb 2002 11:54:26 -0800</pubDate>
		<dc:creator>mokey</dc:creator>
	</item>	<item>
		<title>By: skallas</title>
		<link>http://www.metafilter.com/14448/#218549</link>	
		<description>&lt;i&gt;you can just go in via HTTP and port 80 and browse/grab whatever files you want&lt;/i&gt;

Only the ones that you&apos;ve chosen to shared.  The fears of getting to the root of your drive are unfounded unless you have it set up that way.  If you have enabled c: or d: for sharing then your &quot;my_secret_porn.zip&quot; file has probably already been copied along with your cookies and other goodies through the normal Morpheus client.

Hmm, I think I&apos;m going to go do a search on my secret porn now.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218549</guid>
		<pubDate>Mon, 04 Feb 2002 12:29:51 -0800</pubDate>
		<dc:creator>skallas</dc:creator>
	</item>	<item>
		<title>By: jmd82</title>
		<link>http://www.metafilter.com/14448/#218588</link>	
		<description>Anything that is so private that i wouldn&apos;t want anyone else there to see it, I wouldn&apos;t even put it on my computer.  If someome REALLY wants to break into my computer, more power to them.  But, they won&apos;t find a single useful thing except lots of music and college schit.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218588</guid>
		<pubDate>Mon, 04 Feb 2002 13:18:37 -0800</pubDate>
		<dc:creator>jmd82</dc:creator>
	</item>	<item>
		<title>By: jmd82</title>
		<link>http://www.metafilter.com/14448/#218589</link>	
		<description>Anything that is so private that i wouldn&apos;t want anyone else there to see it, I wouldn&apos;t even put it on my computer.  If someome REALLY wants to break into my computer, more power to them.  But, they won&apos;t find a single useful thing except lots of music and college schit.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218589</guid>
		<pubDate>Mon, 04 Feb 2002 13:18:58 -0800</pubDate>
		<dc:creator>jmd82</dc:creator>
	</item>	<item>
		<title>By: fuq</title>
		<link>http://www.metafilter.com/14448/#218642</link>	
		<description>Oh, hello, what&apos;s this? encryption? Encrypt all the files I don&apos;t want people to get at. What a novel idea!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218642</guid>
		<pubDate>Mon, 04 Feb 2002 14:14:47 -0800</pubDate>
		<dc:creator>fuq</dc:creator>
	</item>	<item>
		<title>By: mutagen</title>
		<link>http://www.metafilter.com/14448/#218651</link>	
		<description>A few things. It is apparantly port 1214, not port 80. However, if you&apos;ve allowed net access to that port (to get Morpheus or Kazaa to work) with ZoneAlarm or any firewall, it opens that personal web server to the world.

Second, it is only sharing the files and folders you set it to share. Unfortunately for many people, they have shared their entire hard drive. If you don&apos;t think people are that stupid, do a search for some common file that lives in the \windows directory. Most of the hits are people that have way too much of their computer shared via this system.

Gnutella works very similarly, a searching mechanism built on top of a web server. Depending on the client a person is running, you may also be able to connect directly to the web server with a browser and look at files on their hard drive.

This is also an example of very poor reporting. The article originally mentioned that this could be the work of a &apos;worm&apos;. That has since been removed. A look at the /. comments contains the original quote.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2002:site.14448-218651</guid>
		<pubDate>Mon, 04 Feb 2002 14:23:46 -0800</pubDate>
		<dc:creator>mutagen</dc:creator>
	</item>
	</channel>
</rss>
