"Winamp Glich...Your now a Recording Artist"

Written by Doc~
Released 2.21.02
www.megasecurity.org
This article and the opinions are the sole belief of the author, and not those of the website. The author acknowledges that there maybe some false information, the author releasing everything at this time fully believes everything to be true, and unless proved otherwise, should be taken so. By reading and or distributing this information you the user are responsible for any actions or responses that may occur.

While working on a new article for MegaSecurity. I came across something I thought I should at least acknowledge. I know fairly recently that Microsoft admitted to having the dvd name sent to a server etc etc....
I'm not claiming that at all. I found this interesting and something I know I didn't know. I use winamp as my choice mp3 player. I believe a lot of people do. I had my packet sniffer running because I was looking for packets from a completely different program. But I started to find packets like:

GET /winamp/WA.html?Alb=The%20Original%20Kings%20of%20Comedy&Art=St.%20Lunatics&Cid=winamp&Tid=Soundtrack&Track=King%20In%20This%20City HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-powerpoint,
application/vnd.ms-excel, application/msword, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: info.winamp.com
Connection: Keep-Alive

These packets all went to the same IP. But again something else caught my eye:

GET /html/93117583/700885828/aol?SNM=HIDBF&CT=I&width=100&height=24&target=_blank&TZ=480 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: ar.atwola.com
Connection: Keep-Alive
Cookie: badsnm=HIDBF

These packets went to a completely different IP not even in the same range. The ip when viewed in a webbrowser, redirected too www.aol.com. Whereas the other IP resolved to winamp. This packet is also setting a cookie. I was a lot more interested in this second packet than the first. When the full URL was entered it brought me to a 100x24 brownish button. This button led too http://64.12.184.57/link/93117583/html?badsc=B0sUuRCQ6xEfUxM6FGBh0aAZHKqr4CzktPs_dA-cQGP-gRpo0dGKEYwU7tzN9FrihbDXPBXAw1iLA$ which opened winamp.com in a new window. The source code of this "button" was:

Interesting way of linking to an image. Could just be an encrypted string that decrypt resolves to the regular way to link an image....In conclusion about this second packet is I have_no_idea. I can speculate, but that only gets me in trouble so make what you want of it.

Now back to the first packet. This packet is a very fun packet. To refresh our memory here it is again:
GET /winamp/WA.html?Alb=The%20Original%20Kings%20of%20Comedy&Art=St.%20Lunatics&Cid=winamp&Tid=Soundtrack&Track=King%20In%20This%20City HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-powerpoint,
application/vnd.ms-excel, application/msword, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: info.winamp.com
Connection: Keep-Alive

The full url would be
info.winamp.com/winamp/WA.html?Alb=The%20Original%20Kings%20of%20Comedy&Art=St.%20Lunatics&Cid=winamp&Tid=Soundtrack&Track=King%20In%20This%20City. That is all fine and dandy now if you click here which is the url just mentioned.
Lets repaste the url with some changes...
http://info.winamp.com/winamp/WA.html?Alb=[Album Title goes here]&Art=[Artist(s) name(s)]&Cid=winamp&Tid=&Track=[Song Title]
Lets try this since i have always wanted to be a superstar
http://info.winamp.com/winamp/WA.html?Alb=The%20Megasecurity.org%20Cure&Art=The%20Doc~&Cid=winamp&Tid=&Track=The%20Cure    
(Note I didn't include the word "soundtrack" but that is a keyword, which means there are plenty more I can guess "single" is also a keyword.)
Click here for the new album...

If you have name similar to a star or a stars name like e.g. "brittany" winamp will have links to buy your cd's, (for example they will have a link to brittany spears cds if you put brittany) you can sike your friends out......maybe.

The purpose was to have a good time. I don't know what the urls in the second packet do and there were more similar to that URL. I don't feel like investigating it. Enjoy what you have ;)

No one is perfect if there is false information or spelling and grammatical errors please e mail me and help me correct them I am firmly against false information and have gone to great lengths to verify everything mentioned above        -> E mail -> http://tnt2.ath.cx:5080/kernel32/[email protected]?subject=false info/error
Thanks goes to the following people in no special order:
Cyberfly, M_R, weed, #tnt, skuzlenuts, and ap0calaps. If you have been forgotten I m sure I was having a memory lapse thanks to you too.