LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-05-2006, 01:17 AM   #1
Freemor
Member
 
Registered: Aug 2005
Location: New Brunswick
Distribution: Trisquel
Posts: 70
Blog Entries: 8

Rep: Reputation: 15
ASF wierdness


I just had a interesting evening caused by of all things a (what seems to me) very strangely formated .asf file.

Things unfolded like this..

I was listening to a stream on the net while watching
network traffic with etherape, which I do periodically
to ensure that there isn't any network "wierdness"
going on.

I noticed something trying to connect to 192.168.22.5
which most definitely does not exist in my LAN (o.k.
that counts as wierdness)

after a little digging I tracked it down to the Stream
I had been listening to at the time. When I wget'ted
the asf for the stream it was formated like:

Ref1=http://real.ip.addy/name_of_stream
Ref2=http://192.168.22.5:80/name_of_stream

So after all this rambling my question is What is up with that second Ref. Is this some Windows wierdness I don't know of yet? I can't think of any reason that they would put an internal IP addy in an ASF stream descriptor. Anyboy have some idea of what they are trying to accomplish here??

Thanks in advance
Freemor
 
Old 06-05-2006, 01:39 AM   #2
osor
HCL Maintainer
 
Registered: Jan 2006
Distribution: (H)LFS, Gentoo
Posts: 2,450

Rep: Reputation: 78
I guess it might be an attempt at a virus?

It could also be that the author used buggy software that inadvertently leaked his internal ip.
 
Old 06-05-2006, 09:36 AM   #3
Freemor
Member
 
Registered: Aug 2005
Location: New Brunswick
Distribution: Trisquel
Posts: 70

Original Poster
Blog Entries: 8

Rep: Reputation: 15
Well I certianly hope it isn't a virus attempt as it is coming from a major radio station in Toronto's stream.

I've googled that IP addy and there are some indication's that it is one favoured by Cisco routers. If so and if this is there due to buggy code (does seem to be the type of ASF that is assembled on the fly). They are exposing information that might be useful to malicious hackers. not good.

I'm still wondering if it isn't tied into some other malware/spyware or Windows Media Player weirdness for tracking/demographic reasons.

After having been able to sleep on it and mull it further I'm definitely leaning more to the buggy code side.. as I fail to see how making a media player attampt to connect even a hidden virtual adapter with that address would do much, as the content would have to be on one's computer all ready and, if so, there are most likely far more effective methods of using the content.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
.asf media problems DanTaylor Linux - Newbie 1 05-01-2006 11:07 AM
Mplayer from ASF to MP3 foomanchew Linux - Software 4 12-05-2005 12:51 PM
Convert *.asf to *.mp3 ntwkthtbtch Linux - Software 1 08-27-2004 11:29 PM
Xine and ASF, MOV,... juanix Linux - Software 2 11-29-2003 03:19 PM
mplayer asf streaming Incanus Linux - Software 0 10-01-2003 03:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 06:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration