User User name Password  
   
Saturday 4.7.2009 / 09:15 AM
Search:        In English   Suomeksi   På svenska
afterdawn.com > news > security hole discovered in y! music unlimited
Show topics
News
News

Security hole discovered in Y! Music Unlimited

30 May 2005 19:29 by James "Dela" Delahunty | 6 comments

Security hole discovered in Y! Music Unlimited Robert Chapin, owner of Chapin Information Services, Inc. has been trying to get Yahoo to fix a security flaw he found in Y! Music Unlimited that could allow a user to download songs for free. The Music Unlimited service is seen as a sort of music rental service, like Napster To Go and Real's new subscription service. For $4.99 customers can download songs and store them on compatible portable devices, but as soon as they stop paying for the service the music would simple disappear.

In order to burn a song to a CD, users would have to pay 79c for the track. Once it is burned to the CD, it is free of any DRM protection and could easily be ripped into MP3 format using any of various tools on the Internet. Tools like PyMusique and Musik allow users to purchase songs from iTunes without having any DRM protection attached, but these tools don’t make it possible to obtain downloads for free.

"This afternoon we checked to confirm the problem is still live. We downloaded a copy of The Moody Blues - Never Blame The Rainbows For The Rain.wma. It isn't going to be one of my personal favourites, but it does illustrate the point. The music on Yahoo can be obtained quickly, easily, and freely." Chapin told AfterDawn.com in an email. Understandably however, he has not reveal just yet how to get the music for free and most likely wont until Yahoo fixes the problem.

Source:
p2pnet
Chapin Information Services (Press Release)


Thanks to Jon Newton of p2pnet for bringing this to my attention.

Permalink to this article

Get AfterDawn's news to your favourite feed reader! Share this story with your friends!
 

 
Related articles:

  • Yahoo Japan offers free streaming music to attract customers (21 August 2005)
  • Yahoo! crashes the online music market party (11 May 2005)
  •  

    « Previous news article
    Toshiba brings LightScribe to laptops
    Next news article »
    Plextor attacks open source programmers
     Post your comment
    Discuss this article! 
    damo_red (Member) 31 May 2005 2:12 Send private message to this user   
    as kind as this guy is,

    isent he still stealing when hes downloadin for free, wonder what yahoo have to say about this
    etherz (Junior Member) 31 May 2005 9:08 Send private message to this user   
    I read the whole bloody article only to find he won't be releasing how he did it, why do we care then!

    Jks, its a shame he wont share his info, and we could all ruin yahoo! They would soon fix the security flaw then...
    Dela (Staff Member) 31 May 2005 9:49 Send private message to this user   
    Quote:
    as kind as this guy is,

    isent he still stealing when hes downloadin for free, wonder what yahoo have to say about this
    They will more than likely say thanks! lol you have to do things to proove these vulnerabilities exist!
    punx777 (Senior Member) 31 May 2005 10:09 Send private message to this user   
    hey with yahoo music unlimited, can you de-drm it and burn it to a cd?
    borhan9 (AfterDawn Addict) 3 June 2005 4:31 Send private message to this user   
    This article is pointless if u dont share the trick.

    Its not exactly "open sourcing" for everyone is it...

    when someone figures it out post it plz
    vudoo (Member) 6 June 2005 21:55 Send private message to this user   
    I don't see how you can download the music for FREE unless you share a friends subscription or use one of those password stealers in a yahoo chatroom that anouther subscriber has that actually pays for Yahoo and tells someone in a chat room they pay. Unless you know how to stop booters they can steal your password. This happens in chat all the time. But if you know the sites to go to you can get your passcode back. Only the super lame may lose their passcode for good. I suppose any music service would be open to trojan horses to steal passcodes from their subs. but really $4 a month is not bad. I have Rhapsody To Go and love it. I'm actually listening to a band called Thin Lizzy now which is an old 70's band. You don't get their full CD's on p2p. If you only like pop then hey p2p is the only way for you.
     Post your comment
     

    Subscribe to our newsfeed

    Get the latest headlines delivered directly to your favourite RSS reader or content aggregation service by using the links below.

    AfterDawn.com: News - RSS feed
    Add to Google
    Add to My Yahoo!
    Add to MyMSN

    Search for headlines

    Search through our news archive.

    Last week's most popular software downloads

    Digital video: AfterDawn.com | AfterDawn Forums
    Music: MP3Lizard.com
    Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
    Software: Software downloads
    Blogs: User profile pages
    RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
    International: AfterDawn in Finnish | AfterDawn in Swedish | download.fi
    Navigate: Search | Site map
    About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
    Contact us: Send feedback | Contact our media sales team
     
      © 1999-2009 by AfterDawn Ltd.