# music industries warning to kazaa users

**URL:** <https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009>\
**Category:** Factual Questions\
**Created:** [April 29, 2003, 9:42pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009 "2003-04-29T21:42:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ata66](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@ata66](https://boards.straightdope.com/u/ata66)\
**Post date:** [April 29, 2003, 9:42pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/1 "2003-04-29T21:42:57Z")

</div>

i was reading some of the news sites today when i saw this [article](http://sg.news.yahoo.com/030429/3/3akqc.html)  
it says that the music industry is sending instant message warnings to kazaa users, and what i’m wondering is, how are they doing this? my aim screen name and kazaa username are not the same and i have changed e-mail addresses since i’ve signed up for kazaa, so how will they find me or find out my screen name to send out one of these warnings?

---

<div class="post-metadata">

**Author:** ![Scruloose](https://avatars.discourse-cdn.com/v4/letter/s/e68b1a/32.png) [@Scruloose](https://boards.straightdope.com/u/Scruloose)\
**Post date:** [April 29, 2003, 9:50pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/2 "2003-04-29T21:50:37Z")

</div>

From the article:

> [@](#):
>
> The message was designed by a third party who utilized the existing capability of the peer-to-peer networks’ instant message systems. The RIAA said by using song titles, it was identifying users who were posting songs for others to download as targets for the message.

It would seem they are using the P2P’s own IM service for this task.

---

<div class="post-metadata">

**Author:** ![ata66](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@ata66](https://boards.straightdope.com/u/ata66)\
**Post date:** [April 29, 2003, 9:56pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/3 "2003-04-29T21:56:31Z")

</div>

:smack: i had no idea kazaa had its own instant message something until one of my friends who just read this sent me a message calling me a moron. it all makes sense now, thanks.

---

<div class="post-metadata">

**Author:** ![bgack](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@bgack](https://boards.straightdope.com/u/bgack)\
**Post date:** [April 30, 2003, 12:02am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/4 "2003-04-30T00:02:27Z")

</div>

I think they (the record companies) will search for tracks from albums that they own the rights to, and just send some sort of automated private message to the people who are sharing those tracks. I don’t think it will change much.

---

<div class="post-metadata">

**Author:** ![gypsymoth3](https://avatars.discourse-cdn.com/v4/letter/g/85e7bf/32.png) [@gypsymoth3](https://boards.straightdope.com/u/gypsymoth3)\
**Post date:** [April 30, 2003, 12:17am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/5 "2003-04-30T00:17:27Z")

</div>

how exactly do they plan on identifying KaZaA users? i have KaZaA, but i registered so long ago that i can’t remember what info i gave them. i don’t think i typed my full last name.

---

<div class="post-metadata">

**Author:** ![stoyel](https://avatars.discourse-cdn.com/v4/letter/s/54ee81/32.png) [@stoyel](https://boards.straightdope.com/u/stoyel)\
**Post date:** [April 30, 2003, 12:31am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/6 "2003-04-30T00:31:21Z")

</div>

I doubt this is what they’re referring to specifically, but there are third-party companies who hunt down your IP address through your Kazaa connection. They collect a bunch of IPs from a certain domain, and then report them to the ISP. My university sent out a bunch of threatening e-mail to students reported this way, which of course accounted for roughly one tenth of one percent of the people who use it.

---

<div class="post-metadata">

**Author:** ![Jonathan\_Chance](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jonathan_chance/32/701_2.png) [@Jonathan\_Chance](https://boards.straightdope.com/u/Jonathan_Chance)\
**Post date:** [April 30, 2003, 12:51am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/7 "2003-04-30T00:51:48Z")

</div>

I’m really surprised some aspiring record exec hasn’t released some damn-all nasty virus embedded in an MP3 so far. That strikes me as the most effective tactic.

But I’m the one who said that the Wall Street Journal should have hired mercenaries to bring back Danny Pearl and his kidnappers heads. Corporate warfare doesn’t _always_ have to be with lawyers.

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [April 30, 2003, 1:12am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/8 "2003-04-30T01:12:09Z")

</div>

> [@](#):
>
> \*Originally posted by Jonathan Chance \*  
> **I’m really surprised some aspiring record exec hasn’t released some damn-all nasty virus embedded in an MP3 so far. That strikes me as the most effective tactic.**

It wouldn’t be effective at all. MP3s aren’t executable and can’t do any damage when played, except possibly freeze up the player if they’re corrupted. Even if an executable were renamed with a .mp3 extension it still wouldn’t run, since double-clicking it would launch the associated media player and try to play it like a music file.

---

<div class="post-metadata">

**Author:** ![effac3d](https://avatars.discourse-cdn.com/v4/letter/e/b487fb/32.png) [@effac3d](https://boards.straightdope.com/u/effac3d)\
**Post date:** [April 30, 2003, 1:12am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/9 "2003-04-30T01:12:40Z")

</div>

And how would you embed a virus in a mp3?  
Mp3 files aren’t executed,so you would have to exploit the player,and even then it would be hard.

---

<div class="post-metadata">

**Author:** ![xvxdarkknightxvx](https://avatars.discourse-cdn.com/v4/letter/x/34f0e0/32.png) [@xvxdarkknightxvx](https://boards.straightdope.com/u/xvxdarkknightxvx)\
**Post date:** [April 30, 2003, 1:24am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/10 "2003-04-30T01:24:04Z")

</div>

I’m pretty sure there was an aticle on slashdot a while ago saying that Windows Media Player was subject to executing programs embedded within mp3s. Not sure if they patched that up yet, though. Doesn’t really matter to me; I use Winamp (not version 3).

---

<div class="post-metadata">

**Author:** ![xvxdarkknightxvx](https://avatars.discourse-cdn.com/v4/letter/x/34f0e0/32.png) [@xvxdarkknightxvx](https://boards.straightdope.com/u/xvxdarkknightxvx)\
**Post date:** [April 30, 2003, 1:25am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/11 "2003-04-30T01:25:05Z")

</div>

aticle = article

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [April 30, 2003, 1:29am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/12 "2003-04-30T01:29:50Z")

</div>

> [@](#):
>
> \*Originally posted by Q.E.D. \*  
> \*\*It wouldn’t be effective at all. MP3s aren’t executable and can’t do any damage when played, except possibly freeze up the player if they’re corrupted. Even if an executable were renamed with a .mp3 extension it still wouldn’t run, since double-clicking it would launch the associated media player and try to play it like a music file. \*\*

I would not be totally sure of that. I can imagine that some popular mp3 players might suffer from some buffer overflow bug that could be exploitable. Lord knows just about every other class of communication programs like tlenet, ftp, email browsers web servers have had similar problems.

---

<div class="post-metadata">

**Author:** ![Mr.Duality](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mr.duality/32/4098_2.png) [@Mr.Duality](https://boards.straightdope.com/u/Mr.Duality)\
**Post date:** [April 30, 2003, 1:36am UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/13 "2003-04-30T01:36:42Z")

</div>

As I understand it, Kazaa won’t necessarily display the entire file name if it’s a really long name. So you could have a filename displayed which appears to end with .mp3 but it actually ends with .vbs

My Kazaa includes Bullguard Lite virus protection. I have no idea if that’s any good. I’d like to know…

---

<div class="post-metadata">

**Author:** ![Una\_Persson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/una_persson/32/346_2.png) [@Una\_Persson](https://boards.straightdope.com/u/Una_Persson)\
**Post date:** [April 30, 2003, 12:12pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/14 "2003-04-30T12:12:16Z")

</div>

> [@](#):
>
> \*Originally posted by gazpacho \*  
> \*\*I would not be totally sure of that. I can imagine that some popular mp3 players might suffer from some buffer overflow bug that could be exploitable. Lord knows just about every other class of communication programs like tlenet, ftp, email browsers web servers have had similar problems. \*\*

Buffer overflow…in an MP3? 😕

I’m sorry that people have become used to “buffer” problems as a result of Microsoft’s incredibly poor software, but not every program or type of media is automatically susceptable in any way to “buffer” problems.

---

<div class="post-metadata">

**Author:** ![Dreaming\_of\_Maria\_Callas](https://avatars.discourse-cdn.com/v4/letter/d/f14d63/32.png) [@Dreaming\_of\_Maria\_Callas](https://boards.straightdope.com/u/Dreaming_of_Maria_Callas)\
**Post date:** [April 30, 2003, 12:30pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/15 "2003-04-30T12:30:03Z")

</div>

Plus not all Kazaa users also use Windows. Kazaa and Kazaa Lite run nicely in Linux with WINE, so a virus would have a limited impact on those users.

UnuMondo

---

<div class="post-metadata">

**Author:** ![World\_Eater](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@World\_Eater](https://boards.straightdope.com/u/World_Eater)\
**Post date:** [April 30, 2003, 3:34pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/16 "2003-04-30T15:34:51Z")

</div>

Plus I would imagine it would illegal.

---

<div class="post-metadata">

**Author:** ![firagon](https://avatars.discourse-cdn.com/v4/letter/f/13edae/32.png) [@firagon](https://boards.straightdope.com/u/firagon)\
**Post date:** [April 30, 2003, 4:37pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/17 "2003-04-30T16:37:41Z")

</div>

Wasn’t there something about a virus imbedded in picture files a while back? I didn’t really follow it, so I’m not sure whatever happened with that…

---

<div class="post-metadata">

**Author:** ![Azael](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@Azael](https://boards.straightdope.com/u/Azael)\
**Post date:** [April 30, 2003, 8:12pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/18 "2003-04-30T20:12:59Z")

</div>

I’m so scared, please don’t IM me to death!

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 30, 2003, 8:26pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/19 "2003-04-30T20:26:35Z")

</div>

Even without any follow-up, though, these messages might be effective at scaring a few kazaa users away. Which would probably suit the record companies just fine.

---

<div class="post-metadata">

**Author:** ![Ms2001](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ms2001/32/18463_2.png) [@Ms2001](https://boards.straightdope.com/u/Ms2001)\
**Post date:** [April 30, 2003, 8:38pm UTC](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009/20 "2003-04-30T20:38:49Z")

</div>

> [@](#):
>
> \*Originally posted by Mr. Duality \*  
> **As I understand it, Kazaa won’t necessarily display the entire file name if it’s a really long name. So you could have a filename displayed which appears to end with .mp3 but it actually ends with .vbs**

Kazaa also lets you filter out those files by their extension. Here’s the default filter list from Kazaa List KPP:

.scr, .vbs, .jpg.exe, .jpg.vbs, .avi.exe, .avi.vbs, .mp3.exe, .mp3.vbs, -fulldownloader, 3-fulldwnloader, -full-downloader, -games-fulldownloader, divx-fulldownloader, 3-full-dwnloader-, -games-fulldownloader-, -games-fulldownload, pack-fully-download, .htm, .html, .url, .sys, .ini, .m3u, .xml, .vbs, .js, .bat, .eml

[Next page](https://boards.straightdope.com/t/music-industries-warning-to-kazaa-users/172009.md?page=2)
