24 July 2014, 07:03 | #641 |
Registered User
Join Date: Jul 2005
Location: Australia
Age: 46
Posts: 666
|
After reading Akin's original advisory, it's pretty clear that what he's done is take advantage of the preload attack vector. You can do a few things such as provide a decent installer which will go some way toward mitigating the potential risk. To be clear you're not the root cause, neither are the FMOD libraries, this guy has setup BZR player in a way that deliberately exposes it to a known vulnerability. The Secunia Advisory makes it clear that the essential precondition is tricking the user, the same tactic can be used with almost any application if the attacker has prior knowledge of the target environment.
Watch the video carefully and ask yourself: Where did that desktop shortcut come from? How did MP3 files become associated with BZR Player? Where did that "Open With" context menu item come from? Your player didn't do any of that nor did any of the third party libraries and the docs don't say to do it either. Also, why is he running with admin rights in direct contravention of known best practice? OK it's in a VM but making the problem more dangerous is just dumb. Why is there no Process Monitor dump to explain why his poisoned library is loaded instead of the real one? It would be just as effective to overwrite the supplied MPEG library and be done with it. You can probably see where I'm going with this, if not, this primer from Microsoft should be helpful. |
25 July 2014, 00:37 | #642 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
Thanks for the info. Yeah that's it, every single program is cracked by supplying modified exes or dlls so I don't see why this is different. But this is an example of why you shouldn't download programs from sites you don't trust.
|
18 August 2014, 17:36 | #643 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
Blazer, thumb up for your player.
I love the pattern view!! Btw, I hope that you will be adding more exotic sound formats from the amiga. keep up the good work matey! |
19 August 2014, 19:46 | #644 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
Glad you like it, Crown! I'm quite fond of the pattern view myself
|
20 August 2014, 16:36 | #645 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
regarding the pattern view, it would be great to be able to close/activate channels when clicking on each one of them 4.
I think this was possible on hippo player and it was a great functionality really. |
20 August 2014, 17:58 | #646 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
Good idea, you mean mute/unmute for each channel? Also have to show that's it's muted somehow, maybe dimming the colors.
By the way I'm sure you know that you can mute channels in the "channels"-window. |
21 August 2014, 11:46 | #647 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
yes, that's right (mute/unmute)
yes I tried the channels window but it would be more handy if was on the pattern view. |
22 August 2014, 14:03 | #648 |
I want an A1000
Join Date: Sep 2004
Location: Pac-Land
Posts: 738
|
Hello bLAZER, is it possible to retrieve the unpacked files (whether they are playable or not) with the Player's lzx extraction feature or is it for internal use only? It'd be nice to have it since lzx unpacking in Windows is problematic.
|
22 August 2014, 18:36 | #649 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
Yeah I know, not many Windows program can unpack lzx. And you are in luck:
lzx files are unpacked to the folder Code:
C:\Users\<username>\AppData\Local\Temp\BZRplayer_tmp |
26 August 2014, 20:41 | #650 |
I want an A1000
Join Date: Sep 2004
Location: Pac-Land
Posts: 738
|
Thank you, that will help quite a lot. Looking forward to your next updates.
|
21 September 2014, 01:53 | #651 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
Crown's suggestion about muting channels by clicking on them in the pattern view is now working fine. Just have to get them to look nice in all other views, only Protracker is done.
Take a look here: [ Show youtube player ] |
23 September 2014, 09:08 | #652 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
Hi Blazer,
thanks for incorporating my suggestion into the soon-to-come version. Can't wait to play around with it. I am experiencing some sort of a bug on my PC. I have done so that mods and mp3s are by default using BZR so that I only have to click on an mp3 to load the program and play a tune. This works great when the program isn't launched but as soon as I am playing a tune and I click on another one from my mod/mp3 directory I get the message that BZR has ceased to function. Therefore it never plays another song unless I drag and drop it onto the UI. And I also wanted to come with another suggestion. I sometimes like to get to listen to just a certain part of a song, for example at 2:35. unfortunately, this is pretty tedious on BZR as when I move my pointer on the sound position slider, it does not display the time. So when searching for position 2:35 I need quite a bit of luck Else than that I am using it everyday and love it! Last edited by Crown; 23 September 2014 at 09:28. |
23 September 2014, 09:35 | #653 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
Btw, I tried to play a MKII tune and it crashed BZR.
Would also be nice to add Sonic Arranger player. |
23 September 2014, 09:37 | #654 |
Global Moderator
Join Date: Nov 2001
Location: Derby, UK
Age: 48
Posts: 9,355
|
bLAZER I think you are doing a great job here.. Well done
Is there a chance the lzx functions can be made into a seperate tool? Would be great for Windows |
23 September 2014, 23:47 | #655 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
@Crown I've noticed the crash, it has something to do with multiple instances, if you enable "Allow multiple instances" in settings it doesn't crash. So something broke somewhere along the way, I'll fix it.
edit: That bug is now fixed. Regarding seeking in sound the time IS displaying during seeking...so I'm not sure what you're doing... The mk2 probably crashed because it happened to match the file signature of some other format. What tune was it, so I can check exactly why? @bippym Regarding developing a lzx tool I'm not really up for it. But I used most of the lzx code from xmp http://xmp.sourceforge.net/ and if you know some c/c++ it isn't that complicated to add some GUI etc. Last edited by bLAZER; 24 September 2014 at 00:52. |
24 September 2014, 08:46 | #656 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
Hi Blazer,
thanks for fixing that bug. I'll send you an email about the two other topics. cheers |
26 September 2014, 22:16 | #657 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
New feature: browse samples in patternview:
[ Show youtube player ]
Protracker and Ultimate Soundtracker done so far |
30 September 2014, 10:10 | #658 |
Demoscener
Join Date: May 2006
Location: FR
Age: 54
Posts: 460
|
hey Blazer,
this is another cool feature, thanks a lot. I wanted to point out something that could be a bug. Whenever I listen to a tune with headphones and then remove the jack plug from my computer there is no sound going out from the laptop loudspeakers. it should normally switch as soon as headphones are plugged/unplugged. This works fine with Deliplayer, WinAMP, etc. so I believe the issue could related to BZR. The only cure to that bug seem to be to load a new tune or restart the program. cheers |
30 September 2014, 18:50 | #659 |
Registered User
Join Date: Jan 2014
Location: Belgrade / Serbia
Age: 41
Posts: 1,004
|
Fabulous player! I just enjoyed Wendetta2175 mods with lowered pitch(tempo) and they sound like some New Generation EBMstep
As I decided that BZR stays and I'll use it as primary player, I wanted that SOTB "skin". After looking through all setting I was about to write here for help... then I simple clicked screen... If you find relevant few things would be great to implement. -First, Reverb slider(like balance) would be great so it won't be necessary to go to settings to change dry/wet amount. I like some songs with more some with less reverb. -Second, for mods maybe separate pitch and tempo slider. -Eq for left and right channel and that would be my dream player |
30 September 2014, 21:02 | #660 |
Awesome to the max
Join Date: Mar 2007
Location: Gothenburg / Sweden
Age: 48
Posts: 1,006
|
1.01 Released
New features:
Bug fixes:
Other:
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
Thread Tools | |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Amiga music player on PC | moriez | Amiga scene | 38 | 07 September 2020 16:23 |
Music player with Batman | glr | Looking for a game name ? | 2 | 04 January 2012 14:02 |
Best music player | quantum112 | support.Apps | 9 | 06 January 2010 09:59 |
FAT Player MikMod v5 (amiga mod player for Nintendo DS) | spajdr | Amiga scene | 0 | 14 August 2008 21:55 |
New Amiga Music Player | Ian | Amiga scene | 1 | 08 October 2001 20:19 |
|
|