Advertisement
Promo

Online business Toolkit

Kazaa users often expose personal files

Steven Musil CNet

Published: 07 Jun 2002 09:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users of the popular file-swapping program Kazaa frequently expose personal data to other network users by erroneously designating which files should be shared files, according to research released by HP Labs.

The study, conducted by computer scientists Nathaniel S. Good of HP Labs and Aaron Krekelberg of the University of Minnesota, points out that peer-to-peer programs often pose a threat to computer privacy.

The research, which was published Wednesday on Hewlett-Packard's Web site, found that a significant percentage of Kazaa users have accidentally or unknowingly designated private files to be shared with everyone who has access to the popular Kazaa network.

The researchers scripted programs to search the Kazaa network for files that store Microsoft Outlook Express email, with the assumption that these would be files that no one would intentionally share on the public network.

The automatic queries occurred every 90 seconds for 12 hours and revealed 443 instances of unintentional file sharing. In that 12-hour period, 156 Kazaa users were found to have email files open for public review. Sixty-one percent of the searches revealed at least one email file.

In another test, researchers studied 20 distinct cases in which the Outlook mail program had been made public. Of those, 19 allowed access to other categories in the program, such as deleted items and mail sent. Nine users exposed their Web browser's cache and cookies, five exposed word processing programs, and two exposed what appeared to be financial data.

Another experiment sought to determine whether other Kazaa users were trying to exploit this vulnerability by downloading files from other users' computers. The researchers placed dummy personal files with titles such as Credit Card.xls and Inbox.dbs on a server. In a 24-hour period, the credit card file was downloaded four times by four unique visitors, and the inbox file was downloaded four times by two unique visitors.

The study said the researchers did not download any files from other Kazaa users.

The researchers blamed shortcomings in the Kazaa installation software for making it easy for users to configure their software improperly and unknowingly share private information.

Kazaa representatives were not immediately available for comment.

Brilliant Digital Entertainment, which owns the Kazaa software, recently came under a firestorm of criticism when it was revealed that it had quietly attached its software to millions of downloads of the popular Kazaa file-trading program and plans to remotely "turn on" people's PCs, welding them into a new network of its own.


Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
31 out of 58 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters