This is such a great music service but I’m wondering who is behind it and why they provide it? It must be costing them something to host the site. Interesting that Cloudflare stats show its biggest user base is India.

  • BlueRingedOctopus@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    7
    ·
    14 days ago

    It gives you literal FLAC files, how are they gonna be malicious!?

    People need to stop over analyzing things, its just a qobuz ripper, people who want to help the community provide them with Qobuz tokens that don’t expire as often as Deezer, now they just rip from Qobuz on your request, as simple as that. Firehawk is also building a similar site from scratch.

    • chirping@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Well it’s both possible, and has been done. both with mp3s and FLAC, not too long ago. It’s not the format itself, but rather the applications parsing the files that are the target.

      CVE-2023-37327: A remote code execution vulnerability in GStreamer’s FLAC file parser caused by an integer overflow. Carefully crafted FLAC files could exploit this flaw to run arbitrary code on the target system

      https://nvd.nist.gov/vuln/detail/CVE-2023-37327#%3A~%3Atext=GStreamer+FLAC%2Ccode+on

    • Coopr8@kbin.earth
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      14 days ago

      I mean, a website where you make requests to download many files are pretty ripe for a bate and switch scenario. That said, I’m looking for more cybersecuroty savvy folks than myself to chime in with the all-clear after doing some actual checks and analysis.