Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,148,762 members, 7,802,325 topics. Date: Friday, 19 April 2024 at 12:32 PM

Kodi App And Other Media Players Now Prone To Malicious Attack By Subtitles - Science/Technology - Nairaland

Nairaland Forum / Science/Technology / Kodi App And Other Media Players Now Prone To Malicious Attack By Subtitles (531 Views)

How To Use Nextpvr And Kodi To Watch Live TV On A Windows Computer / Is It Possible To Add Kodi On Roku? / New Kodi Update Arrives - Download It Now! (2) (3) (4)

(1) (Reply)

Kodi App And Other Media Players Now Prone To Malicious Attack By Subtitles by zubbie01(m): 3:33pm On May 26, 2017
Check Point researchers revealed a new attack vector which threatens millions of users worldwide – attack by subtitles. By crafting malicious subtitle files, which are then downloaded by a victim’s media player, attackers can take complete control over any type of device via vulnerabilities found in many popular streaming platforms, including VLC, Kodi (XBMC), Popcorn-Time and strem.io. We estimate there are approximately 200 million video players and streamers that currently run the vulnerable software, making this one of the most widespread, easily accessed and zero-resistance vulnerability reported in recent years.
[img]https://3.bp..com/-U6RnJ1gUjIg/WSgzg6Qt76I/AAAAAAAABqI/mb-63ixsq_g8A9p6eg0wp92JJyLVhcNWQCK4B/s400/Kodi_hacked.png[/img]

What is the root cause?

The attack vector relies heavily on the poor state of security in the way various media players process subtitle files and the large number of subtitle formats. To begin with, there are over 25 subtitle formats in use, each with unique features and capabilities. Media players often need to parse together multiple subtitle formats to ensure coverage and provide a better user experience, with each media player using a different method. Like other, similar situations which involve fragmented software, this results in numerous distinct vulnerabilities.

[img]https://1.bp..com/-lJS6Ie5meM0/WSgzsjy0FxI/AAAAAAAABqQ/Ab539ZQMRmE43oLHARV6OtUlYdJ0imMdACK4B/s400/hacked%2Bin%2Btranslation.png[/img]

What’s the effect?
Scope: The total number of the affected users is in the hundreds of millions. Each of the media players found to be vulnerable to date has millions of users, and we believe other media players could be vulnerable to similar attacks as well. VLC has over 170 million downloads of its latest version alone, which was released June 5, 2016. Kodi (XBMC) has reached over 10 million unique users per day, and nearly 40 million unique users each month. No current estimates exist for Popcorn Time usage, but it’s safe to assume that the number is likewise in the millions.

Damage: By conducting attacks through subtitles, hackers can take complete control over any device running them. From this point on, the attacker can do whatever he wants with the victim’s machine, whether it is a PC, a smart TV, or a mobile device. The potential damage the attacker can inflict is endless, ranging anywhere from stealing sensitive information, installing ransomware, mass Denial of Service attacks, and much more.

GET YOUR MEDIA PLAYERS SECURED HERE: http://www.digitalbog.com/2017/05/Kodi-App-hacked-by-subtitles.html

(1) (Reply)

How To Transfer Files Between Pc/laptop And Android Using Wifi / How Do I Protect My Tech Ideas In Nigeria & Everything I Need To Know Please... / Facebook Group For Sale

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 9
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.