Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,158,546 members, 7,837,092 topics. Date: Wednesday, 22 May 2024 at 04:41 PM

Hackers Can Use Subtitles To Infect Your Devices - TV/Movies - Nairaland

Nairaland Forum / Entertainment / TV/Movies / Hackers Can Use Subtitles To Infect Your Devices (452 Views)

How To Add Subtitles To Your Video With Your Mobile Phone / Where Can I Get Clear Tvseries With Subtitles To Watch? (2) (3) (4)

(1) (Reply)

Hackers Can Use Subtitles To Infect Your Devices by Dotng: 5:15pm On May 28, 2017
Hackers Can Use Subtitles to Infect Your Devices



BY ANGELA MOSCARITOLO
MAY 25, 2017 10:44AM EST


Researchers from security firm Check Point said 'hundreds of millions' of devices running media players such as VLC, Kodi, Popcorn Time, and Stremio are at risk.

Enjoy watching foreign films? We have some bad news.

Security researchers have discovered a new attack vector that could allow online miscreants to gain access to your PC, mobile device, and smart TV: malicious subtitles. Researchers from security firm Check Point said "hundreds of millions" of devices running VLC, Kodi, Popcorn Time, and Stremio — four of the most popular media players out there — are at risk.

SecurityWatch"Malicious subtitles could be created and delivered to millions of devices automatically, bypassing security software and giving the attacker full control of the infected device and the data it holds," Check Point vulnerability research team leader Omri Herscovici said in a statement.

He went on to say that the subtitle supply chain is "complex," with more than 25 different formats in use, all with unique features. "This fragmented ecosystem, along with limited security, means there are multiple vulnerabilities that could be exploited, making it a hugely attractive target for attackers," Herscovici said.

Subtitles for films and TV shows are created by "a wide range of subtitle writers," who upload them to shared online repositories such as OpenSubtites.org, where the files are indexed and ranked, Check Point explained. Here's the problem: bad actors can manipulate the repositories' ranking algorithm, so that their malicious subtitles are automatically downloaded by media players. This would allow the attacker to "take complete control over the entire subtitle supply chain" with "little or no deliberate action on the part of the user."

Check out Check Point's proof-of-concept video below demonstrating how an attacker could use malicious subtitles to take over your machine.


https://www.youtube.com/watch?v=vYT_EGty_6A


Check Point said it followed responsible disclosure guidelines and reported the bugs to the developers of the vulnerable media players. Some of the issues have already been fixed while others are still under investigation.

"To protect themselves and minimize the risk of possible attacks, users should ensure they update their streaming players to the latest versions," Herscovici said. PopcornTime has released a new version, which corrects the problem; it can be downloaded here. The latest versions of Kodi, VLC, and Stemio are also officially fixed.

RELATED

Speakers Become Latest Threat to Your Digital Security
Check Point said there is "reason to believe similar vulnerabilities exist in other media players as well." The company has not yet released full technical details of the flaws to give the developers more time to address the problem.

Part of the issue, Check Point said, is that movie subtitles are often perceived as "nothing more than benign text files."

"This means users, anti-virus software, and other security solutions vet them without trying to assess their real nature, leaving millions of users exposed to this risk," the company said. Check Point estimates that approximately 200 million video players and streamers currently run the vulnerable software, "making this one of the most widespread, easily accessed and zero-resistance vulnerability reported in recent years."



http://www.pcmag.com/news/353891/hackers-can-use-subtitles-to-infect-your-devices

(1) (Reply)

Nicki Minaj, And Drake Apologize To Themselves For Their Stupid Quarrel.(video) / ABUJA Crazy Birthday Party / Doocast Movie International

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 14
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.