Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Tuesday May 23 2017, @05:10PM   Printer-friendly
from the targeting-the-hard-of-hearing dept.

Submitted via IRC for TheMightyBuzzard

Check Point researchers revealed a new attack vector threatening millions of users of popular media players, including VLC, Kodi (XBMC), Popcorn Time and Stremio. By crafting malicious subtitle files for films and TV programmes, which are then downloaded by viewers, attackers can potentially take complete control of any device running the vulnerable platforms.

"The supply chain for subtitles is complex, with over 25 different subtitle formats in use, all with unique features and capabilities. This fragmented ecosystem, along with limited security, means there are multiple vulnerabilities that could be exploited, making it a hugely attractive target for attackers," said Omri Herscovici, vulnerability research team leader at Check Point.

The subtitles for films or TV shows are created by a wide range of subtitle writers, and uploaded to shared online repositories, such as OpenSubtitles.org, where they are indexed and ranked. Researchers also demonstrated that by manipulating the repositories' ranking algorithm, malicious subtitles can be automatically downloaded by the media player, allowing a hacker to take complete control over the entire subtitle supply chain without user interaction.

Source: https://www.helpnetsecurity.com/2017/05/23/subtitle-hack/


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Tuesday May 23 2017, @06:35PM (2 children)

    by Anonymous Coward on Tuesday May 23 2017, @06:35PM (#514447)

    > I smell a copyright rat.

    Or...
    news likes sensationalism so they sexed up the story a little bit to get more clicks.

  • (Score: 0) by Anonymous Coward on Wednesday May 24 2017, @01:03AM (1 child)

    by Anonymous Coward on Wednesday May 24 2017, @01:03AM (#514608)

    Not outside the realm of possibility. Corporations like to use the media to push agendas. They do it all the time. They have for years. The news orgs are so crap they run with pretty much anything that sorta looks like a story. I have been seeing tons of KODI hate out there for the past month. It smells like a corporate run hit job. Proof? Not a shred. Of course all of the articles are of the same quality.

    • (Score: 0) by Anonymous Coward on Wednesday May 24 2017, @05:49AM

      by Anonymous Coward on Wednesday May 24 2017, @05:49AM (#514687)

      Corps rarely run their shady dealings in a way that can be uncovered. Usually a good investigative journalist is required, and even then it often depends on a whistle blower.