New era of hacking technique : You may be attacked through malicious movie subtitles

in #security7 years ago

image credit

Now-a-days computer and internet is an essential part of our daily life. Everything is now connected to computers through internet. But, in the last couple of years this internet world are being faced numerous cyber attacks & threats. Only a few days ago WannaCry ransomware was spread out in the form of epidemic. Thousands of computers were infected by it.  All of this goes to show computer users have to worry about a lot of potential problems these days.  Now, another very anxious news is that - "Watching a movie with external subtitles has become a threat right now".

More specifically, researchers  came across a vulnerability of how video players load and parse subtitle  files. This exploit can lead to computers being taken over by third  parties. 

image credit

Playing a downloaded or copied movie with external subtitles has now turned into an risky habit. All the more particularly, video player software parses and loads subtitles in a certain manner. Along these lines of dealing with subtitles can be misused by hackers who need to pick up remotely control over your PC. It is a significant troubling development, most definitely.

All the more particularly, analysts ran over this vulnerability because of a particular examination. It is feasible for attackers to create malicious subtitle documents which execute malicious code on the victim's gadget. This will just work if the victim plays the video and subtitle document in one of the vulnerable media players. The most noticeably bad part is the manner by which the victim would not know something malicious is going ahead, as the subtitle will show the content in the video player as initially anticipated.

image credit

How to protect ?

Please, follow this simple guidelines to keep safe yourself from this kind of attack --

1. Only use reputed video players. There are a numerous types of video player available in the net. But, you only choose reputed video players - VLC Media Player, Kodi, Stremio, and  Popcorn time are just a few of the examples. It is possible several  other players are susceptible to this malicious subtitle attack as well,   

2. Please, update frequently your all installed software including even video players. This will cut off the possibility of being targeted by malicious codes.  It is evident this new vulnerability  affects millions of computer users all over the world. Most people  download a video player and don’t worry about updating it again. This is  a very real problem that needs to be addressed. 

3. Do not download any subtitles from third party & untrusted repositories. Downloading subtitles from  third-party untrusted sources should be avoided at all costs for the time  being. Users who stream content legally will not be affected by this  problem, though. 

4. Please, do not rely on third-party platforms which  offer custom subtitles. It is impossible for these platforms to  distinguish between legitimate subtitles and those that are embedded  with malicious code.

5. Generally all the movie subtitle files are text files. So, you may open this files via notepad to see the content on it. If any malicious codes detected then delete it.


image credit

Reference :

https://www.bleepingcomputer.com/news/security/malicious-movie-subtitles-can-give-hackers-full-control-over-your-pc/

http://www.independent.co.uk/life-style/gadgets-and-tech/news/kodi-hacked-subtitles-users-details-security-tv-phone-a7753986.html

http://www.eweek.com/security/check-point-discovers-media-subtitle-vulnerability-impacting-millions

https://themerkle.com/hackers-can-remotely-control-your-computer-through-malicious-movie-subtitles/

http://gizmodo.com/subtitles-open-you-up-to-hackers-when-using-popular-med-1795493495


follow me on steemit AND resteem it


>>Thanks to @elyaque for designing my badges :)<<

                     MY STATS
   REPUTATION SCORE : 68.3 | TOTAL FOLLOWERS : 432
   TOTAL BLOG POSTS : 467  | TOTAL LIKES : 28277
   TOTAL EARNINGS   : $3336.27
Sort:  

Thank you for this warning. I never knew about this before!

thanks for commenting :)

That's why I never open the torrent magnet links on my machine. I pay $7/month for a cloud torrent downloading service. Great advice by the way!

Nice way to be safe. thnx for sharing :)

Excellent work dear friend @royalmacro thank you very much for sharing this valuable information, have a beautiful day

Coin Marketplace

STEEM 0.20
TRX 0.14
JST 0.030
BTC 69264.29
ETH 3316.64
USDT 1.00
SBD 2.66